Category index

Cyber Security

4276 articles

4276 ARTICLES

Introducing OAuth Support for AWS MCP Server
CYBERSECURITY

Introducing OAuth Support for AWS MCP Server

You can now connect your agents to the AWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Management Console or AWS Command Line Interface (AWS CLI) through a familiar browser-based experience powered by industry-standard OAuth. This new sign-in path supports AWS Identity and Access Management

1 MIN READ arrow_forward
How to Meet a 3-Day Remediation SLA & Comply with CISA BOD 26-04
CYBERSECURITY

How to Meet a 3-Day Remediation SLA & Comply with CISA BOD 26-04

Key Takeaways CISA BOD 26–04 mandates remediation of the publicly exposed, highest-risk, known-exploited vulnerabilities within 3 days. The directive applies a risk-based model evaluating exposure, KEV status, automation potential, and technical impact. Most high-risk vulnerability instances reside on non-critical endpoint assets, which are suited for automated patching at scale. Patchless remediation techniques can reduce exposure

1 MIN READ arrow_forward
WolfSSL, GeoVision, VTK vulnerabilities
CYBERSECURITY

WolfSSL, GeoVision, VTK vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For

1 MIN READ arrow_forward
Winning 54% of the time
CYBERSECURITY

Winning 54% of the time

With Wimbledon’s help, Hazel argues against the popular myth that “Attackers only need to be right once, but defenders need to be right 100% of the time.”

1 MIN READ arrow_forward
Implementing CCM: Universal Endpoint Management Controls
CYBERSECURITY

Implementing CCM: Universal Endpoint Management Controls

The Cloud Controls Matrix (CCM) is a framework of controls that are essential for cloud computing security. Created by CSA, the CCM aligns with CSA best practices. You can use CCM to assess and guide the security of any cloud service. CCM also provides guidance on which actors within the cloud supply chain should implement which controls. Both cloud service customers (CSCs) and cloud service providers (CSPs) use CCM in many ways. CCM contains 197 controls structured into 17 domain…

1 MIN READ arrow_forward
When "Who Are You?’ Is No Longer Enough: The Case for Intent-Based Access Control in the Age of AI Agents
CYBERSECURITY

When "Who Are You?’ Is No Longer Enough: The Case for Intent-Based Access Control in the Age of AI Agents

It keeps coming back to a conversation I had about six months ago. I sat with the CISO of a fortune 50 retail organization to review an incident that had kept the security team up for two straight nights. No credentials were stolen. No malware was deployed. No firewall rule was broken. Yet the critical reconciliation process had gone seriously wrong, wrong enough to draw regulatory scrutiny. The culprit? An AI-powered automation agent that had been granted, quite legitimately, acce…

1 MIN READ arrow_forward
How GitHub gave every repository a durable owner
CYBERSECURITY

How GitHub gave every repository a durable owner

GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here’s how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed. The post How GitHub gave every repository a durable owner appeared first on The GitHub Blog.

1 MIN READ arrow_forward
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
CYBERSECURITY

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper, also tracked as BLUERABBIT, is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders detect and defend against similar threats. The post GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware appeared first on Microsoft Security Blog.

1 MIN READ arrow_forward