A bill in the Georgia senate would criminalize some activities that security researchers commonly perform.
When GitHub unveiled its Security Alerts scanning feature last November, it was betting that if project owners knew which software components they were using had vulnerabilities, they would update them with patched versions. GitHub said that by Dec. 1, 450,000 vulnerabilities had been resolved, either by removing the dependency entirely or swapping out with a more recent, patched version. That's a little over 10 percent of the vulnerabilities addressed, right off the bat.
Recent advances in artificial intelligence, especially in deep learning and other machine learning approaches, are really exciting for the future of security. In the rush to roll out AI in security technology, it is easy to forget that machine learning is just a tool, and that like any tool, is the most effective when used by an expert.
The CLOUD Act gives governments new powers to seize data stored in other countries, raising privacy concerns.
Organizations don't have to decide between hiring a CSO/CISO or not having a security leader at all. They can tap the CISO's security expertise by working with a virtual CSO. Gal Shpantzer and Wim Remes talk about the challenges of being an intricate part of the organization's security but still an outsider.