Security
"Without a change in incentives, tooling, behaviors, ownership, and ultimately focus, there will be no material change in actual technical risk management."
"Routine initial exploitation of zero-day vulnerabilities represents the new normal which should concern end-user organisations and vendors alike."
Regulators admit that forcing critical third-party firms to "openly" share vulns would "go against" plan to reduce systemic risk and boost operational resilience.
Public advisory comes after alleged PAN-OS vulnerability advertised on exploit forum.
"Cybercriminals have access to sophisticated tools that make their attacks increasingly challenging to recognise and counter."
Expedition, a migration tool, hit by bug that could allow attackers with network access to "access secrets, credentials, and other data".
Sophos’ CISO to The Stack on its firewall kernel implant: “We were aware we were taking unusual steps”
Former Lieutenant Colonel and CEO of CybSafe discusses a human-centric approach to organisational defence.