Production data in testing is still common, and Tricentis’ CISO wants it gone
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the…
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the…
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while…
July saw ransomware attacks reach a peak of 894 recorded attacks, hitting the highest level seen so far this year, up almost a quarter on…
The Internet Architecture Board (IAB) says it is concerned that age assurance approaches that rely on service provider checks will not only fail, but also…
Multi-factor authentication (MFA) has become one of cybersecurity’s most important controls. Roughly 70% of enterprise workforce users are now protected by it. But its success…
CISA Red Team Fully Compromised Two Critical Infrastructure Orgs Pierluigi Paganini August 26, 2026 CISA red teams fully compromised two critical infrastructure orgs. One SOC…
Federal authorities Wednesday revealed a multi-layered Chinese state-sponsored espionage operation that’s targeted and compromised U.S. critical infrastructure, including multiple federal agencies, since 2018. Officials seized…
The Justice Department and the FBI said on Wednesday that they seized two Chinese state-sponsored online platforms that targeted US critical infrastructure and other critical…
Protecting identities in the cloud is paramount to ensuring the security and integrity of your data and resources. Misconfigured identities or identity-related risks can create…
At Elastic, we know that the best way to build security tools is to bring them to the community, have security pros use them, and…
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the…
Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF images. The first flaw, tracked…