Security
The US department of justice has busted up a prolific ransomware as a service ring that targeted hundreds of companies
Vulnerabilities are turning into actively exploited flaws at a rapid pace, often within the same day. This according to research from security vendor Qualys.
The NSA has posted a new set of cybersecurity guidelines for government agencies
Attacker "disrupted… business operations by encrypting some IT systems, and stole data from the company"
Firms need to disclose any cybersecurity incident they determine to be material and to describe the material aspects of the incident's nature, scope, and timing within four days.
The DOJ has launched a legal campaign against what it says are a network of fraudsters that thrive on extracting micropayment charges in order to avoid detection by banks
"Institutions continue to report gaps in risk control areas considered fundamental to cyber hygiene, such as proper identity and access management, timely vulnerability patching or network security"
IBM is providing a custom "Asset, Configuration, Patching and Vulnerability” service with a special focus on vulnerability management.
A CVSS 9,8 bug that lets attackers spoof legitimate connectors between Microsoft/Azure services is the pick of the bunch...