The Cybersecurity and Infrastructure Security Agency has clarified that security flaws should have a CVE identifier, reliable proof of active exploitation, including exploitation attempts, and necessary patches, mitigations, or workarounds, to be included in its Known Exploited Vulnerabilities catalog, according to SecurityWeek.
Vulnerable Linux servers with unpatched Atlassian Confluence Server and Data Center installations have been targeted by numerous botnets, according to BleepingComputer.
London-based security awareness firm CybSafe has pulled in a $28 million investment in a Series B funding round led by Evolution Equity Partners, SecurityWeek reports.
Organizations have been urged by RSA CEO Rohit Ghai to consider identity as a constant in cybersecurity amid evolving threats, according to TechRepublic.
Cybersecurity collaboration between the industry and government has been lacking, with National Cyber Director Chris Inglis noting that such partnership had not been discussed "very well" and Cybersecurity and Infrastructure Security Agency Director Jen Easterly saying that the term had not been tackled when she began serving in the government, CyberScoop reports.
ZDNet reports that cybercriminals have been spending a median dwell time of 15 days inside compromised networks in 2021, compared with 11 days in 2020, indicating a prolonged duration for performing malicious activities without being detected.
VMware ESXi virtual machines on Linux are being targeted by the Black Basta ransomware gang, which has developed new binaries directed at encrypting Linux instances, according to BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.