Topic: security tools

  • Outcome-based SOC fixes slow teams caused by too many alerts

    Outcome-based SOC fixes slow teams caused by too many alerts

    Attackers are increasingly using stolen credentials and trusted administrative tools like PowerShell to bypass traditional malware, making alert-based detection less effective by generating noise that slows SOC teams. The real bottleneck in security operations is the overwhelming volume of alerts...

    Read More »
  • Nudge Security automates detection of risky OAuth and browser extensions

    Nudge Security automates detection of risky OAuth and browser extensions

    Nudge Security has introduced new agentic capabilities to automatically detect and neutralize dangerous OAuth grants and browser extensions, two rapidly growing and hard-to-monitor attack vectors. The platform uses behavioral analysis and continuous monitoring to identify excessive permissions an...

    Read More »
  • Little Snitch Brings Mac Security Features to Linux

    Little Snitch Brings Mac Security Features to Linux

    Little Snitch, a major network traffic monitoring tool previously exclusive to macOS, has officially launched a version for Linux systems this week. The Linux version provides core network-monitoring capabilities to visualize and block connections, but is positioned as a utility for visibility an...

    Read More »
  • AI to Drive 50% of Incident Response by 2028

    AI to Drive 50% of Incident Response by 2028

    The rapid deployment of custom AI applications is creating major security vulnerabilities, with over half of enterprise incident response expected to be dedicated to AI-related issues by 2028 due to insufficient testing and established response processes. Security leaders must integrate security ...

    Read More »
  • Cloud-Audit: Fast, Open-Source AWS Security Scanner

    Cloud-Audit: Fast, Open-Source AWS Security Scanner

    Cloud-audit is an open-source Python CLI tool that provides actionable security findings for AWS, executing 45 curated checks across core services and mapping them to CIS benchmarks. It delivers specific remediation steps for each finding, including AWS CLI commands or Terraform snippets, and can...

    Read More »
  • Why Password Audits Fail to Protect High-Value Accounts

    Why Password Audits Fail to Protect High-Value Accounts

    Traditional password audits focus on compliance and complexity, missing critical risks like breached credentials, orphaned accounts, and over-privileged service accounts. A password can meet all complexity rules yet be dangerously weak if it is reused, follows a predictable pattern, or has alread...

    Read More »
  • Google Ads Passkeys: New Guide for Secure Sign-In

    Google Ads Passkeys: New Guide for Secure Sign-In

    Google has released a guide for using passkeys to sign into Google Ads accounts, offering a more secure, password-free authentication method to combat account breaches and phishing. The guide details mandatory passkey use for high-sensitivity operations like modifying user permissions and linking...

    Read More »
  • Shift Left Security Nightmare: Why It's Failing Developers

    Shift Left Security Nightmare: Why It's Failing Developers

    The "shift left" security model has failed by overburdening developers with security tasks, creating conflict between the need for rapid feature delivery and robust protection. A critical vulnerability stems from the unchecked use of public container registries, where malicious images and exposed...

    Read More »
  • SmarterTools Breached by Hackers Exploiting Own Software Flaw

    SmarterTools Breached by Hackers Exploiting Own Software Flaw

    The Warlock ransomware gang breached SmarterTools by exploiting an unpatched SmarterMail server, demonstrating how a single overlooked system can compromise an entire network. Attackers used a specific authentication bypass vulnerability to gain access, moved laterally with Windows tools, but wer...

    Read More »
  • Browser Attacks That EDR, Email, and SASE Can't Stop

    Browser Attacks That EDR, Email, and SASE Can't Stop

    The web browser is now the primary workspace for critical business tasks, yet it remains a major security blind spot, creating a dangerous gap between where work happens and where security is focused. Sophisticated attacks exploit this visibility gap by operating entirely within the browser, usin...

