Fortinet Ships Emergency Patch for Already-Exploited VPN Flaw

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the flaw in the wild.
read more Continue reading Fortinet Ships Emergency Patch for Already-Exploited VPN Flaw

Proofpoint Buys Deception Tech Startup Illusive Networks

Enterprise security vendor Proofpoint on Monday announced plans to acquire Illusive Networks, a startup that helped pioneer deception technology to help detect data breaches. Financial terms of the planned acquisition were not disclosed.
read more Continue reading Proofpoint Buys Deception Tech Startup Illusive Networks

Apple Scraps CSAM Detection Tool for iCloud Photos

Apple has scrapped plans to ship a controversial child pornography protection tool for iCloud Photos, a concession to privacy rights advocates who warned it could have been used for government surveillance.
read more Continue reading Apple Scraps CSAM Detection Tool for iCloud Photos

Google Documents IE Browser Zero-Day Exploited by North Korean Hackers

Google’s Threat Analysis Group (TAG) has shared technical details on an Internet Explorer zero-day vulnerability exploited in attacks by North Korean hacking group APT37.
read more Continue reading Google Documents IE Browser Zero-Day Exploited by North Korean Hackers

Big Tech Vendors Object to US Gov SBOM Mandate

The U.S. government’s mandates around the creation and delivery of SBOMs (software bill of materials) to help mitigate supply chain attacks has run into strong objections from big-name technology vendors.
read more Continue reading Big Tech Vendors Object to US Gov SBOM Mandate

Investors Pour $200 Million Into Compliance Automation Startup Drata

High-flying security compliance and automation startup Drata continues to attract major venture capital investor interest, banking $200 million in Series C funding that values the company north of $2 billion.
read more Continue reading Investors Pour $200 Million Into Compliance Automation Startup Drata

‘Scattered Spider’ Cybercrime Group Targets Mobile Carriers via Telecom, BPO Firms

A threat actor tracked as ‘Scattered Spider’ is targeting telecommunications and business process outsourcing (BPO) companies in an effort to gain access to mobile carrier networks and perform SIM swapping, cybersecurity firm CrowdStrike warns.
read mo… Continue reading ‘Scattered Spider’ Cybercrime Group Targets Mobile Carriers via Telecom, BPO Firms

Balance Theory Scores Seed Funding for Secure Workspace Collaboration

Balance Theory, a seed-stage startup working on technology to help security teams collaborate and manage data flows securely, has closed a $3 million funding round.
The Columbia, Maryland-based Balance Theory said the early-stage investment was led by … Continue reading Balance Theory Scores Seed Funding for Secure Workspace Collaboration