Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Security

ISO 27001 Lead Implementer vs Auditor: What's the Difference?

In the process of securing a business and achieving a full certification with ISO 27001, there are many different tasks that need to be accomplished, and many different people who need to be working towards achieving those tasks. In fact, a key part of a successful certification and a passing audit is accountability. Different people will need to take on different roles and responsibilities, some of which are for the purposes of the audit, and others for ongoing security.

Fidelis Elevate (XDR): A Proactive Way to Eliminate Blind Spots

The growing complexity of IT environments—across cloud, IoT, and hybrid settings—has ushered in new opportunities for innovation but also expanded the threat landscape for cyber vulnerabilities. These vulnerabilities, now known as blind spots, serve as areas within an organization’s security posture that are ignored or poorly monitored.

CyberArk + Wiz: Securing the Cloud, One Identity at a Time

Discover how CyberArk and Wiz are revolutionizing cloud security! In this exclusive interview with Information Security Media Group, CyberArk Chief Strategy Officer Clarence Hinton and Wiz Vice President of Product Extensibility & Partnerships Oron Noah discuss how their partnership addresses critical cloud challenges: Key Highlights: Watch now to explore how CyberArk and Wiz empower organizations to secure their cloud environments effortlessly!

Cloudflare Radar's 2024 Internet Year in Review

Explore the worldwide trends that shaped the Internet with Cloudflare Radar’s 2024 Internet Year in Review. Join Host João Tomé and Cloudflare Head of Data Insights, David Belson as they look at Internet trends and patterns across 2024. We also discuss Robotcop and how content creators can prevent bots and crawlers from scraping their sites using a button in the AI Audit section of the Cloudflare dashboard.

Cybersecurity in 2025: Converging Identities, Private AIs and Autonomous APTs

2024 has proved historic for technology and cybersecurity—and we still have some distance from the finish line. We’ve witnessed everything from advancements in artificial intelligence (AI) and large language models (LLMs) to brain-computer interfaces (BCIs) and humanoid robots. Alongside these innovations, new attack vectors like AI model jailbreaking and prompt hacking have emerged. And we also experienced the single largest IT outage the world has ever seen.

94% of U.K. Businesses Aren't Adequately Prepared for AI-Driven Phishing Scams

A new report makes it clear that U.K. organizations need to do more security awareness training to ensure their employees don’t fall victim to the evolving use of AI. Here at KnowBe4, we’ve long known that AI is going to be a growing problem, with phishing attacks and the social engineering they employ far more believable and effective.

Sophisticated Phishing Campaign Attempts to Bypass SEGs

A widespread phishing campaign is attempting to steal credentials from employees working at dozens of organizations around the world, according to researchers at Group-IB. The campaign has targeted organizations across twelve industries, including government, aerospace, finance, energy, telecommunications, and fashion. “The campaign begins with phishing links crafted to mimic trusted platforms commonly used for document management and electronic signatures, such as DocuSign,” Group-IB says.