Active exploitation of a critical zero-day flaw in Sophos' firewall product has prompted Sophos to immediately issue a patch update, reports The Hacker News.
BleepingComputer reports that American Airlines has confirmed that it was breached after being targeted by a phishing attack leveraging an employee's compromised Microsoft 365 account.
BleepingComputer reports that GitHub users are being targeted in an ongoing phishing campaign spoofing the CircleCI continuous integration and delivery platform, which commenced last week.
Millions of devices, including those manufactured by Microsoft, HP, Intel, Dell, Siemens, Framework, and Fujitsu, are being affected by seven firmware vulnerabilities in Insyde Software's InsydeH20 UEFI firmware, which could be exploited to facilitate persistent device access, SecurityWeek reports.
Dumping passwords and going fully passwordless may seem like an impossible task, but there are tried-and-true ways it can be done. Here's how to get your organization to move beyond passwords for good.
Morgan Stanley's wealth and asset management division Morgan Stanley Smith Barney has agreed to pay a $35 million fine to settle charges filed by the U.S. Securities and Exchange Commission pertaining to federal regulation violations on customer data protection and disposal, TechRepublic reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.