Topic: security tools
-
Outcome-based SOC fixes slow teams caused by too many alerts
Attackers are increasingly using stolen credentials and trusted administrative tools like PowerShell to bypass traditional malware, making alert-based detection less effective by generating noise that slows SOC teams. The real bottleneck in security operations is the overwhelming volume of alerts...
Read More » -
Nudge Security automates detection of risky OAuth and browser extensions
Nudge Security has introduced new agentic capabilities to automatically detect and neutralize dangerous OAuth grants and browser extensions, two rapidly growing and hard-to-monitor attack vectors. The platform uses behavioral analysis and continuous monitoring to identify excessive permissions an...
Read More » -
Little Snitch Brings Mac Security Features to Linux
Little Snitch, a major network traffic monitoring tool previously exclusive to macOS, has officially launched a version for Linux systems this week. The Linux version provides core network-monitoring capabilities to visualize and block connections, but is positioned as a utility for visibility an...
Read More » -
AI to Drive 50% of Incident Response by 2028
The rapid deployment of custom AI applications is creating major security vulnerabilities, with over half of enterprise incident response expected to be dedicated to AI-related issues by 2028 due to insufficient testing and established response processes. Security leaders must integrate security ...
Read More » -
Cloud-Audit: Fast, Open-Source AWS Security Scanner
Cloud-audit is an open-source Python CLI tool that provides actionable security findings for AWS, executing 45 curated checks across core services and mapping them to CIS benchmarks. It delivers specific remediation steps for each finding, including AWS CLI commands or Terraform snippets, and can...
Read More » -
Why Password Audits Fail to Protect High-Value Accounts
Traditional password audits focus on compliance and complexity, missing critical risks like breached credentials, orphaned accounts, and over-privileged service accounts. A password can meet all complexity rules yet be dangerously weak if it is reused, follows a predictable pattern, or has alread...
Read More » -
Google Ads Passkeys: New Guide for Secure Sign-In
Google has released a guide for using passkeys to sign into Google Ads accounts, offering a more secure, password-free authentication method to combat account breaches and phishing. The guide details mandatory passkey use for high-sensitivity operations like modifying user permissions and linking...
Read More » -
Shift Left Security Nightmare: Why It's Failing Developers
The "shift left" security model has failed by overburdening developers with security tasks, creating conflict between the need for rapid feature delivery and robust protection. A critical vulnerability stems from the unchecked use of public container registries, where malicious images and exposed...
Read More » -
SmarterTools Breached by Hackers Exploiting Own Software Flaw
The Warlock ransomware gang breached SmarterTools by exploiting an unpatched SmarterMail server, demonstrating how a single overlooked system can compromise an entire network. Attackers used a specific authentication bypass vulnerability to gain access, moved laterally with Windows tools, but wer...
Read More » -
Browser Attacks That EDR, Email, and SASE Can't Stop
The web browser is now the primary workspace for critical business tasks, yet it remains a major security blind spot, creating a dangerous gap between where work happens and where security is focused. Sophisticated attacks exploit this visibility gap by operating entirely within the browser, usin...
Read More » -
Find and Fix Internal Vulnerabilities with Detectify Scanning
Detectify's new Internal Scanning solution extends security testing to private networks, addressing the visibility gap and allowing organizations to efficiently find and fix vulnerabilities in internal applications. The solution uses advanced proprietary technology, including a crawling engine po...
Read More » -
OPNsense 26.1: Major Updates for Open-Source Firewall
OPNsense 26.1, "Witty Woodpecker," introduces major enhancements to firewall management, including a redesigned rules interface and expanded API coverage for deeper automation and programmability. The update adds new threat intelligence and asset visibility features, such as optional Q-Feeds for ...
Read More » -
Patched FortiGate Firewalls Hacked, Cisco RCE Probed
A critical authentication bypass flaw (CVE-2025-59718) persists in Fortinet firewalls despite patches, while Cisco urgently addressed an exploited RCE vulnerability (CVE-2026-20045), highlighting ongoing challenges in securing network infrastructure. Sophisticated phishing targets the energy sect...
Read More » -
Parrot OS Unveils 2026 Roadmap for Security & Platform Upgrades
Parrot OS is a specialized Debian-based Linux distribution for cybersecurity, integrating tools for penetration testing, forensics, malware analysis, and privacy research. The 2026 roadmap focuses on platform upgrades, including enhanced support for lightweight and container-based deployments, an...
Read More » -
CISOs in Survival Mode: Navigating Risk Under Pressure
CISOs face an overwhelming threat environment where most believe a successful breach is inevitable, leading to a focus on rapid response amid frequent, high-impact attacks and low confidence in employee threat detection. Generative AI is a top priority as both a major security risk and a tool for...
Read More » -
Cisco Zero-Day Exploited, Kali Linux 2025.4 Released
A critical zero-day vulnerability in Cisco's email security appliances is being actively exploited by a suspected Chinese-nexus group to compromise devices and erase logs, highlighting urgent patch management needs. Major vendors like Fortinet, SonicWall, and Apple are addressing serious, activel...
Read More » -
Master NIS2 Compliance: Secure Passwords & MFA
The NIS2 Directive is a critical EU regulation requiring medium and large organizations in key sectors to implement stringent security controls, with a major focus on robust identity and access management to combat credential-based attacks. Compliance is mandatory for qualifying organizations, an...
Read More » -
Google's Dark Web Report Feature Discontinued in February
Google will retire its dark web monitoring tool in February 2026, citing user feedback that the alerts lacked actionable next steps for addressing data exposures. The tool, which scanned for personal information in data breaches, is being replaced by integrated security features like Security Che...
Read More » -
NCSC Playbook: Embedding Cyber Essentials in Supply Chains
UK authorities are urging businesses to strengthen supply chain security by integrating the Cyber Essentials certification into procurement, supported by a new NCSC playbook and a Supplier Check tool for verification. The initiative addresses significant risk, as only 14% of firms fully understan...
Read More » -
Terra Security Launches Continuous Exploitability Validation for CTEM
Terra Security has launched a continuous exploitability validation solution to help organizations determine if detected vulnerabilities are actually exploitable within their unique, live environments, moving beyond simple detection. A key challenge is that traditional security tools often fail to...
Read More »