Fortinet updates FortiSASE; SASE from a single vendor
Fortinet has announced updates to its single-vendor Secure Access Service Edge (SASE) product FortiSASE. The new functionality should help companies secure hybrid workers.
The rise of hybrid working means companies need to pay more attention to employee security, including when they move more fr... Read more
Microsoft makes major change to Excel due to rising malware attacks
The effort aims to stop attackers from abusing various Office document formats as an infection vector. The company has announced that Excel will block untrusted XLL add-ins by default in Microsoft 365 tenants worldwide.
Excel XLL files are dynamic-link libraries (DLLs) that expand the functional... Read more
Expert talks
Four Steps to Take Your API Security to the Next Level
APIs, or application programming interfaces, are an essential part of modern software development. They enable applications and services to communicate with each other, providing a way for different pieces of software to work together. Using APIs, a single backend service can serve a multitude of c... Read more
Acer confirms 160 GB data leak
Acer has confirmed a 160 GB data leak of documents from repair employees. The data leak became public after cybercriminals posted an example on a hacker forum.
According to BleepingComputer, cybercriminals recently managed to capture a large amount of data from the computer manufacturer. The dat... Read more
CrowdStrike and Dell Technologies team up to secure businesses
CrowdStrike and Dell Technologies will jointly provide solutions that allow businesses to better secure themselves against cyber threats. These include solutions for preventing, detecting and responding to the threats.
According to CrowdStrike and Dell, the new partnership should provide compani... Read more
Business-grade routers hit by Hiatus malware
Business-grade DrayTek routers are under attack by the Hiatus malware campaign. The successfully attacked routers are transformed into "listening posts" that can intercept email and steal files.
Security experts at Lumen note that the Hiatus malware campaign has been active since July 2022. The ... Read more
Nearly all companies have misconfigurations in cloud environments
Nearly all organizations (98.6 percent) are experiencing worrisome misconfigurations that pose significant risks to data and infrastructure.
According to research by Zscaler, the increasing use of cloud technology is leading to more and more vulnerability problems. In the study, Zscaler finds th... Read more
Study attacks EU cloud security label that excludes US vendors
The study was commissioned by a US non-profit industry group dedicated to "open markets".
This week Reuters reports that a study commissioned by a tech lobbying group concludes that a proposed EU cloud security certification regime that could exclude US tech giants like Amazon, Google, Microsoft... Read more
Hackers hit British retailer WH Smith
The cyberattack resulted in the theft of some company data.
On Thursday, UK retail group WH Smith announced that it had been the victim of a cyberattack. The company did not disclose the exact nature of the attack, but the official "notice of cybersecurity incident" it issued to the London Stock... Read more
Microsoft releases security updates for Intel CPU vulnerabilities
Microsoft has released out-of-band security updates to tackle the 'Memory Mapped I/O Stale Data (MMIO)' information disclosure vulnerabilities affecting Intel CPUs.
The vulnerability, initially disclosed by Intel on June 14, 2022, warned that processes running in a virtual machine could gain acc... Read more