Threat actor exploits critical Citrix vulnerability

Dive Brief: Federal cyber authorities on Tuesday urged organizations to patch a critical vulnerability in Citrix ADC (application delivery controller) and Citrix Gateway. The remote code execution vulnerability, CVE-2022-27518, is being actively exploited in the wild, Citrix said in a security update. It has a CVSS score of 9.8.  The National Security Agency issued a […]

Continue Reading

Threat actors abuse legitimate Microsoft drivers to bypass security

Dive Brief: Prominent threat actors have abused legitimately signed Microsoft drivers to bypass traditional endpoint security and launch attacks against organizations in several key industries, according to research from SentinelOne and Mandiant. Researchers discovered Poortry and Stonestop malware, which are part of small toolkits that can shut down antivirus and endpoint detection and response (EDR) […]

Continue Reading

CISOs are becoming more technical

Dive Brief: CISOs with graduate degrees in science, technology, engineering and math (STEM) outnumber those with an advanced degree in business administration or management for the first time this year, according to a Marlin Hawk report published on Tuesday. More than 3 in 5 CISOs at large enterprises have earned a STEM advanced degree, reflecting […]

Continue Reading

Rackspace blames ransomware attack on financially motivated threat actor

Dive Brief: Rackspace Technology confirmed that a financially motivated threat actor was behind the Dec. 2 ransomware attack, which disrupted email service to thousands of customers that use its Hosted Exchange service, the company said in an update Wednesday evening. The cloud services provider said the investigation by cybersecurity firm CrowdStrike and other cybersecurity experts, along […]

Continue Reading

NIST bids adieu to SHA-1 cryptographic algorithm

A cryptographic algorithm standard first published almost 30 years ago has reached the end of the road, the National Institute of Standards and Technology said Thursday. While NIST reemphasized the need for anyone relying on secure hash algorithm (SHA-1) for security to migrate to newer and more advanced algorithms in SHA-2 or SHA-3, the issue […]

Continue Reading

Little Rock School District approves $250K payment in ransomware settlement

Listen to the article 4 min This audio is auto-generated. Please let us know if you have feedback. Dive Brief: While trying to retrieve stolen data from its network, the Little Rock School District’s board voted 6-3 on Dec. 5 to approve a $250,000 settlement that would end a recent ransomware incident. An LRSD school […]

Continue Reading

Incident responders brace for end-of-year cyber scaries

While many professionals might approach the end of a year as a time for pause and reflection, setting goals for the new year or at least some respite, cybersecurity professionals can’t shake the premonition that something bad is about to occur. It’s no wonder why. Blame the SolarWinds attack discovered in December 2020 and the […]

Continue Reading

Remote work, quality of life lure tech workers away from traditional hubs

Listen to the article 5 min This audio is auto-generated. Please let us know if you have feedback. The tech workforce is shifting away from familiar hubs and toward cities that haven’t traditionally been viewed as innovation hotbeds. Houston, Detroit, and Orlando, Florida, are three cities with the fastest growing tech workforces this year, according […]

Continue Reading

How tech companies make IT purchasing decisions

Listen to the article 3 min This audio is auto-generated. Please let us know if you have feedback. Dive Brief: When companies weigh IT purchases, improving efficiency, productivity and profitability are the top priorities, according to a recent report by Forrester that surveyed 2,000 technology buyers at high-tech companies. Keeping business running, revenue growth and […]

Continue Reading

Salesforce launches DevOps Center, blending low code and collaboration

Listen to the article 3 min This audio is auto-generated. Please let us know if you have feedback. Dive Brief: Salesforce made its DevOps Center available to the general public Thursday following months under beta testing. The product aims to accelerate development and shorten release cycles by making it easier to build, test and deploy […]

Continue Reading