‘Secrets Sprawl’ Haunts Software Supply Chain Security

A cybersecurity startup is warning of a major, unattended weak link in the software supply chain: the vexing problem of valuable corporate secrets — API keys, usernames and passwords, and security certificates — publicly exposed in corporate reposito… Continue reading ‘Secrets Sprawl’ Haunts Software Supply Chain Security

High-Severity Vulnerabilities Patched in BIND Server

The Internet Systems Consortium (ISC) has released security updates to fix multiple high-severity vulnerabilities in the widely deployed Berkeley Internet Name Domain (BIND) server software.
read more

Continue reading High-Severity Vulnerabilities Patched in BIND Server

Todyl Banks $28M Series A Investment

Security and networking platform start-up Todyl on Thursday announced the closing of a $28 million Series A funding round. 
The new investment round was led by Anthos Capital with participation from previous investors Blu Ventures, StoneMill Ventu… Continue reading Todyl Banks $28M Series A Investment

Legit Security Raises $30M to Tackle Supply Chain Security

A team of Israeli entrepreneurs with roots in the application security ecosystem is taking a stab at software supply chain security with big backing from Bessemer Venture Partners.
read more

Continue reading Legit Security Raises $30M to Tackle Supply Chain Security

Apple Says WebKit Zero-Day Hitting iOS, macOS Devices

Appleā€™s struggles with zero-day attacks on its iOS and macOS platforms are showing no signs of slowing down.
read more

Continue reading Apple Says WebKit Zero-Day Hitting iOS, macOS Devices

Law Enforcement Blowback, Cyber Insurance Renewals Powering Anti-Ransomware Success

read more

Continue reading Law Enforcement Blowback, Cyber Insurance Renewals Powering Anti-Ransomware Success

Critical Flaws Expose Mimosa Wireless Broadband Devices to Remote Attacks

A researcher has discovered several critical vulnerabilities in wireless broadband products made by Mimosa Networks. The flaws can expose affected devices to remote attacks.
Mimosa, a division of Airspan, provides wireless broadband solutions that can … Continue reading Critical Flaws Expose Mimosa Wireless Broadband Devices to Remote Attacks

Volexity Warns of ‘Active Exploitation’ of Zimbra Zero-Day

Malware hunters at Volexity are raising the alarm for a Chinese threat actor seen exploiting a zero-day flaw in the Zimbra email platform to infect media and government targets in Europe.
read more

Continue reading Volexity Warns of ‘Active Exploitation’ of Zimbra Zero-Day