The Biden administration’s national cyber strategy is a bold effort to strengthen cybersecurity across critical infrastructure. But low-resourced sectors will need broad support to meet the lofty goals.
Aqua researchers discovered that Jenkins open source automation servers are being impacted by two severe vulnerabilities dubbed "CorePlague," which could be exploited to facilitate arbitrary code execution, reports The Hacker News.
Looking at topics around go-to-market strategy and product management, including: how building products is unique in cybersecurity compared to other industries, what is product-led growth and what shape it takes in security, and how to do it right. Touching on the broader and adjacent topics of writing, supporting cybersecurity startups, investing,...
You know SBOMs can help you keep track of your software assets and therefore, their vulnerabilities. Despite even the White House pressing the issue, many vendors aren't forthcoming with SBOMs, and you can't afford to wait. With Tanium's Roland Diaz, we'll discuss the most important considerations when generating your own SBOMs (which is now someth...
One hundred or more businesses in North and South America and Europe have been impacted by the ongoing Hiatus hacking campaign that exploits DrayTek Vigor routers to facilitate data exfiltration and establish a covert proxy network, BleepingComputer reports.
In this edition of Below The Surface, we discuss insights Scott collected from various members of our community. Topics include supply chain threats, critical firmware attacks, and more! We also welcome special guest Tyler Robinson! View the full report here: https://eclypsium.com/2022/12/13/december-firmware-threat-report/ This segment is sponsore...
SecurityWeek reports that four security flaws impacting programmable logic controllers by German industrial automation solutions provider Wago have been fixed in recently issued patches.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.