A recent upgrade to the RansomHouse ransomware operation has added new concerns for enterprise defenders, introducing a multi-layered encryption update to the…
News
Hackers exploit Microsoft OAuth device codes to hijack enterprise accounts
Cybercriminals and state-sponsored hackers are increasingly exploiting Microsoft’s legitimate OAuth 2.0 device authorization process to hijack enterprise accounts, bypassing multifactor authentication protections…
What CISOs should know about the SolarWinds lawsuit dismissal
The US Securities and Exchange Commission’s Nov. 30 decision to dismiss its lawsuit against SolarWinds and its CISO, Tim Brown, was met…
Iranian APT Prince of Persia returns with new malware and C2 infrastructure
Researchers have discovered new activity from a threat actor dubbed Prince of Persia that’s believed to be tied to the Iranian government….
Identity Management and Information Security News for the Week of December 19th: 1Kosmos, Prove, Opal Security, and More
The editors at Solutions Review have curated this list of the most noteworthy Identity Management and Information Security news from the week…
How to Stop Identity Fraud Before It Starts: Building Trust in a Synthetic World
Patrick Harding, Chief Product Architect at Ping Identity, explains how companies can prevent identity fraud before it occurs. This article originally appeared in Insight Jam,…
WatchGuard fixes ‘critical’ zero-day allowing firewall takeover
WatchGuard has issued an urgent patch alert for its Firebox firewall appliances after discovering a critical-rated vulnerability that is under exploit by…
Attackers bring their own passwords to Cisco and Palo Alto VPNs
Security researchers have flagged a coordinated credential-based campaign targeting VPN authentication endpoints from Cisco and Palo Alto Networks. Over just two days…
Cisco bestätigt Zero-Day-Exploit für Secure Email
Cisco hat eine Zero-Day-Lücke in seinen Secure-Email-Produkten entdeckt. JarTee – shutterstock.com Cisco Talos hat kürzlich eine Cyberkampagne entdeckt, die auf Ciscos AsyncOS-Software…
Managing agentic AI risk: Lessons from the OWASP Top 10
LLM-powered chatbots have risks that we see playing out in the headlines on a nearly daily basis. But chatbots are limited to…