“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-
3 eye-catching vendor announcements from Black Hat
At Black Hat 2025, some vendors had intriguing acquisitions and announcements in the realms of shadow AI, unmanaged devices and browser security.Read More
-
What is integrated risk management (IRM)?
Integrated risk management (IRM) is a set of proactive, businesswide practices that contribute to an organization’s security, risk tolerance profile and strategic decisions.Read More
-
Credit Karma leader shares AI governance lessons learned
Start slow and break things — that’s how the head of data and AI at the fintech says enterprises should start building AI governance frameworks.Read More
-

Malicious Go, npm Packages Deliver Cross-Platform Malware, Trigger Remote Data Wipes [email protected] (The Hacker News)
Cybersecurity researchers have discovered a set of 11 malicious Go packages that are designed to download additional payloads from remote servers and execute them on both Windows and Linux systems. “At runtime the code silently spawns a shell, pulls a second-stage payload from an interchangeable set of .icu and .tech command-and-control (C2) endpoints, and executes…
-
What is COMSEC (communications security)?
Communications security (COMSEC) is the prevention of unauthorized access to telecommunications traffic or to any written information that is transmitted or transferred.Read More
-
What is the Mitre ATT&CK framework?
The Mitre ATT&CK — pronounced miter attack — framework is a free, globally accessible knowledge base that describes the latest behaviors and tactics of cyberadversaries to help organizations strengthen their cybersecurity strategies.Read More
-

Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups [email protected] (The Hacker News)
Microsoft has released an advisory for a high-severity security flaw affecting on-premise versions of Exchange Server that could allow an attacker to gain elevated privileges under certain conditions. The vulnerability, tracked as CVE-2025-53786, carries a CVSS score of 8.0. Dirk-jan Mollema with Outsider Security has been acknowledged for reporting the bug. “In an Exchange hybrid…
-

6,500 Axis Servers Expose Remoting Protocol, 4,000 in U.S. Vulnerable to Exploits [email protected] (The Hacker News)
Cybersecurity researchers have disclosed multiple security flaws in video surveillance products from Axis Communications that, if successfully exploited, could expose them to takeover attacks. “The attack results in pre-authentication remote code execution on Axis Device Manager, a server used to configure and manage fleets of cameras, and the Axis Camera Station, client software used to…
-

The AI-Powered Security Shift: What 2025 Is Teaching Us About Cloud Defense [email protected] (The Hacker News)
Now that we are well into 2025, cloud attacks are evolving faster than ever and artificial intelligence (AI) is both a weapon and a shield. As AI rapidly changes how enterprises innovate, security teams are now tasked with a triple burden: Secure AI embedded in every part of the business. Use AI to defend faster…
-

SonicWall Confirms Patched Vulnerability Behind Recent VPN Attacks, Not a Zero-Day [email protected] (The Hacker News)
SonicWall has revealed that the recent spike in activity targeting its Gen 7 and newer firewalls with SSL VPN enabled is related to an older, now-patched bug and password reuse. “We now have high confidence that the recent SSL VPN activity is not connected to a zero-day vulnerability,” the company said. “Instead, there is a…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
