Duncan Riley
Latest from Duncan Riley
A new report from enterprise domain registrar CSC finds that despite the rapid rise of artificial intelligence, many of the Forbes Global 2000 do not control their .AI domain names or have not registered a .AI domain name for their business. The finding …
Sophos-Boise State collaboration takes aim at the growing cybersecurity skills gap
Cybersecurity firm Sophos Group plc today announced a new partnership with Boise State University’s Insitute for Pervasive Security to provide Boise State University access to Sophos’ endpoint security offerings to create experiential learning opportunities for students and assist in addressing the worldwide cybersecurity skill gap. The …
BackBox introduces Network Vulnerability Manager to enhance network automation
Network automation platform startup BackBox Software Inc. today announced the launch of Network Vulnerability Manager, a new service that offers deep integration with vulnerability management for network teams. The new NVM, which is offered alongside BackBox’s existing Network Automation Platform, integrates automated …
Phishing attacks hit record high in third quarter, with malware not far behind
A new report from threat detection and response startup Vade Secure SASU finds a substantial increase in phishing and malware attacks in the third quarter, so large that the level of attacks is some of the highest ever recorded for any quarter. The Vade …
Critical Atlassian Confluence flaw with vulnerability score of 10 draws federal warning
The U.S. Cybersecurity and Infrastructure Agency, the Federal Bureau of Investigation and the Multi-State Information Sharing and Analysis Center today released a Cybersecurity Advisory over a recently disclosed vulnerability in Atlassian Corp.’s Confluence Data Center and Server that opens the door to malicious …
Cisco warns customers of actively exploited critical vulnerability in IOS XE devices
Cisco Systems Inc. is warning customers of its IOS XE devices of a critical vulnerability that has no patch and is actively being exploited in the wild. The vulnerability, tracked as CVE-2023-20198, has been given the highest possible Common Vulnerabilities and Exposure score …
New repository aims to illuminate open-source package vulnerabilities and malicious code
The Open Source Security Foundation today launched its Malicious Packages Repository, an open-source system for collecting and publishing cross-ecosystem reports of malicious packages. Claimed to be the first open-source system of its type, the repository was created in response to the rising …
Nightfall AI and Snyk partner to provide AI-powered secrets scanning to developers
Cloud data protection startup Nightfall AI today announced a new partnership with cybersecurity company Snyk Ltd. to provide developers with artificial intelligence-powered secrets scanning capabilities. Secrets, in terms of what Nightfall scans for, are passwords, application programming interface keys, token and database credentials used by …
Semperis adds Microsoft Entra ID support to its attack path management tool
Enterprise identity protection and cyber resilience startup Semperis Ltd. today announced the expansion of Forest Druid, its community-driven attack path management tool, to include support for Microsoft Entra ID, the service previously known as Azure AD. The additional support, coming after the company added …
Google issues new cybersecurity updates and initiatives
In commemoration of the 20th anniversary of Cybersecurity Awareness Month, Google LLC today introduced various updates and initiatives to enhance cybersecurity and ensure user-friendly online experiences. Cybersecurity Awareness Month was created in 2004 as a collaborative effort between the U.S. government and …