CISA Hires ‘Mudge’ to Work on Security-by-Design Principles

Peiter ‘Mudge’ Zatko joins the US government’s cybersecurity agency to preach the gospel of security-by-design and secure-by-default development principles.
The post CISA Hires ‘Mudge’ to Work on Security-by-Design Principles appeared first on Security… Continue reading CISA Hires ‘Mudge’ to Work on Security-by-Design Principles

Exploit Code Published for Critical-Severity VMware Security Defect

Exploit code and root-cause analysis released by SinSinology documents the problem as a case where VMWare “forgot to regenerate” SSH keys.
The post Exploit Code Published for Critical-Severity VMware Security Defect appeared first on SecurityWeek.
Continue reading Exploit Code Published for Critical-Severity VMware Security Defect

Operation ‘Duck Hunt’: Qakbot Malware Disrupted, $8.6 Million in Cryptocurrency Seized

U.S. law enforcement announce the disruption of the notorious Qakbot cybercrime operation and the release of an auto-disinfection tool to 700,000 infected machines.
The post Operation ‘Duck Hunt’: Qakbot Malware Disrupted, $8.6 Million in Cryptocurrenc… Continue reading Operation ‘Duck Hunt’: Qakbot Malware Disrupted, $8.6 Million in Cryptocurrency Seized

VMware Patches Major Security Flaws in Network Monitoring Product

VWware patches critical flaws that allow hackers to bypass SSH authentication and gain access to the Aria Operations for Networks command line interface.
The post VMware Patches Major Security Flaws in Network Monitoring Product appeared first on Secur… Continue reading VMware Patches Major Security Flaws in Network Monitoring Product

OpenAI Turns to Security to Sell ChatGPT Enterprise

ChatGPT Enterprise is a corporate edition of ChatGPT that promises “enterprise-grade security” and a commitment not to use prompts and company data to train AI models.
The post OpenAI Turns to Security to Sell ChatGPT Enterprise appeared first on Secur… Continue reading OpenAI Turns to Security to Sell ChatGPT Enterprise

Did Microsoft Just Upend the Enterprise Browser Market?

NEWS ANALYSIS: Redmond plants its feet firmly in the enterprise browser space, sending major ripples through Silicon Valley’s bustling venture-backed startup ecosystem.
The post Did Microsoft Just Upend the Enterprise Browser Market? appeared first on … Continue reading Did Microsoft Just Upend the Enterprise Browser Market?

Acquisition Chatter Swirls Around SentinelOne, BlackBerry

Cybersecurity vendors SentinelOne and BlackBerry have been separately named in public acquisition chatter with a surprise suitor emerging.
The post Acquisition Chatter Swirls Around SentinelOne, BlackBerry appeared first on SecurityWeek.
Continue reading Acquisition Chatter Swirls Around SentinelOne, BlackBerry

Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint

Microsoft warns that Chinese spies are hacking into Taiwanese organizations with minimal use of malware and by abusing legitimate software.
The post Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint appeared firs… Continue reading Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint

Thoma Bravo Merges ForgeRock with Ping Identity

The private equity firm merges the newly acquired ForgeRock with Ping Identity, combining two of the biggest names in enterprise IAM market.
The post Thoma Bravo Merges ForgeRock with Ping Identity appeared first on SecurityWeek.
Continue reading Thoma Bravo Merges ForgeRock with Ping Identity