Adopting a cyber security framework provides clear benefits that increase over time; but for most organizations, framework adoption requires overcoming a range of both technical and organizational impediments. Automated foundational controls are currently not being widely implemented.
read more
Edge Exploits Added to Sundown EK
The maintainers of the Sundown exploit kit have started using two Microsoft Edge vulnerabilities just a few days after researchers published a proof-of-concept (PoC) exploit.
read more
Understanding the Benefits of Security Abstraction
The world of cybersecurity is becoming more and more complicated and – some say – almost unmanageable. This is due to the increasing volume of advanced attack campaigns and subsequent investment by organizations in more and more security tools – tools that are potentially effective, but are also trapped in silos that limit their capabilities.
read more
Rockwell Automation Addresses Flaws in Programmable Controllers
Several vulnerabilities have been found in Allen-Bradley programmable automation controllers, programmable logic controllers and safety programmable controllers from Rockwell Automation.
read more
Man Pleads Guilty to Hacking Accounts of U.S. Officials
Justin G. Liverman, a 24-year-old from North Carolina, has pleaded guilty for his part in a hacking conspiracy that targeted several U.S. government officials, including CIA chief John Brennan.
read more
Cloud Security Firm Bitglass Raises $45 Million
Bitglass, a Silicon Valley-based provider of mobile and cloud data protection solutions, today announced that it has secured $45 million in a Series C funding round.
read more
China-Linked “DragonOK” Group Expands Operations
A China-linked threat group known as DragonOK has updated its toolset, and the decoy documents it has used in attacks suggest that its list of targets may have been expanded to include Russia and Tibet.
read more
Google Patches High Risk Vulnerability in Android Bootloader
A vulnerability recently addressed in Google’s January 2017 Android security bulletin was a denial of service (DoS) flaw in the bootloader, which could be exploited to target Nexus 6 and 6P custom boot modes, IBM security researchers reveal.
read more
New “Ghost Host” Technique Boosts Botnet Resiliency
Malware Developers Trick Web Security Systems by Changing Domain Names and Inserting Non-malicious Hostnames into HTTP Host Field.
read more
Multiple Attackers Hijacking MongoDB Databases for Ransom
The recently reported hijacking of MongoDB databases to hold their content for ransom is picking up pace as more hackers are trying to monetize the attack method, security researchers say.
read more


