SC Media

SC Media SC Media arms information security professionals with the in-depth, unbiased business and technical information they need.

The official page for all things IT security.

Attackers are leveraging browser notifications to distribute malicious links via a new cybercrime service called Matrix ...
11/21/2025

Attackers are leveraging browser notifications to distribute malicious links via a new cybercrime service called Matrix Push C2, BlackFog reported.

An illicit service called Matrix Push C2 allows users to coordinate push notification attacks.

  tactics have adapted as more organizations move to the cloud with bad actors not just targeting services such as Amazo...
11/21/2025

tactics have adapted as more organizations move to the cloud with bad actors not just targeting services such as Amazon’s S3 buckets and cloud databases, but the groups are integrating them into their own toolkits.

Attackers now integrate multiple AWS S3 buckets, cloud databases, and container images into their toolkits.

Colgate-Palmolive secured its “digital front door” by using Cerby + Okta to centralize control of social accounts, enfor...
11/21/2025

Colgate-Palmolive secured its “digital front door” by using Cerby + Okta to centralize control of social accounts, enforce MFA, eliminate credential sprawl, and streamline agency access. A model for treating digital channels as core identity assets — not exceptions.

In a recent SC Media webcast, host Adrian Sanabria spoke with Alexander Schuchman, CISO at Colgate-Palmolive Company, and Matthew Chiodi, Chief Strategy Officer at Cerby. They discussed how Cerby helped Colgate secure its digital front door.

When Cloudflare went down, many assumed a massive Mirai-class  . But the Nov. 18 outage turned out to be an internal tec...
11/20/2025

When Cloudflare went down, many assumed a massive Mirai-class . But the Nov. 18 outage turned out to be an internal technical issue, not a reprisal. Early attribution is tricky, says Approov's Ted Miracco in this commentary.

Initial fears of a Mirai reprisal attack yesterday were quickly dispelled.

Browsers are now the frontline of enterprise risk, says LayerX Security's Or Eshed in this commentary. Shadow  , risky e...
11/20/2025

Browsers are now the frontline of enterprise risk, says LayerX Security's Or Eshed in this commentary. Shadow , risky extensions, and hidden data flows demand a real strategy.

Teams need to turn the browser from a blind spot to a control plane – here’s how.

Identity is the new battleground. In a recent SC Media webcast, Veza's Rich Dandliker warned that excessive access, shad...
11/20/2025

Identity is the new battleground. In a recent SC Media webcast, Veza's Rich Dandliker warned that excessive access, shadow permissions, and rising AI-driven identities are pushing orgs to rethink least privilege.

In a recent SC Media webcast, host Adrian Sanabria spoke with Rich Dandliker, Chief Strategy Officer at Veza Technologies, Inc., about the realities of identity security going into 2026 -- from the chaos of excessive access and shadow permissions to the mounting attacks exploiting identity systems t...

A Fortinet FortiWeb zero-day vulnerability has been patched and added to the Known Exploited Vulnerabilities catalog by ...
11/20/2025

A Fortinet FortiWeb zero-day vulnerability has been patched and added to the Known Exploited Vulnerabilities catalog by the Cybersecurity and Infrastructure Security Agency, which gave federal civilian executive branch agencies seven days to resolve the flaw.

An authenticated user could use the flaw to execute unauthorized code.

The EU’s recent naming of 19 third-party companies as “critical” tech providers was viewed by industry experts in the U....
11/20/2025

The EU’s recent naming of 19 third-party companies as “critical” tech providers was viewed by industry experts in the U.S. in a different light following the disruption caused by the Nov. 18 Cloudflare outage.

Security pros say more regulation is inevitable in the wake of Cloudflare, AWS outages.

Tanium + Microsoft are teaming up to tame SOC alert overload with real-time endpoint intelligence and copilot-style auto...
11/20/2025

Tanium + Microsoft are teaming up to tame SOC alert overload with real-time endpoint intelligence and copilot-style automation. The goal: auto-triage low-value alerts, surface real threats, and ease analyst burnout.

Tanium announced that its Security Triage Agents are now generally available within Microsoft Security Copilot—a move that seeks to shift the paradigm of alert triage, reduce analyst overload and inject real-time endpoint context into SOC workflows.

Legacy apps break  . Many can’t use SSO or SCIM, leading to manual onboarding, ghost accounts, and security gaps. Cerby ...
11/19/2025

Legacy apps break . Many can’t use SSO or SCIM, leading to manual onboarding, ghost accounts, and security gaps. Cerby bridges the gap with connectors + automated lifecycle management for SaaS and on-prem apps.

Old and on-prem applications often can't connect easily to IAM and IGA systems. Fortunately, there are now workarounds to make this possible.

Cyber defense is cracking from the inside. New Sophos research shows missing fundamentals + widespread burnout are creat...
11/19/2025

Cyber defense is cracking from the inside. New Sophos research shows missing fundamentals + widespread burnout are creating gaps tech alone can’t fix. Exhausted teams, patchy controls, and alert overload fuel real risk.

Two new 2025 research reports from Sophos illuminate a growing challenge for organizations worldwide: the combination of incomplete security fundamentals and widespread cybersecurity burnout is creating structural weaknesses that technology alone can’t fix.

AI-driven automation takes center stage at  . Tanium unveiled deeper ServiceNow integration, plus expanded agentic  , OT...
11/19/2025

AI-driven automation takes center stage at . Tanium unveiled deeper ServiceNow integration, plus expanded agentic , OT/mobile management, and new SecOps tools. The push toward unified, autonomous IT is accelerating fast.

Tanium used its annual conference to showcase both new AI-driven platform capabilities and an expanded partnership with ServiceNow—moves that signal how central automation, real-time telemetry and cross-platform interoperability have become in the push toward “autonomous IT.”

Address

400 Madison Avenue
New York, NY
10017

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Alerts

Be the first to know and let us send you an email when SC Media posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to SC Media:

Share