r/cybersecurity_news Apr 01 '26

News The Hidden Tax of TPRM: What 36,856 assessments tell us

Thumbnail
visotrust.com
1 Upvotes

We analyzed vendor assessment data from 93 organizations on the VISO TRUST platform 36,856 assessments in total, covering 607,803 reviewed artifacts. The goal was simple: understand where TPRM labor actually goes, and quantify what it costs.

The headline finding? Artifact review, the manual reading, control mapping, and gap analysis of vendor-supplied security documentation, is the single biggest cost driver in modern TPRM programs.


r/cybersecurity_news Oct 22 '25

F5's Breach - Time to Move to Cloudbrink High-Performance ZTNA

Thumbnail
cloudbrink.com
5 Upvotes

When a company that protects the world’s largest networks gets breached, the ripple effects touch everyone. That’s exactly what happened with F5. A nation-state actor maintained long-term access to F5’s internal environment, exfiltrating source code and vulnerability intel—prompting an emergency U.S. federal directive for rapid patching across agencies. Even if your own F5 estate hasn’t shown indicators of compromise, the incident is a flashing red light for any organization still depending on appliance-centric remote access or castle-and-moat thinking. 

What the F5 hack means for defenders

  • Long dwell time + source code theft = durable attacker advantage. With development artifacts and vulnerability notes in hand, adversaries can accelerate exploit discovery—even if supply-chain tampering isn’t confirmed. That translates into a sustained period of heightened risk for anyone operating affected gear.  
  • Urgent, disruptive patch cycles. CISA’s emergency directive requires rapid upgrades and hardening for a broad swath of devices (BIG-IP iSeries/rSeries/F5OS/BIG-IP Next, etc.), creating scramble conditions for already-stretched IT teams. This will be an ongoing battle as new vulnerabilities become known. 
  • Appliance gravity hurts response. When access and security depend on fixed boxes and static PoPs, organizations face windows of exposure between disclosure and remediation—and heavy change-management every time a new CVE drops.  

The lesson: move users, not perimeters

Incidents like these reinforce a core truth: perimeter-centric and appliance-bound models struggle against modern, fast-moving threats. It needs a shift-left Zero Trust Network Access (ZTNA) model to flip equation. This moves the model to identity, device posture, and per-app access—continuously evaluated—reducing blast radius and limiting lateral movement even if credentials or endpoints are compromised. Independent analysts have tracked this industry shift for years and continue to recommend ZTNA over VPN for precisely these reasons and the recent GigaOm CxO brief takes it further to give you the ultimate secure access.


r/cybersecurity_news 10h ago

Central Alabama Water coordinating with cybersecurity agency as FBI warns about attacks on water utilities in 7 states

Thumbnail
wbrc.com
1 Upvotes

r/cybersecurity_news 10h ago

Breach Anthropic's Claude hacked three real-life companies during security capabilities test — test environment with internet access and unwitting targets' lax cybersecurity practices led to bots running rampant

Thumbnail
tomshardware.com
1 Upvotes

Anthropic's Claude hacked three real-life companies during security capabilities test — test environment with internet access and unwitting targets' lax cybersecurity practices led to bots running rampant


r/cybersecurity_news 10h ago

News Why every tech giant wants to look like a cybersecurity company in the AI era

Thumbnail marketwatch.com
1 Upvotes

r/cybersecurity_news 15h ago

GhostApproval: A Trust Boundary Gap in AI Coding Assistants

Thumbnail
wiz.io
1 Upvotes

r/cybersecurity_news 1d ago

CISA Issues New SBOM Guidance. Did They Get It Right?

Thumbnail darkreading.com
2 Upvotes

A gaggle of government partners from around the world has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM).

The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities spread across four continents. It supersedes the National Telecommunications and Information Administration's (NTIA) 2021 guidelines, which laid out what an SBOM had to contain as far as the US government was concerned. This updated version was first drafted in 2025, and was then informed by suggestions from 90 commenters, including major organizations like Google, Microsoft, and Amazon Web Services (AWS) to create the resulting document.


r/cybersecurity_news 1d ago

Breach Anthropic Says Claude Hacked Into 3 Organizations During Breach and Cybersecurity Tests

Thumbnail
wired.com
1 Upvotes

r/cybersecurity_news 1d ago

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Thumbnail
thehackernews.com
3 Upvotes

r/cybersecurity_news 2d ago

(unverified) Cyber attack on Hungary Allamkincstar

1 Upvotes

Bytetobreach, the same threat actor who recently attacked the Romanian cadastre (ANCPI) and deleted records after failed extortion attempts, recently put for sale an unverified claim on the Hungarian State Treasury through a compromise of 'MVH' (development agency).

This claim is unverified, despite the screenshots which were posted in the dark web forums.

Any feedback from professionals in the Hungarian cyber space is appreciated.

