Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest posts

Can gamification unite development and security?

Despite years of effort encouraging a DevSecOps approach, development and security teams tend to remain divided. For example, according to 2020 research, 65% of security professionals reported that their companies had successfully shifted security left. Good, right? But the same research also shows that almost a third of people believe the security team is primarily responsible for security — despite shifting left.

Kubernetes Version 1.26: Everything You Should Know

The Kubernetes community is ready for the last release of 2022—version 1.26. Since its beginning, Kubernetes has been a place of constant change and improvement. The platform evolves and matures with every new API change and bug fix. In this release, there are 38 tracked enhancements in addition to a large number of bug fixes. In this article, we will focus on some highlighted enhancements, important deprecations, and removals so that you can be confident before upgrading your clusters.

How Good is ClamAV at Detecting Commodity Malware?

"People tell you who they are, but we ignore it, because we want them to be who we want them to be.” - Don Draper Earlier this year we announced some security enhancements to how we handle submissions to Splunkbase. The simple statement is we are making things faster/cheaper/better where Splunkbase security is concerned. Faster in that it takes less time for a developer to get an app into our platform. Cheaper in that it’s more automated.

Self-Signed vs. Publicly Trusted CA Code Signing Certificates: What to Choose?

Being a developer, it has become your moral responsibility to offer clean and safe software products for users to install on their systems. You can easily tackle this by signing your software code and other executables with a digital security certificate.

IONIX: The State of Fortune 500 Attack Surface Threats

In our 2022 research, we discovered 148,000 critical vulnerabilities across Fortune 500 organizations. Security leaders face an onslaught of vulnerabilities. In 2021 alone, 18,378 new vulnerabilities were reported. As enterprises become increasingly hyper-connected and internet facing, the expanding attack surface is a top security concern. On Wednesday, December 7, 2022 at 1 PM ET / 10 AM PT, Cyberpion Chief Product Officer Michael Groskop will discuss our findings in detail at this Cyberpion Attack Surface Protection Series webinar.

Great Power(Shell) doesn't always come with great responsibility: Sometimes, SIEM is all you need

Fileless threats are on the rise. These threats occur when cybercriminals use pre-existing software in victims’ systems to carry out attacks, instead of using a malicious attachment or file. More often than not, a criminal’s favorite tool for a fileless attack is PowerShell.

Tips for Developing Your Ransomware Strategy

Ransomware attacks continue to make headlines and cause havoc on organizations on an international scale. Unfortunately, we should expect that ransomware attacks will persist as one of the primary threats to organizations. Ransomware attacks have grown 350% in recent years, and while the best strategy is to prevent attacks from happening in the first place, there is no guarantee your data won’t be compromised.

The Top 5 CCPA Software Solutions

The California Consumer Privacy Act (CCPA) is a law that allows California consumers to ask companies to provide them with all the information they have stored about them as well as a full list of any third parties that the company has shared that data with. In addition, the California law gives consumers the right to sue companies if the privacy guidelines are violated, even if there have been no actual breaches of privacy.