CSO

The day's top cybersecurity news and in-depth coverage

CSO First Look

October 06, 2021

Iranian APT targets aerospace and telecom firms with stealthy ShellClient Trojan

The MalKamak group has been running its Operation GhostShell campaign for at least three years unnoticed. Read more ▶

Image: Sponsored by Jamf: Come for the InfoSec insight. Stay for the camaraderie.

Sponsored by Jamf: Come for the InfoSec insight. Stay for the camaraderie.

Starting October 19, the world's largest rally of Apple IT, users and InfoSec leaders will attend Virtual JNUC to find new and better ways to connect, manage and protect their organization's Apple devices through product demos, deep-dive info sessions, and community camaraderie. Get your spot now!

Microsoft Exchange Emergency Mitigation: What admins need to know

The Emergency Mitigation service adds protections to Exchange Server in the wake of recent zero-day compromises.

One Identity acquires OneLogin in bid to offer consolidated IAM suite

In a move to offer its customers a consolidated suite of security applications, One Identity has acquired OneLogin, an IAM (identity and access management) provider, adding to its own set of PAM (privileged access management, IGA (identity governance and administration), and ADMS (active directory management and security) applications.

Image: 5 steps toward real zero trust security

5 steps toward real zero trust security

Looking to advance in your zero trust journey? These steps will keep your strategy on track.

How corporate data and secrets leak from GitHub repositories

Attackers constantly search public code repositories like GitHub for secrets developers might inadvertently leave behind, and any tiny mistake can be exploited.

FCC asks carriers to step up to stop SIM swapping, port-out fraud

The US federal agency puts pressure on telecom carriers to put better authentication, account protection safeguards in place.

Device identity: The overlooked insider threat

Device/machine identity, especially in association with robotic process automation, can be a conduit for intentional and unintentional insider breaches.

Why today’s cybersecurity threats are more dangerous

Greater complexity and interdependence among systems gives attackers more opportunity for widespread, global damage, say government and industry experts.

CSO
Facebook Twitter LinkedIn
© 2021 CSO
140 Kendrick Street, Building B
Needham, MA 02494