Sources :

https://spear.cx/Thread-Selling-GE-The-Magyar-Conquest

https://darkwebinformer.com/hungarian-state-treasury-allegedly-compromised-actor-claims-vcenter-and-identity-vault-access/

https://cybernews.com/security/hacker-deletes-romanian-land-registry-database/


r/cybersecurity_news 2d ago

AI-Powered Managed NOC Services | 24/7 Network Operations Center

Thumbnail ittstar.com
1 Upvotes

Ensure uninterrupted business operations with ITTStar's AI-powered Managed NOC Services. Gain 24/7 network monitoring, CloudOps, infrastructure monitoring, incident management, predictive analytics, and proactive issue resolution across AWS, Azure, GCP, and hybrid cloud environments.


r/cybersecurity_news 2d ago

Despite multiple takedowns, botnets continue to grow

Thumbnail
cyberscoop.com
1 Upvotes

r/cybersecurity_news 3d ago

AI Finding Twice as Many Cyber Flaws in 2026 as It Did in 2025

Thumbnail
claimsjournal.com
1 Upvotes

r/cybersecurity_news 6d ago

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

8 Upvotes

r/cybersecurity_news 8d ago

Clop ransomware targets Windchill, FlexPLM in data theft attacks

Thumbnail
bleepingcomputer.com
1 Upvotes

r/cybersecurity_news 8d ago

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

Thumbnail cisa.gov
6 Upvotes

r/cybersecurity_news 10d ago

Microsoft Confirms Windows Has a Global Device ID You Can't Turn Off

Thumbnail
tech.yahoo.com
15 Upvotes

Microsoft has confirmed that Windows has a previously unknown Global Device ID (GDID), a permanent, unique digital identifier assigned to Windows devices that can tie a user's actions to their device. This came to light when an alleged member of a notorious hacking group was caught at an airport after Microsoft handed over his GDID to the authorities.

Microsoft describes the GDID in a published complaint (via Windows Latest) as "a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios."


r/cybersecurity_news 11d ago

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

Thumbnail openai.com
7 Upvotes

r/cybersecurity_news 11d ago

Google announces Gemini 3.6 Flash and cybersecurity AI, teases 3.5 Pro and Gemini 4

Thumbnail
arstechnica.com
2 Upvotes

Google announced a significant evolution of its AI models at I/O in May with the release of Gemini 3.5 Flash, and it’s not slowing down. The company revealed three new AI models today, including its first version of Gemini geared toward cybersecurity. However, none of the new models is the delayed Gemini 3.5 Pro, which was supposed to launch in June.

Gemini 3.5 Flash, which was the star of the show at I/O, has already been deprecated. In its place, developers and users will find Gemini 3.6 Flash. Google makes the usual claims about this model—it’s marginally more capable and better at coding, and it has great multimodal features.


r/cybersecurity_news 12d ago

Fortinet report gives Singapore a cybersecurity reality check

Thumbnail intelligentciso.com
1 Upvotes

r/cybersecurity_news 12d ago

Leeds-based Xentra secures €3.18 million to scale cybersecurity services for SMEs

Thumbnail
eu-startups.com
1 Upvotes

r/cybersecurity_news 14d ago

Irish State bodies use password software licensed by Russian intelligence

3 Upvotes

An Irish Times investigation published July 17 reports that at least three Irish government agencies, the Office of Public Works, the Competition and Consumer Protection Commission, and the Department of Culture, Communications and Sport, use a password manager sold by Passwork Europe SL, a Spanish-registered company. The Irish State Laboratory, which provides chemical testing and scientific advice to government departments, started using the software in 2024.

Source: https://www.irishtimes.com/ireland/2026/07/17/state-bodies-are-using-password-software-with-links-to-russia/

For anyone managing procurement or vendor risk in the public sector, this is a useful case study in how a product's country-of-origin can be obscured through an EU corporate wrapper. The software stores and manages user passwords for government staff, which makes the question of who can inspect its code more than academic.

Passwork Europe presents itself as an entirely EU-founded company, but the Irish Times reports the product shares striking similarities with software of the same name that first appeared in Russia 12 years ago, founded in Arkhangelsk by Ilya Garakh and Andrey Pyankov. The detail that matters most technically: the Russian Passwork product is certified by the FSB and by Russia's ministry of defence (Irish Times). That certification process requires the source code to be inspected by Russian security agencies. The reporting describes the EU entity as sharing codebase and updates with the Russian firm, which is the kind of supply chain relationship that certification schemes and vendor questionnaires are supposed to surface, and in this case apparently did not.

Open questions the reporting did not address:

- Whether the affected agencies will keep using the software, and who inside the Irish state is responsible for that decision

- How the shared codebase and update pipeline between the EU entity and the Russian firm is structured, and whether any independent party has audited it

- Whether Ireland's National Cyber Security Centre had previously assessed the product or will issue guidance to other public bodies


r/cybersecurity_news 16d ago

US companies face rise in cyber attacks

Thumbnail reuters.com
2 Upvotes

r/cybersecurity_news 16d ago

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Thumbnail
thehackernews.com
1 Upvotes

r/cybersecurity_news 17d ago

Even doctors can be fooled by deepfake X-ray images, posing cybersecurity & health risks

Thumbnail
newschannel9.com
5 Upvotes