
Insider threats and the misuse of privileged credentials
35% of IT professionals see themselves as the biggest internal security risk to networks within their organisation, according to new research from Balabit. Biggest insider …

Is your mainframe security GDPR compliant?
Only one in four IBM mainframe customers questioned in a new UK survey are confident that their system security complies with the incoming General Data Protection Regulation …

Week in review: DevOps security, macOS root password bug, and the evil of vanity metrics
Here’s an overview of some of last week’s most interesting news and articles: Stealthy in-browser cryptomining continues even after you close window Hackers are …

How secure are cryptocurrency mobile apps?
Are the mobile apps you’re using to store or handle your cryptocurrency stash, track the currencies’ price, or interact with cryptocurrency exchanges secure? …

BSidesLjubljana 0x7E2 CFP is now open!
BSidesLjubljana 0x7E2, taking place on March 10th 2018, is looking for speakers, sponsors and everyone in between. This is an amazing community-focused event, led by a group …

New infosec products of the week: December 1, 2017
Automated security and compliance solution for Docker containers CloudPassage unveiled Container Secure, a set of automated compliance and security controls for containers. …

Credit card fraud down 29% for the first time
Iovation released data collected from its retail and e-commerce subscribers from the 2017 holiday weekend (Nov. 24 – 27, 2017). For the first time in recent years, …

How organizations across industries create and manage policies
MetricStream evaluated 260+ organizations across 15 industries to understand the ways in which organizations create, manage, and communicate policies, the challenges they …

Stealthy in-browser cryptomining continues even after you close window
In-browser cryptocurrency mining is, in theory, a neat idea: make users’ computers “mine” Monero for website owners so they don’t have to bombard users …

UK shipbroker Clarksons refuses to pay hackers ransom for stolen data
London-based shipbroking firm Clarksons has suffered a data breach and refuses to pay the attackers to prevent the stolen data from being publicly released. About the …

Richard Ford: A physicist’s strange journey to become an infosec scientist
Many of today’s information security professionals started their path towards a career in the industry by becoming frustrated gamers. Richard Ford, Chief Scientist at …

Triggered via malicious files, flaws in Cisco WebEx players can lead to RCE
Cisco has plugged six security holes in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files that could be exploited …
Featured news
Resources
Don't miss
- Building a healthcare cybersecurity strategy that works
- AI-generated images have a problem of credibility, not creativity
- The five-minute guide to OT cyber resilience
- Another remotely exploitable Oracle EBS vulnerability requires your attention (CVE-2025-61884)
- Apple offers $2 million for zero-click exploit chains