In the leadership and communications section: Do You Really Need a CISO?, A CISO Employment Contract May Mean the Difference Between Success and Jail, When Your Employee Tells You They’re Burned Out, and more!
New TLDs are already old news, fuzzing eBPF validators, Microsoft sets to kill bug classes, draft RFC to track location trackers, a top ten list with directory traversal on it, conference videos from Real World Crypto and BSidesSF, and an attack tree generator from markdown.
The OWASP Top 10 dates back to 2003, when appsec was just settling on terms like cross-site scripting and SQL injection. It's a list that everyone knows about and everyone talks about. But is it still the right model for modern appsec awareness? What if we put that attention and effort elsewhere? Maybe we could have secure defaults instead. Or lint...
Sixty-eight percent of chief information security officers worldwide reported feeling that their organizations would be impacted by a cyberattack within the next year, up from 48% of CISOs who expressed such concern last year, reports TechRepublic.
The Biden administration has been urged by Cyberspace Solarium Commission co-chairs Sen. Angus King, I-Maine, and Rep. Mike Gallagher, R-Wis., to immediately nominate Acting National Cyber Director Kemba Walden to the national cyber director post following the resignation of Chris Inglis in an effort to prevent delays in national cybersecurity strategy adoption, reports The Hill.
Senate bill proposes creating a rural hospital cybersecurity workforce development plan to address healthcare gaps in finding and retaining skilled cyber professionals.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.