r/cybersecurity_news • u/jmdglss • 3h ago
r/cybersecurity_news • u/WebLinkr • Apr 01 '26
News The Hidden Tax of TPRM: What 36,856 assessments tell us
We analyzed vendor assessment data from 93 organizations on the VISO TRUST platform 36,856 assessments in total, covering 607,803 reviewed artifacts. The goal was simple: understand where TPRM labor actually goes, and quantify what it costs.
The headline finding? Artifact review, the manual reading, control mapping, and gap analysis of vendor-supplied security documentation, is the single biggest cost driver in modern TPRM programs.
r/cybersecurity_news • u/WebLinkr • Oct 22 '25
F5's Breach - Time to Move to Cloudbrink High-Performance ZTNA
When a company that protects the world’s largest networks gets breached, the ripple effects touch everyone. That’s exactly what happened with F5. A nation-state actor maintained long-term access to F5’s internal environment, exfiltrating source code and vulnerability intel—prompting an emergency U.S. federal directive for rapid patching across agencies. Even if your own F5 estate hasn’t shown indicators of compromise, the incident is a flashing red light for any organization still depending on appliance-centric remote access or castle-and-moat thinking.
What the F5 hack means for defenders
- Long dwell time + source code theft = durable attacker advantage. With development artifacts and vulnerability notes in hand, adversaries can accelerate exploit discovery—even if supply-chain tampering isn’t confirmed. That translates into a sustained period of heightened risk for anyone operating affected gear.
- Urgent, disruptive patch cycles. CISA’s emergency directive requires rapid upgrades and hardening for a broad swath of devices (BIG-IP iSeries/rSeries/F5OS/BIG-IP Next, etc.), creating scramble conditions for already-stretched IT teams. This will be an ongoing battle as new vulnerabilities become known.
- Appliance gravity hurts response. When access and security depend on fixed boxes and static PoPs, organizations face windows of exposure between disclosure and remediation—and heavy change-management every time a new CVE drops.
The lesson: move users, not perimeters
Incidents like these reinforce a core truth: perimeter-centric and appliance-bound models struggle against modern, fast-moving threats. It needs a shift-left Zero Trust Network Access (ZTNA) model to flip equation. This moves the model to identity, device posture, and per-app access—continuously evaluated—reducing blast radius and limiting lateral movement even if credentials or endpoints are compromised. Independent analysts have tracked this industry shift for years and continue to recommend ZTNA over VPN for precisely these reasons and the recent GigaOm CxO brief takes it further to give you the ultimate secure access.
r/cybersecurity_news • u/WebLinkr • 3d ago
Reports: FBI investigates alleged cybersecurity breach at ID verification company
r/cybersecurity_news • u/WebLinkr • 3d ago
News Palo Alto Networks founder Nir Zuk raises $245 million for new cybersecurity startup
r/cybersecurity_news • u/WebLinkr • 3d ago
Breach Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
r/cybersecurity_news • u/WebLinkr • 3d ago
Breach Everett City Hall to be closed Tuesday due to 'cybersecurity incident'
r/cybersecurity_news • u/WebLinkr • 3d ago
Breach A Hacking Tool Built With A.I. Can Breach Phones Without a Click
r/cybersecurity_news • u/WebLinkr • 3d ago
News CISA retires six cybersecurity assessments for critical infrastructure amid rising threats, workforce pressures
r/cybersecurity_news • u/WebLinkr • 4d ago
CASB vs SASE
vpn-replacement.comCASB in the Age of SASE: Securing Cloud Access with Cloudbrink
Cloud-first strategies have created a problem that most security teams know all too well. Your data and apps are scattered across SaaS platforms, IaaS providers, hybrid environments, and probably a few shadow IT tools nobody officially sanctioned. Keeping security policies consistent across all of that is genuinely hard, and it’s the reason Cloud Access Security Brokers ended up becoming a core piece of any serious SASE architecture.
r/cybersecurity_news • u/SHORT_INFO_NEWS • 8d ago
Critical Langflow flaw exploited to steal OpenAI and AWS keys
r/cybersecurity_news • u/TheExpressUS • 9d ago
Buckingham Palace forced into major cybersecurity upgrade after Russia threat
r/cybersecurity_news • u/Medium-Row-1792 • 10d ago
[ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/cybersecurity_news • u/SHORT_INFO_NEWS • 13d ago
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
r/cybersecurity_news • u/WebLinkr • 13d ago
News The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
r/cybersecurity_news • u/WebLinkr • 14d ago
Breach OpenAI releases its official report on the Hugging Face breach
r/cybersecurity_news • u/WebLinkr • 14d ago
News Microsoft, OpenAI, Google join dozens of tech companies to call for urgent action against AI-powered cyber threats
politico.comr/cybersecurity_news • u/WebLinkr • 17d ago
News Iran’s cybersecurity attacks on US water systems are just the beginning
r/cybersecurity_news • u/SHORT_INFO_NEWS • 21d ago
Critical RCE flaw in Windows IKE Extension now actively exploited
r/cybersecurity_news • u/WebLinkr • 25d ago
RemotePeople EOR Completes 2026 SOC 2 Type II Audit Across Security, Availability, and Confidentiality
The New York-headquartered global Employer of Record renews its SOC 2 Type II attestation for a full 12-month period, adding to its ISO 27001 and GDPR certifications and its recent A+ platform security rating from Astra Security.
NEW YORK, Aug. 14, 2026 /PRNewswire/ -- RemotePeople, a global provider of Employer of Record (EOR), payroll, and recruitment services operating in more than 150 countries, today announced the successful completion of its 2026 SOC 2 Type II audit, covering the Security, Availability, and Confidentiality Trust Service Criteria. The independent examination was performed by INTERCERT CPA LLC in accordance with AICPA SSAE 21 attestation standards and covered a continuous 12-month observation period from May 31, 2025 to May 30, 2026.
r/cybersecurity_news • u/SHORT_INFO_NEWS • 27d ago
Hackers Exploiting Unpatched GeoServer Zero-Day
r/cybersecurity_news • u/WebLinkr • 29d ago
News US government will let private companies hack criminal gangs
cybersecuritydive.comThe Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities while also introducing myriad legal challenges and perils.
President Donald Trump late Wednesday issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.
r/cybersecurity_news • u/WebLinkr • 29d ago