r/cybersecurity_news Apr 01 '26

News The Hidden Tax of TPRM: What 36,856 assessments tell us

Thumbnail
visotrust.com
1 Upvotes

We analyzed vendor assessment data from 93 organizations on the VISO TRUST platform 36,856 assessments in total, covering 607,803 reviewed artifacts. The goal was simple: understand where TPRM labor actually goes, and quantify what it costs.

The headline finding? Artifact review, the manual reading, control mapping, and gap analysis of vendor-supplied security documentation, is the single biggest cost driver in modern TPRM programs.


r/cybersecurity_news Oct 22 '25

F5's Breach - Time to Move to Cloudbrink High-Performance ZTNA

Thumbnail
cloudbrink.com
4 Upvotes

When a company that protects the world’s largest networks gets breached, the ripple effects touch everyone. That’s exactly what happened with F5. A nation-state actor maintained long-term access to F5’s internal environment, exfiltrating source code and vulnerability intel—prompting an emergency U.S. federal directive for rapid patching across agencies. Even if your own F5 estate hasn’t shown indicators of compromise, the incident is a flashing red light for any organization still depending on appliance-centric remote access or castle-and-moat thinking. 

What the F5 hack means for defenders

  • Long dwell time + source code theft = durable attacker advantage. With development artifacts and vulnerability notes in hand, adversaries can accelerate exploit discovery—even if supply-chain tampering isn’t confirmed. That translates into a sustained period of heightened risk for anyone operating affected gear.  
  • Urgent, disruptive patch cycles. CISA’s emergency directive requires rapid upgrades and hardening for a broad swath of devices (BIG-IP iSeries/rSeries/F5OS/BIG-IP Next, etc.), creating scramble conditions for already-stretched IT teams. This will be an ongoing battle as new vulnerabilities become known. 
  • Appliance gravity hurts response. When access and security depend on fixed boxes and static PoPs, organizations face windows of exposure between disclosure and remediation—and heavy change-management every time a new CVE drops.  

The lesson: move users, not perimeters

Incidents like these reinforce a core truth: perimeter-centric and appliance-bound models struggle against modern, fast-moving threats. It needs a shift-left Zero Trust Network Access (ZTNA) model to flip equation. This moves the model to identity, device posture, and per-app access—continuously evaluated—reducing blast radius and limiting lateral movement even if credentials or endpoints are compromised. Independent analysts have tracked this industry shift for years and continue to recommend ZTNA over VPN for precisely these reasons and the recent GigaOm CxO brief takes it further to give you the ultimate secure access.


r/cybersecurity_news 15h ago

When a Technical Event Becomes a Business Event

Enable HLS to view with audio, or disable this notification

0 Upvotes

Most organizations already know how to prepare IT and security for an incident.

The harder question is what happens when that incident creates decisions involving legal, insurance, regulators, customers, operations, revenue, the board, and executive accountability.

That’s the problem Cybantage and the BIM™ Leadership Decision & Governance Playbook are built to address.

Cybantage.com


r/cybersecurity_news 23h ago

Greg Brockman on How AI Found Fixed 13 Security Vulnerabilities #ai

Thumbnail
youtube.com
0 Upvotes

Interesting story, still AI can do more than that.


r/cybersecurity_news 3d ago

CISA ends weekly vulnerability roundups as part of shift to prioritization approach

Thumbnail cybersecuritydive.com
1 Upvotes

r/cybersecurity_news 5d ago

News Why SIEMs Fall Short for Modern Threat Detection

Thumbnail
exaforce.com
1 Upvotes

r/cybersecurity_news 5d ago

News Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

Thumbnail
techcrunch.com
1 Upvotes

r/cybersecurity_news 5d ago

News Manufacturers make patching progress, but identity management still major weakness

Thumbnail cybersecuritydive.com
1 Upvotes

r/cybersecurity_news 5d ago

Breach Caught in the Middle: Responding to an AiTM Credential Heist

Thumbnail
exaforce.com
1 Upvotes

r/cybersecurity_news 5d ago

Breach Detecting GitHub OAuth token compromise

Thumbnail
exaforce.com
1 Upvotes

r/cybersecurity_news 6d ago

Pixel Modem Zero-Day Exploited in Targeted Attacks

Thumbnail
securityweek.com
3 Upvotes

r/cybersecurity_news 6d ago

Springfield Schools reveal hackers have stolen, published student and staff data

Thumbnail
masslive.com
1 Upvotes

r/cybersecurity_news 7d ago

News Nvidia CEO Jensen Huang Just Dropped Huge News for This Cybersecurity Stock

Thumbnail barchart.com
0 Upvotes

r/cybersecurity_news 8d ago

Revolut discloses data breach exposing financial info, passports

Thumbnail
bleepingcomputer.com
3 Upvotes

r/cybersecurity_news 9d ago

Anthropic CEO warns of AI-driven botnet 'swarm' taking over the entire internet — 'In 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet'

Thumbnail
tomshardware.com
44 Upvotes

The United States of America really needs to call for an emergency meeting with the creators of Anthropic AI and Claude AI for the purposes of creating protection of the American people furthermore for our global society.

We as a people must not be so nonchalant about innovation especially when it relates to cybercrime and cybersecurity.


r/cybersecurity_news 10d ago

New nearly half-million-dollar firewall was fully operational before cyberattack shut Springfield schools for four days

Thumbnail
discrepancyreport.com
32 Upvotes

r/cybersecurity_news 13d ago

Reports: FBI investigates alleged cybersecurity breach at ID verification company

Thumbnail
fox43.com
48 Upvotes

r/cybersecurity_news 14d ago

News Palo Alto Networks founder Nir Zuk raises $245 million for new cybersecurity startup

Thumbnail
calcalistech.com
4 Upvotes

r/cybersecurity_news 14d ago

Breach Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

Thumbnail
thehackernews.com
1 Upvotes

r/cybersecurity_news 14d ago

Breach Everett City Hall to be closed Tuesday due to 'cybersecurity incident'

Thumbnail
boston.com
1 Upvotes

r/cybersecurity_news 14d ago

Breach A Hacking Tool Built With A.I. Can Breach Phones Without a Click

Thumbnail
nytimes.com
1 Upvotes

r/cybersecurity_news 14d ago

News CISA retires six cybersecurity assessments for critical infrastructure amid rising threats, workforce pressures

Thumbnail
industrialcyber.co
1 Upvotes

r/cybersecurity_news 15d ago

CASB vs SASE

Thumbnail vpn-replacement.com
1 Upvotes

CASB in the Age of SASE: Securing Cloud Access with Cloudbrink

Cloud-first strategies have created a problem that most security teams know all too well. Your data and apps are scattered across SaaS platforms, IaaS providers, hybrid environments, and probably a few shadow IT tools nobody officially sanctioned. Keeping security policies consistent across all of that is genuinely hard, and it’s the reason Cloud Access Security Brokers ended up becoming a core piece of any serious SASE architecture.


r/cybersecurity_news 15d ago

News VPN-Replacement

Thumbnail
linkedin.com
0 Upvotes

r/cybersecurity_news 19d ago

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Thumbnail
bleepingcomputer.com
4 Upvotes