news Archive

Cloud Security, DevOps, AppSec – The Week’s Best News – 2021.03.24

A Review of the Best News of the Week on Cloud Security, DevOps, AppSec New Malware Hidden in Apple IDE Targets macOS Developers (Dark Reading:, Mar 19 2021) XcodeSpy is latest example of growing attacks on software supply chain. Researchers Discover Two Dozen Malicious Chrome Extensions (Dark Reading:, Mar 22

Threats & Defense – The Week’s Best News – 2021.03.22

A Review of the Best News of the Week on Cyber Threats & Defense Microsoft One-Click Tool Mitigates Exchange Server Attacks (Infosecurity Magazine, Mar 16 2021) Tool designed for customers without dedicated IT or cybersecurity resource Exploiting Spectre Over the Internet (Schneier on Security, Mar 18 2021) “Google has demonstrated

15 Bullet Friday – The Best Security News of the Week – 2021.03.19

The Top 15 Security Posts – Vetted & Curated *Threats & Defense* 1. Microsoft Reports ‘DearCry’ Ransomware Targeting Exchange Servers (Dark Reading:, Mar 12 2021) Attackers have begun to deploy ransomware on Microsoft Exchange Servers compromised by the ProxyLogon exploits. 2. New Side-Channel Attack Targets Intel CPU Ring Interconnect (SecurityWeek,

CISO View – The Week’s Best News – 2021.03.19

A Review of the Best News of the Week on Cybersecurity Management & Strategy Illegal Content and the Blockchain (Schneier on Security, Mar 17 2021) “This openness is also a vulnerability, one that opens the door to asymmetric threats and small-time malicious actors. Anyone can put information in the one

Identity Mgt & Web Fraud – The Week’s Best News – 2021.03.18

A Review of the Best News of the Week on Identity Management & Web Fraud Twitter Updates 2FA Use of Multiple Security Keys (Infosecurity Magazine, Mar 16 2021) Users will soon be able to use security keys as sole authentication method Netflix’s Password-Sharing Crackdown Has a Silver Lining (Wired, Mar

Cloud Security, DevOps, AppSec – The Week’s Best News – 2021.03.17

A Review of the Best News of the Week on Cloud Security, DevOps, AppSec Mimecast says SolarWinds hackers breached its network (Ars Technica, Mar 16 2021) Mimecast-issued certificate used to connect to customers’ Microsoft 365 tenants. Validate access to your S3 buckets before deploying permissions changes with IAM Access Analyzer

Threats & Defense – The Week’s Best News – 2021.03.15

A Review of the Best News of the Week on Cyber Threats & Defense Microsoft Reports ‘DearCry’ Ransomware Targeting Exchange Servers (Dark Reading:, Mar 12 2021) Attackers have begun to deploy ransomware on Microsoft Exchange Servers compromised by the ProxyLogon exploits. New Side-Channel Attack Targets Intel CPU Ring Interconnect (SecurityWeek,