Cybersecurity

Threat Actors Increasingly Abusing GitHub for Malicious Purposes

Jan 11, 2024NewsroomCybersecurity / Software Security The ubiquity of GitHub in information technology (IT) environments has made it a lucrative choice for threat actors to host and deliver malicious payloads and act as dead drop resolvers, command-and-control, and data exfiltration points. “Using GitHub services for malicious infrastructure allows adversaries to blend in with legitimate network […]

Cybersecurity

anecdotes Raises $25M in Series B Funding

anecdotes, a Palo Alto, CA-based enterprise GRC (Governance, Risk and Compliance) technology company, raised $25M in Series B funding. The round was led by Glilot Capital Partners, with participation from existing investors Red Dot Capital Partners, Vintage Investment Partners, and Shasta Ventures, with participation from Vertex and DTCP. The company intends to use the funds […]

Cybersecurity

NIST Warns of Security and Privacy Risks from Rapid AI System Deployment

Jan 08, 2024NewsroomArtificial Intelligence / Cyber Security The U.S. National Institute of Standards and Technology (NIST) is calling attention to the privacy and security challenges that arise as a result of increased deployment of artificial intelligence (AI) systems in recent years. “These security and privacy challenges include the potential for adversarial manipulation of training data, […]

Cybersecurity

5 Ways to Reduce SaaS Security Risks

As technology adoption has shifted to be employee-led, just in time, and from any location or device, IT and security teams have found themselves contending with an ever-sprawling SaaS attack surface, much of which is often unknown or unmanaged. This greatly increases the risk of identity-based threats, and according to a recent report from CrowdStrike, […]

Cybersecurity

China’s MIIT Introduces Color-Coded Action Plan for Data Security Incidents

Dec 16, 2023NewsroomCyber Security / Incident Response China’s Ministry of Industry and Information Technology (MIIT) on Friday unveiled draft proposals detailing its plans to tackle data security events in the country using a color-coded system. The effort is designed to “improve the comprehensive response capacity for data security incidents, to ensure timely and effective control, […]

Cybersecurity

Security automation gains traction, prompting a “shift everywhere” philosophy – Help Net Security

The use of automated security technology is growing rapidly, which in turn is propagating the “shift everywhere” philosophy – performing security tests throughout the entire software development life cycle – across more organizations, according to Synopsys. This year’s findings revealed a clear trend of firms increasingly taking advantage of security automation to replace manual, subject […]