Zyxel Networks is formalizing a product security governance framework — vulnerability disclosure, lifecycle policies and secure-by-design development — aimed at the small businesses and managed service providers most exposed as the EU Cyber Resilience Act takes hold.
Proofpoint says two large campaigns are already using OAuth client ID spoofing to validate accounts and passwords against Microsoft Entra ID while leaving almost nothing behind in the sign-in logs defenders rely on.
Group-IB's new Purple Teaming service puts red-team attackers and in-house defenders in the same room, in real time, to find out whether all that security spending actually detects anything.
Snapchat is giving 13-to-15-year-olds a dedicated profile where Stories and Spotlight videos are visible only to mutual friends. The trade-off: younger teens lose access to the public feed entirely.
The threat intelligence firm is putting its red team and a client's own defenders in the same live exercise, then making them fix detection rules on the spot. It is a direct shot at the pentest report nobody reads.
KnowBe4 ran 42 million phishing simulations across 14.8 million users. The takeaway: untrained staff fail constantly, and a year of consistent training fixes most of it.
Deloitte joins the IBM- and Red Hat-backed Lightwell initiative, which backports validated security fixes straight to the software versions enterprises already run — no disruptive upgrade required.
New managed security services, plus a ThinkShield TraceLock feature that can locate and wipe powered-off ThinkPads over cellular, headline Lenovo's expanded cyber-resiliency push.


