Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest posts

Getting the best out of your SIEM

An effective SIEM solution ingests logs from different network sources to give visibility into user and host activities. It uses capabilities such as threat intelligence and behavioral analysis to set correlation rules to spot malicious activities within a network. This e-book will help you obtain the maximum value from your SIEM deployment by guiding you through 10 of the most critical capabilities capabilities.

1Password: The Heart of Cybersecurity Webinar Series: Pete Matheson

At 1Password, our goal is to keep everyone, everywhere safe as they go about their work and play. Our webinar series, "The Heart of Cybersecurity," aims to explore what's really at the heart of the complex world of cybersecurity: real people, solving real problems, and their extraordinary stories. April's session features Pete Matheson, mentor and coach to IT business owners. He frequently shares his thoughts and opinions on the latest tech announcements, security and privacy issues, and products you should know about on his website and YouTube channel.

Outpost 24: Live Webinar: Why API security matters and how to get it right

APIs are everywhere and now a critical part of any modern SaaS and web application. API security has become a critical priority because the nature of publicly available APIs give outsiders direct access to your application logic and data for potential abuse. In fact, Gartner predicts "by 2022, API abuses will move from infrequent to the most frequent attack vector, resulting in data breaches for enterprise web applications." Recent API attacks on Peloton, LinkedIn, and Clubhouse are good examples of the risk of vulnerable APIs in the real world.

WatchGuard: Elevating Your MSP Security Practice with a Unified Security Platform

You're tired of struggling with disjointed security information, incomplete integrations, and too much time and energy spent with multiple security vendors. These aren't minor headaches of a managed services business, they ultimately drain efficiency and profits, and many are considering vendor consolidation as the answer.

How to Meet Third-party Risk Requirements of NIST 800-161

The National Institute of Standards and Technology (NIST) has produced several publications addressing the different components of information technology security within the NIST 800 computer security series. Compliance across this entire NIST 800 series is expected for all internal and external service providers of government entities - such as the DoD federal agencies.

DevSecOps build and test process

In the previous article about the coding process, we covered developers using secure coding practices and how to secure the central code repository that represents the single source of truth. After coding is complete, developers move to the build and test processes of the Continuous Integration (CI) phase. These processes use automation to compile code and test it for errors, vulnerabilities, license conformity, unexpected behavior, and of course bugs in the application.

Kubescape March 2022 version - what is new and what is improved

The ARMO Kubescape team has been busy lately… we have several new and improved features for you that we are very excited about. Based on the feedback and ideas we got from the amazing community, we worked hard to enhance Kubescape with better and deeper scanning capabilities, UI improvements, and a more friendly CLI version. We invite everyone to shape the Kubescape roadmap by giving us feedback and suggestions using git, discord, or mail.

The Impact of Cyberattacks on Healthcare

While the COVID-19 pandemic brought much of the world to work together to advance medical research and slow the spread of the disease, it may be of little surprise that cyber threat actors took advantage of the pandemic for their own personal gain. While all industries can be affected by a cybersecurity incident, the nature of the health and human services industry’s mission poses unique challenges.

Coffee Talk with SURGe: 2022-APR-05 State Department, Elections, Spring4Shell, Certs/Lapsus$, RSA!

Grab a cup of coffee and join Ryan Kovar, Mick Baccio, and Audra Streetman for another episode of Coffee Talk with SURGe. The team from Splunk will discuss the latest security news and compete in a 60 second charity challenge. You don't want to miss it!