14 May

Metal maker meltdown: Nucor stops production after cyber-intrusion

Nucor, the largest steel manufacturer in the US, shut down production operations after discovering its servers had been penetrated. In a Tuesday 8-K filing to

Author rabih
14 May

Why CVSS is failing us and what we can do about it

Partner content Two decades ago, CVSS revolutionized vulnerability management, enabling security teams to speak a common language when measuring and prioritizing risks posed by the

Author rabih
14 May

Uncle Sam pulls $2.4B Leidos deal to support CISA after rival alleges foul play

The Department of Homeland Security (DHS) scrapped a highly lucrative cybersecurity contract originally awarded to Leidos following a legal challenge from rival bidder Nightwing, yet

Author rabih
14 May

Ivanti patches two zero-days under active attack as intel agency warns customers

Australia’s intelligence agency is warning organizations about several new Ivanti zero-days chained for remote code execution (RCE) attacks. The vendor itself has said the vulns

Author rabih
14 May

Meta’s still violating GDPR rules with latest plan to train AI on EU user data, says noyb

There’s a Max Schrems-shaped object standing in the way of Meta’s plans to train its AI on the data of its European users, and he’s

Author rabih
14 May

VPN Secure parent company CEO explains why he had to axe thousands of ‘lifetime’ deals

Customers are blasting VPN Secure’s new parent company after it abruptly axed thousands of “lifetime” accounts. The reason? The CEO admits in an interview with

Author rabih
14 May

Go ahead and ignore Patch Tuesday – it might improve your security

Patch Tuesday has rolled around again, but if you don’t rush to implement the feast of fixes it delivered, your security won’t be any worse

Author rabih
14 May

Everyone’s deploying AI, but no one’s securing it – what could go wrong?

CYBERUK Peter Garraghan – CEO of Mindgard and professor of distributed systems at Lancaster University – asked the CYBERUK audience for a show of hands:

Author rabih
14 May

Ransomware scum have put a target on the no man’s land between IT and operations

Criminals who attempt to damage critical infrastructure are increasingly targeting the systems that sit between IT and operational tech. These in-between systems are no man’s

Author rabih
14 May

Apple patched one first, but Microsoft’s blasted five exploited flaws this Pa-Tu

Patch Tuesday It’s that time of the month again, and Microsoft has made it extra spicy by revealing five flaws it says are under active

Author rabih
13 May

Intel’s data-leaking Spectre defenses scared off yet again

Researchers at ETH Zurich in Switzerland have found a way around Intel’s defenses against Spectre, a family of data-leaking flaws in the x86 giant’s processor

Author rabih
13 May

Qatar’s $400M jet for Trump is a gold-plated security nightmare

The Trump administration is set to accept a $400 million luxury 747-8 from the royal family of Qatar – a lavish “palace in the sky”

Author rabih
13 May

Commvault fixes critical Command Center issue after flaw finder alert

An update that fixed a critical flaw in data protection biz Commvault’s Command Center was initially not available to a significant user subset – those

Author rabih
13 May

‘We still have embeds in CISA’: CTO of Brit cyber agency talks post-Trump relationship with US counterpart

CYBERUK The top brass from the UK’s cyber agency say everything is business as usual when it comes to the GCHQ arm’s relationship with CISA,

Author rabih
13 May

Five Years Later: Evolving IoT Cybersecurity Guidelines

The Background…and NIST’s Plan for Improving IoT Cybersecurity The passage of the Internet of Things (IoT) Cybersecurity Improvement Act in 2020 marked a pivotal step

Author rabih
13 May

Marks & Spencer admits cybercrooks made off with customer info

Marks & Spencer has confirmed that customer data was stolen as part of its cyberattack, fueling conjecture that ransomware was involved. The retail giant’s operations

Author rabih
13 May

As US vuln-tracking falters, EU enters with its own security bug database

The European Vulnerability Database (EUVD) is now fully operational, offering a streamlined platform to monitor critical and actively exploited security flaws amid the US struggles

Author rabih
13 May

Türkiye-linked spy crew exploited a messaging app zero-day to snoop on Kurdish army in Iraq

Turkish spies exploited a zero-day bug in a messaging app to collect info on the Kurdish army in Iraq, according to Microsoft, which says the

Author rabih
Load moreLoadingAll items loaded