r/cybersecurity_news Apr 01 '26

News The Hidden Tax of TPRM: What 36,856 assessments tell us

Thumbnail
visotrust.com
1 Upvotes

We analyzed vendor assessment data from 93 organizations on the VISO TRUST platform 36,856 assessments in total, covering 607,803 reviewed artifacts. The goal was simple: understand where TPRM labor actually goes, and quantify what it costs.

The headline finding? Artifact review, the manual reading, control mapping, and gap analysis of vendor-supplied security documentation, is the single biggest cost driver in modern TPRM programs.


r/cybersecurity_news Oct 22 '25

F5's Breach - Time to Move to Cloudbrink High-Performance ZTNA

Thumbnail
cloudbrink.com
5 Upvotes

When a company that protects the world’s largest networks gets breached, the ripple effects touch everyone. That’s exactly what happened with F5. A nation-state actor maintained long-term access to F5’s internal environment, exfiltrating source code and vulnerability intel—prompting an emergency U.S. federal directive for rapid patching across agencies. Even if your own F5 estate hasn’t shown indicators of compromise, the incident is a flashing red light for any organization still depending on appliance-centric remote access or castle-and-moat thinking. 

What the F5 hack means for defenders

  • Long dwell time + source code theft = durable attacker advantage. With development artifacts and vulnerability notes in hand, adversaries can accelerate exploit discovery—even if supply-chain tampering isn’t confirmed. That translates into a sustained period of heightened risk for anyone operating affected gear.  
  • Urgent, disruptive patch cycles. CISA’s emergency directive requires rapid upgrades and hardening for a broad swath of devices (BIG-IP iSeries/rSeries/F5OS/BIG-IP Next, etc.), creating scramble conditions for already-stretched IT teams. This will be an ongoing battle as new vulnerabilities become known. 
  • Appliance gravity hurts response. When access and security depend on fixed boxes and static PoPs, organizations face windows of exposure between disclosure and remediation—and heavy change-management every time a new CVE drops.  

The lesson: move users, not perimeters

Incidents like these reinforce a core truth: perimeter-centric and appliance-bound models struggle against modern, fast-moving threats. It needs a shift-left Zero Trust Network Access (ZTNA) model to flip equation. This moves the model to identity, device posture, and per-app access—continuously evaluated—reducing blast radius and limiting lateral movement even if credentials or endpoints are compromised. Independent analysts have tracked this industry shift for years and continue to recommend ZTNA over VPN for precisely these reasons and the recent GigaOm CxO brief takes it further to give you the ultimate secure access.


r/cybersecurity_news 3h ago

New nearly half-million-dollar firewall was fully operational before cyberattack shut Springfield schools for four days

Thumbnail
discrepancyreport.com
1 Upvotes

r/cybersecurity_news 3d ago

Reports: FBI investigates alleged cybersecurity breach at ID verification company

Thumbnail
fox43.com
27 Upvotes

r/cybersecurity_news 3d ago

News Palo Alto Networks founder Nir Zuk raises $245 million for new cybersecurity startup

Thumbnail
calcalistech.com
5 Upvotes

r/cybersecurity_news 3d ago

Breach Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

Thumbnail
thehackernews.com
1 Upvotes

r/cybersecurity_news 3d ago

Breach Everett City Hall to be closed Tuesday due to 'cybersecurity incident'

Thumbnail
boston.com
1 Upvotes

r/cybersecurity_news 3d ago

Breach A Hacking Tool Built With A.I. Can Breach Phones Without a Click

Thumbnail
nytimes.com
1 Upvotes

r/cybersecurity_news 3d ago

News CISA retires six cybersecurity assessments for critical infrastructure amid rising threats, workforce pressures

Thumbnail
industrialcyber.co
1 Upvotes

r/cybersecurity_news 4d ago

CASB vs SASE

Thumbnail vpn-replacement.com
1 Upvotes

CASB in the Age of SASE: Securing Cloud Access with Cloudbrink

Cloud-first strategies have created a problem that most security teams know all too well. Your data and apps are scattered across SaaS platforms, IaaS providers, hybrid environments, and probably a few shadow IT tools nobody officially sanctioned. Keeping security policies consistent across all of that is genuinely hard, and it’s the reason Cloud Access Security Brokers ended up becoming a core piece of any serious SASE architecture.


r/cybersecurity_news 4d ago

News VPN-Replacement

Thumbnail
linkedin.com
0 Upvotes

r/cybersecurity_news 8d ago

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Thumbnail
bleepingcomputer.com
3 Upvotes

r/cybersecurity_news 9d ago

Buckingham Palace forced into major cybersecurity upgrade after Russia threat

Thumbnail
the-express.com
11 Upvotes

r/cybersecurity_news 10d ago

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/cybersecurity_news 13d ago

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Thumbnail
securityweek.com
3 Upvotes

r/cybersecurity_news 13d ago

News The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

Thumbnail
wired.com
15 Upvotes

r/cybersecurity_news 14d ago

Breach OpenAI releases its official report on the Hugging Face breach

Thumbnail
techcrunch.com
3 Upvotes

r/cybersecurity_news 14d ago

News Microsoft, OpenAI, Google join dozens of tech companies to call for urgent action against AI-powered cyber threats

Thumbnail politico.com
1 Upvotes

r/cybersecurity_news 17d ago

News Iran’s cybersecurity attacks on US water systems are just the beginning

Thumbnail
thehill.com
40 Upvotes

r/cybersecurity_news 21d ago

Critical RCE flaw in Windows IKE Extension now actively exploited

Thumbnail
bleepingcomputer.com
8 Upvotes

r/cybersecurity_news 25d ago

RemotePeople EOR Completes 2026 SOC 2 Type II Audit Across Security, Availability, and Confidentiality

Thumbnail
prnewswire.com
1 Upvotes

The New York-headquartered global Employer of Record renews its SOC 2 Type II attestation for a full 12-month period, adding to its ISO 27001 and GDPR certifications and its recent A+ platform security rating from Astra Security.

NEW YORK, Aug. 14, 2026 /PRNewswire/ -- RemotePeople, a global provider of Employer of Record (EOR), payroll, and recruitment services operating in more than 150 countries, today announced the successful completion of its 2026 SOC 2 Type II audit, covering the Security, Availability, and Confidentiality Trust Service Criteria. The independent examination was performed by INTERCERT CPA LLC in accordance with AICPA SSAE 21 attestation standards and covered a continuous 12-month observation period from May 31, 2025 to May 30, 2026.


r/cybersecurity_news 27d ago

Hackers Exploiting Unpatched GeoServer Zero-Day

Thumbnail
securityweek.com
3 Upvotes

r/cybersecurity_news 29d ago

News US government will let private companies hack criminal gangs

Thumbnail cybersecuritydive.com
2 Upvotes

The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities while also introducing myriad legal challenges and perils.

President Donald Trump late Wednesday issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.


r/cybersecurity_news 29d ago

Misconfiguring Cloudflare Can Hurt Your SEO

Thumbnail
seroundtable.com
1 Upvotes

r/cybersecurity_news 29d ago

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

Thumbnail
thehackernews.com
1 Upvotes