Penetration testing stories - Page 5
Sophos launches new services to help plug organisational cyber gaps
Thu, 2nd Oct 2025
#
firewalls
#
devops
#
network security
Sophos has launched Advisory Services, a new suite of cybersecurity tests to identify and fix security gaps within organisations, enhancing cyber resilience.
Astra launches platform to combat API threats & shadow APIs
Wed, 24th Sep 2025
#
devops
#
cloud security
#
application security
Astra Security has launched a new platform to identify and secure undocumented and shadow APIs, tackling rising threats from unmonitored digital interfaces.
ReveNet: APAC SMS revenue at risk without urgent operator action
Thu, 11th Sep 2025
#
uc
#
devops
#
apm
ReveNet warns APAC's USD $55bn A2P SMS revenue faces steep decline without urgent operator action to tackle rising costs, fraud, and fragmented regulation.
September Patch Tuesday: Microsoft addressing 176 vulnerabilities
Wed, 10th Sep 2025
#
devops
#
cloud security
#
advanced persistent threat protection
Microsoft patches 176 vulnerabilities this September, including critical flaws in Azure Linux, SQL Server, and Azure HPC, with no current exploits reported.
Healthcare sector slow to fix vulnerabilities despite strong prevention
Thu, 4th Sep 2025
#
data protection
#
devops
#
advanced persistent threat protection
Healthcare sector excels in preventing serious security flaws but takes nearly two months to fix them, risking sensitive data exposure amid rising cyber threats.
New DripDropper malware exploits then patches Linux cloud flaw
Thu, 21st Aug 2025
#
ransomware
#
devops
#
cloud security
New DripDropper malware exploits then patches a Linux cloud flaw, securing exclusive access to servers via Apache ActiveMQ vulnerability CVE-2023-46604.
Rapid7 unveils Vector Command Advanced for compliance, security
Wed, 20th Aug 2025
#
devops
#
apm
#
risk & compliance
Rapid7 launches Vector Command Advanced, a platform combining automated and human-led tests to enhance security and simplify compliance with PCI, ISO 27001, and NIST.
CISO report: AI, supply chain, & insider risks reshape security
Sat, 2nd Aug 2025
#
devops
#
digital transformation
#
supply chain
CISO report reveals AI, supply chain, and insider threats prompt security leaders to adopt offensive strategies and continuous testing for better resilience.
Crowdsourced security gives CISOs edge in AI & data privacy
Thu, 31st Jul 2025
#
devops
#
advanced persistent threat protection
#
apm
New research shows 15% of CISOs fully leverage crowdsourced security to better tackle AI safety and data privacy challenges in large firms.
CREST launches staged programme to guide firms to full cyber accreditation
Fri, 25th Jul 2025
#
devops
#
apm
#
risk & compliance
CREST launches Pathway and Pathway+ programmes to guide firms through staged progression towards full cyber security accreditation and trust.
SharePoint zero-day flaw exploited as over 9,000 servers at risk
Wed, 23rd Jul 2025
#
devops
#
encryption
#
apm
A zero-day flaw in Microsoft SharePoint servers puts over 9,000 systems at risk, with active exploits threatening critical data security globally.
Check Point earns CREST accreditation for penetration testing
Mon, 21st Jul 2025
#
firewalls
#
devops
#
network security
Check Point Software Technologies has earned CREST accreditation for its penetration testing services, affirming its high standards in cybersecurity assurance.
Spectrum appoints Deane Jessep to drive sovereign AI strategy
Fri, 11th Jul 2025
#
data protection
#
private cloud
#
network infrastructure
Spectrum names Deane Jessep CTO to lead New Zealand's sovereign AI strategy, tackling cloud costs, data sovereignty, and AI governance in enterprise and government sectors.
Race condition in nopCommerce gift cards enables repeated use
Fri, 11th Jul 2025
#
devops
#
apm
#
e-commerce
A race condition vulnerability in nopCommerce gift cards lets attackers redeem the same card repeatedly, exploiting a flaw in the checkout process.
Zyxel advances Secure by Design for global SMB networking security
Thu, 10th Jul 2025
#
firewalls
#
devops
#
network security
Zyxel Networks adopts CISA's Secure by Design Pledge, enhancing SMB networking security with MFA, unique passwords, and transparent vulnerability reporting worldwide.
LevelBlue acquires Trustwave to form largest global MSSP
Fri, 4th Jul 2025
#
devops
#
cloud security
#
advanced persistent threat protection
LevelBlue's acquisition of Trustwave creates the world's largest pure-play managed security services provider, enhancing global cyber defence capabilities.
Most fintechs fail API security, risking sensitive payment data
Thu, 3rd Jul 2025
#
data protection
#
devops
#
fintech
New research reveals 84% of fintechs lack robust API security, exposing sensitive payment data to significant cyber risks beyond regulated sectors.
LevelBlue to acquire Trustwave, creating top global cyber giant
Wed, 2nd Jul 2025
#
devops
#
cloud security
#
advanced persistent threat protection
LevelBlue will acquire Trustwave, creating the world's largest pure-play managed security services provider with enhanced global cybersecurity capabilities.
AI drives 80 percent of phishing with USD $112 million lost in India
Tue, 1st Jul 2025
#
malware
#
data protection
#
semiconductors
AI powers 80% of phishing attacks, causing USD $112 million in losses in India by May 2025, as cybercrime evolves with machine-generated deception.
Tech sector faces sharp rise in AI & ransomware threats
Fri, 27th Jun 2025
#
firewalls
#
ransomware
#
devops
Trustwave reveals a surge in AI-driven and ransomware attacks, with tech firms facing 85% of global ransomware incidents amid rising cyber threats.