While the number of extended internet of things security flaws reported during the first six months of 2022 was relatively unchanged from the second half of 2021, significant improvements were found in vendors' vulnerability discovery and reporting methods, according to SecurityWeek.
Google Cloud’s CISO Office director details ongoing federal efforts to address systemic cybersecurity challenges in healthcare, while renewing calls for more collaboration.
BleepingComputer reports that more threat actors have been exploiting software-as-a-service platforms to host credential-stealing phishing campaigns, with phishing URLs on SaaS platforms increasing by more than 1,100% between June 2021 and June 2022.
Several well-known Wall Street U.S. banks will be dipping into their own pockets to pay more than $1 billion all together in regulatory fines because their traders used private messaging applications such as WhatsApp in their work, due to potential security and privacy issues of this practice.
Mitiga researchers spotted a business email compromise campaign leveraging inherent weaknesses in Microsoft 365 Multi-Factor Authentication, Authenticator, and Identity Protection.
More than 80,000 Hikvision cameras used by 2,300 organizations across 100 countries remain vulnerable to an easily exploitable critical command injection bug, tracked as CVE-2021-36260, which has been fixed by the vendor last September, BleepingComputer reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.