Security news aggregator

Latest coverage for Mitigation

Explore the latest in cyber threat Mitigation strategies to safeguard your data. Stay updated with our comprehensive info security insights and tips.

188 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Mitigation is the process of implementing strategies and actions to reduce the impact of potential threats on information systems. In the context of information security, mitigation involves the identification of vulnerabilities within computer systems, networks, and software applications, and promptly employing methods to counteract or prevent exploitation by cyber threats.

Effective mitigation measures can include deploying security patches to fix software vulnerabilities, configuring firewalls to guard against unauthorized access, conducting regular security training for employees, and establishing protocols to respond to security incidents. The goal is to minimize the risk of data breaches, system infiltrations, and the resulting damage to an organization’s operations and reputation. Mitigation strategies are an essential part of an organization's defensive mechanisms, ensuring resilience against the evolving landscape of cyber threats.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 188 Filtered view
Bank Info Security 5 days, 4 hours ago

AI-Driven Bug Tsunami Prompts Exploitability Questions

Severity and Reachability Metrics Also Essential for Mythos-Era Bug MitigationIf there's one thing artificial intelligence has done, it's multiply bugs, and the annual CVE Program count of new vulnerabilities is set to break records. Less apparent is how many of those AI-ferreted vulnerabilities can be turned into high-impact exploit chains - if they're exploitable at all.

Microsoft Security Research 5 days, 20 hours ago

Typosquatted npm packages used to steal cloud and CI/CD secrets

The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt related activity. The post Typosquatted npm packages used to steal cloud and CI/CD secrets appeared first on Microsoft Security Blog.

On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users. [...]

Vendor Details Mitigations, Promises Patched PAN-OS Software in Coming WeeksPalo Alto Networks warned that a critical vulnerability in the PAN-OS software that runs its firewalls is being actively exploited in the wild by attackers. The vendor detailed temporary mitigations and promised to release updated software to fully patch the flaw later this month.

Bank Info Security 2 months, 1 week ago

AI and Medical Device Cybersecurity: The Good and Bad

Is AI Exposing a Growing Vulnerability Risk Mitigation Gap?AI-fueled tools can help to identify medical device vulnerabilities much faster and at a higher volume than more traditional tools. But can device manufacturers and healthcare delivery organizations keep up with prioritizing and addressing a tidal wave of newly discovered flaws?

Mitigation: SSO Access Restricted After Attackers Compromised Fully Patched DevicesNetwork security giant Fortinet locked out cloud customers from its single sign-on service until they update device firmware with a patch against active attacks exploiting an improper access control zero day. Only Fortinet devices running the latest, patched firmware versions can use Fortinet SSO.

Patches Issued for MongoBleed as Ransomware Groups Target Flaw to Steal DataTens of thousands of internet-exposed MongoDB databases are at risk as attackers actively target a critical vulnerability in the software to steal sensitive data, with ransomware groups having joined the fray, researchers warn. MongoDB has issued patches and mitigation advice.

Bank Info Security 5 months, 2 weeks ago

AI Governance Unlocks Speed, Not Bureaucracy

ServiceNow's Neeraj Jain on Risk Mitigation and Real-Time Data Access for AI AgentsEnterprises that embed governance from intake to deployment scale AI faster than those that bolt it on afterward. Clear frameworks mitigate risk, ensure compliance and increase operational efficiency, says Neeraj Jain, director of product management, hyperscalers and multi-cloud at ServiceNow.

Bank Info Security 5 months, 4 weeks ago

React Flaw Mitigation Leads to Cloudflare Outage

Outage Briefly Took Down Zoom, LinkedIn and Other WebsitesContent delivery network giant Cloudflare is investigating a brief outage early Friday that took down multiple websites. The incident marks the second outage in the span of a month, although the causes are unrelated. It stemmed from how Cloudflare's web application firewall parses requests.

Bank Info Security 6 months, 1 week ago

Ransomware Reshaping Cyber as National Security Priority

Public-Private Cooperation Key for Ransomware Mitigation, Says Anne NeubergerOngoing, high-profile ransomware attacks against Britain and the United States have transformed cybersecurity into a national security priority, Anne Neubehttps://cms.ismgcorp.com/userpolicy/titlelevelrger, the former White House deputy national security adviser for cyber, said at a Wednesday event in London.

Nonprofit Foundation Holds Equity, Oversight Around $130B For-Profit CorporationThe nonprofit OpenAI Foundation now controls a $130 billion for-profit arm after a recapitalization process approved by attorneys general in California and Delaware. The nonprofit retains governance authority and will fund global health and AI risk mitigation programs, backed by regulatory approval.

Bank Info Security 7 months, 1 week ago

CISA Flags Highly Exploitable Windows SMB Flaw

NTLM Reflection Attack Strikes AgainA three-month old flaw in a network protocol for file sharing used by Microsoft is under active exploitation, warns the U.S. Cybersecurity and Infrastructure Security Agency. The flaw's exploitation bypasses mitigations Microsoft has built over the years to prevent NTLM reflection attacks.

Loading more headlines...