When focused on cybersecurity through a vulnerability management lens, it's tempting to see the problem as a race between exploit development and patching speed. This is a false narrative, however. While there are hundreds of thousands of vulnerabilities, each requiring unique exploits, the number of post-exploit actions is finite. Small, even. Alt...
Intrusions exploiting a Firefox animation timeline use-after-free vulnerability, tracked as CVE-2024-9680, and a Windows Task Scheduler privilege escalation bug, tracked as CVE-2024-49039 both of which are zero-days have been deployed by Russian threat operation RomCom, also known as Tropical Scorpius, Storm-0978, and UNC2596, against North America and Europe as part of a sweeping attack campaign, BleepingComputer reports.
In the enterprise security news, Bitsight, Snyk, and Silverfort announce acquisitions, Tanium announces an “autonomous” endpoint security offering, We find out how much a smartphone costs when it is manufactured in the US, CISA’s leadership announces resignations, Ransomware is going after old versions of Excel, Should vendors be doing more about a...
Why a special segment on Microsoft Ignite announcements? There were a lot of announcements, Microsoft is the largest security vendor, in terms of revenue, Microsoft and its products are also the biggest and most vulnerable hacking target in the tech industry..
Any form of MFA is better than passwords alone, but organizations must implement modern, phishing-resistant forms of MFA to truly improve their security postures.
Such newly secured funds, which come after Armis reached $200 million in annual recurring revenue, will be allocated towards accelerating product development and studying opportunities for acquisition as it aims to reach an ARR of $500 million by 2026, when the firm is reported to be planning to stage an IPO.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.