The disclosure of the SolarWinds attack by FireEye is encouraging for the development of a national data breach reporting law, government and private-sector experts say.
With the cyber workforce gap looming, security hiring managers are looking in unconventional places and tweaking their job descriptions to appeal to candidates with "soft skills."
The SolarWinds breach, ransomware epidemic and other threats have emphasized the urgent need for more resilient systems.
A 5G threat vector analysis by several federal agencies pointed to existing legacy infrastructure deployment weaknesses and supply-chain security challenges.
CISA and other federal agencies are expanding their incident response capacities, but there is discussion of tapping into private sector resources during major incidents.
The Transparent Tribe APT has evolved its lures, expanded its victimology and added a new malware family to its arsenal.
The executive order makes widespread mandates addressing software supply-chain security and outdated security models.
The attack on Colonial Pipeline has focused the attention of the FBI and White House on the DarkSide ransomware developers and its operators.
A set of implementation and design flaws have been uncovered in the 802.11 standard that underpins Wi-Fi.
Lindsey O'Donnell-Welch talks to Ken Munro with Pen Test Partners about the biggest challenges around securing Internet of Things devices, and how regulatory efforts and consumer awareness are beginning to have a positive impact on the IoT security landscape.
Overall, Microsoft patched 55 flaws, including four critical-severity remote code execution bugs.
The DarkSide ransomware hit the Colonial Pipeline on Friday, forcing the company to take its main distribution lines offline to recover.
The Lemon Duck cryptocurrency-mining botnet was seen behind a spike of April attacks exploiting the Microsoft Exchange server ProxyLogon flaw.
Google Project Zero's recent tweaking of its vulnerability disclosure window reflects how researchers are taking into account patch adoption when mulling disclosure policies.
The newly disclosed Moriya rootkit has been used since at least 2018 in a campaign targeting large regional diplomatic organizations in Asia and Africa.