    Read More »
  • Find and Fix Internal Vulnerabilities with Detectify Scanning

    Find and Fix Internal Vulnerabilities with Detectify Scanning

    Detectify's new Internal Scanning solution extends security testing to private networks, addressing the visibility gap and allowing organizations to efficiently find and fix vulnerabilities in internal applications. The solution uses advanced proprietary technology, including a crawling engine po...

    Read More »
  • OPNsense 26.1: Major Updates for Open-Source Firewall

    OPNsense 26.1: Major Updates for Open-Source Firewall

    OPNsense 26.1, "Witty Woodpecker," introduces major enhancements to firewall management, including a redesigned rules interface and expanded API coverage for deeper automation and programmability. The update adds new threat intelligence and asset visibility features, such as optional Q-Feeds for ...

    Read More »
  • Patched FortiGate Firewalls Hacked, Cisco RCE Probed

    Patched FortiGate Firewalls Hacked, Cisco RCE Probed

    A critical authentication bypass flaw (CVE-2025-59718) persists in Fortinet firewalls despite patches, while Cisco urgently addressed an exploited RCE vulnerability (CVE-2026-20045), highlighting ongoing challenges in securing network infrastructure. Sophisticated phishing targets the energy sect...

    Read More »
  • Parrot OS Unveils 2026 Roadmap for Security & Platform Upgrades

    Parrot OS Unveils 2026 Roadmap for Security & Platform Upgrades

    Parrot OS is a specialized Debian-based Linux distribution for cybersecurity, integrating tools for penetration testing, forensics, malware analysis, and privacy research. The 2026 roadmap focuses on platform upgrades, including enhanced support for lightweight and container-based deployments, an...

    Read More »
  • CISOs in Survival Mode: Navigating Risk Under Pressure

    CISOs in Survival Mode: Navigating Risk Under Pressure

    CISOs face an overwhelming threat environment where most believe a successful breach is inevitable, leading to a focus on rapid response amid frequent, high-impact attacks and low confidence in employee threat detection. Generative AI is a top priority as both a major security risk and a tool for...

    Read More »
  • Cisco Zero-Day Exploited, Kali Linux 2025.4 Released

    Cisco Zero-Day Exploited, Kali Linux 2025.4 Released

    A critical zero-day vulnerability in Cisco's email security appliances is being actively exploited by a suspected Chinese-nexus group to compromise devices and erase logs, highlighting urgent patch management needs. Major vendors like Fortinet, SonicWall, and Apple are addressing serious, activel...

    Read More »
  • Master NIS2 Compliance: Secure Passwords & MFA

    Master NIS2 Compliance: Secure Passwords & MFA

    The NIS2 Directive is a critical EU regulation requiring medium and large organizations in key sectors to implement stringent security controls, with a major focus on robust identity and access management to combat credential-based attacks. Compliance is mandatory for qualifying organizations, an...

    Read More »
  • Google's Dark Web Report Feature Discontinued in February

    Google's Dark Web Report Feature Discontinued in February

    Google will retire its dark web monitoring tool in February 2026, citing user feedback that the alerts lacked actionable next steps for addressing data exposures. The tool, which scanned for personal information in data breaches, is being replaced by integrated security features like Security Che...

    Read More »
  • NCSC Playbook: Embedding Cyber Essentials in Supply Chains

    NCSC Playbook: Embedding Cyber Essentials in Supply Chains

    UK authorities are urging businesses to strengthen supply chain security by integrating the Cyber Essentials certification into procurement, supported by a new NCSC playbook and a Supplier Check tool for verification. The initiative addresses significant risk, as only 14% of firms fully understan...

    Read More »
  • Terra Security Launches Continuous Exploitability Validation for CTEM

    Terra Security Launches Continuous Exploitability Validation for CTEM

    Terra Security has launched a continuous exploitability validation solution to help organizations determine if detected vulnerabilities are actually exploitable within their unique, live environments, moving beyond simple detection. A key challenge is that traditional security tools often fail to...

    Read More »