CSO

The day's top cybersecurity news and in-depth coverage

CSO First Look

August 26, 2022

New ransomware HavanaCrypt poses as Google software update

The HavanaCrypt ransomware has data exfiltration capabilities and goes to great lengths to avoid analysis. Read more ▶

Image: DNS data indicates increased malicious domain activity, phishing toolkit reuse

DNS data indicates increased malicious domain activity, phishing toolkit reuse

Akamai research discovers phishing toolkit reuse played a key role in increased malicious domain activity in the second quarter of 2022.

Up to 35% more CVEs published so far this year compared to 2021

A new report shows that significantly more CVEs will be published this year, and that some organizations are still vulnerable from older, unpatched CVEs.

How 2023 cybersecurity budget allocations are shaping up

Security spending is not expected to slow much next year as organizations look to improve cloud defenses, rely more on MSSPs.

Image: Sophisticated BEC scammers bypass Microsoft 365 multi-factor authentication

Sophisticated BEC scammers bypass Microsoft 365 multi-factor authentication

Analysis of the BEC campaign reveal weaknesses in Microsoft's authentication system.

Why SBOMs alone aren’t enough for software supply chain security

Organizations must be willing to ask software vendors hard risk-based questions and be prepared for that to lengthen the purchase process.

Security Recruiter Directory

To find the right security job or hire the right candidate, you first need to find the right recruiter. CSO's security recruiter directory is your one-stop shop.

CSO
Facebook Twitter LinkedIn
© 2022 CSO
140 Kendrick Street, Building B
Needham, MA 02494