Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Secure Code Warrior Spotlights the Importance of Developer Security Skills with 2nd Annual Devlympics Competition

The global secure coding competition will be held In October, during Cybersecurity Awareness Month.

DARKReading
#vulnerability
One-Third of Popular PyPI Packages Mistakenly Flagged as Malicious

The scans used by the Python Package Index (PyPI) to find malware fail to catch 41% of bad packages, while creating plentiful false positives.

Coalfire Federal Among First Authorized to Conduct CMMC Assessments

Company fortifies its ability to help organizations prepare and obtain CMMC certification.

Apathy Is Your Company's Biggest Cybersecurity Vulnerability — Here's How to Combat It

Make security training more engaging to build a strong cybersecurity culture. Here are four steps security and IT leaders can take to avoid the security disconnect.

Meta Takes Offensive Posture With Privacy Red Team

Engineering manager Scott Tenaglia describes how Meta extended the security red team model to aggressively protect data privacy.

Novant Health Notifies Patients of Potential Data Privacy Incident

Patients face possible disclosure of protected health information (PHI) to Meta, Facebook's parent company, resulting from an incorrect configuration of an online tracking tool.

Charming Kitten APT Wields New Scraper to Steal Email Inboxes

Google researchers say the nation-state hacking team is now employing a data-theft tool that targets Gmail, Yahoo, and Microsoft Outlook accounts using previously acquired credentials.

Fake DDoS Protection Alerts Distribute Dangerous RAT

Security vendor Sucuri says adversaries are injecting malicious JavaScript into numerous WordPress websites that triggers phony bot-related checks.

Metasploit Creator Renames His Startup and IT Discovery Tool Rumble to 'runZero'

HD Moore's company has rebranded its IT, IoT, and OT asset discovery tool as the platform rapidly evolves.

For Penetration Security Testing, Alternative Cloud Offers Something Others Don't

Alternative cloud providers offer streamlined capabilities for penetration testing, including more accessible tools, easy deployment, and affordable pricing.