SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers

Log4j stories

Flux result 6e43f861 242a 4606 a620 43480305c4e9

Orca Security flags AI secrets & supply chain gaps

Last week
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
Flux result d2cebe18 95d7 46b4 b7a5 7ed6eb834b59

SonicWall flags SMB cyber gaps as attacks rise 20.8%

This month
#
firewalls
#
vpns
#
ransomware
SonicWall says small firms are being hit hardest by basic security lapses as ransomware, bot traffic and identity theft keep climbing.
Editorial cybersecurity analyst pen test results attack path cloud diagrams

Cobalt adds AI features to boost continuous pentests

Last month
#
devops
#
cloud security
#
application security
Cobalt weaves AI into its pentesting platform, automating recon and triage while keeping human experts on complex attack paths.
Secure digital fortress open source code ai scanning cloud

GitHub backs Alpha-Omega with fresh open source funds

Last month
#
siem
#
hyperscale
#
application security
GitHub joins tech giants in a USD $12.5 million Alpha-Omega push, boosting AI-powered defences for critical open source software.
Moody night coding workstation puzzle piece supply chain risks

Open source dependencies leave apps dangerously exposed

Last month
#
uc
#
digital transformation
#
application security
Secure.com warns most apps hide critical flaws in open source components, as unpatched dependencies and licence risks leave firms exposed.
Software supply chain security python java js ai circuits lock

Chainguard extends secure libraries to Python, Java, JS

Fri, 27th Feb 2026
#
application security
#
devsecops
#
supply chain
Chainguard expands its rebuilt-from-source Libraries to Python, Java and JavaScript, targeting malware risks in AI-driven software supply chains.
Photorealistic secure locked shipping containers digital code software java security

Azul & Chainguard partner on zero-CVE Java containers

Thu, 19th Jun 2025
#
devops
#
supply chain
#
apm
Azul and Chainguard have teamed up to offer zero-CVE Java containers, enhancing security and support for enterprise Java workloads with Hardened, source-built images.
Illustration computer server shield secure data flow java applications tech

Azul boosts Java security with improved runtime vulnerability detection

Fri, 13th Jun 2025
#
devops
#
application security
#
apm
Azul's Intelligence Cloud now cuts Java security false positives by up to 99%, using runtime data to boost vulnerability detection accuracy for DevOps teams.
Computer screen shield icon protection software vulnerabilities code symbols illustration

Azul unveils Java tool to cut false positives by up to 99%

Wed, 11th Jun 2025
#
devops
#
application security
#
apm
Azul has launched a Java vulnerability tool that cuts false positives by up to 99%, improving threat detection accuracy for production environments.
Techday 0140157319e50cf2954b

Qualys launches report to tackle tech debt & cyber risks

Wed, 10th Jul 2024
#
advanced persistent threat protection
#
cto
#
cyber threat
Qualys has launched a no-cost Tech Debt Report to help organisations identify and mitigate cyber risks from outdated technology.
Techday 67c3a1a5a5f5de6e9b38

Sonatype launches SBOM Manager to enhance software security

Mon, 8th Jul 2024
#
saas
#
partner programmes
#
supply chain
Sonatype releases its SBOM Manager, a crucial tool to help organisations track and manage software components.
Img agcpkv4gaaocymyfropl0cdr

Check Point introduces API Discovery to bolster cloud security

Thu, 23rd May 2024
#
firewalls
#
digital transformation
#
cloud security
Check Point fortifies its CloudGuard WAF with a new API Discovery feature, aiming to enhance cloud security by identifying and mitigating API vulnerabilities.
Img jjdptjst3gtcy7zyqrkrnzi5

Cato Networks reveals insecure protocols widespread in inaugural SASE report

Wed, 15th May 2024
#
firewalls
#
network security
#
casb
Cato Networks exposes systemic cybersecurity gaps in inaugural threat report, revealing insecure protocols employed across WAN by all examined organisations.
Img bhx8z7s0mmacazmvlpkmqwln

New Relic report uncovers ongoing trends in Java adoption

Wed, 1st May 2024
#
encryption
#
fintech
#
martech
New Relic's fourth annual State of the Java Ecosystem report reveals latest trends in Java development and adoption, highlighting significant growth in Java 21's uptake and shifts in preferred Java Developer Kits.
Img fnaphtzptgghc9gzbbryoj1n

Cloudflare reports 25% spike in global traffic & rise in cyber threats in 2023

Mon, 18th Dec 2023
#
hyperscale
#
public cloud
#
it automation
Cloudflare reveals a 25% surge in global internet traffic and heightened cybersecurity threats in its 2023 report.
Erin stephan

Beware the lasting legacy of the Log4j vulnerability

Mon, 18th Dec 2023
#
application security
#
open source
#
software development
Efforts to mitigate the Log4j vulnerability involve updating to patched versions of Log4j, but the process continues to be complex.
Sbom

The IT industry is stalling on SBOMs when it should be working on best practice

Tue, 24th Oct 2023
#
open source
#
software
#
it industry
SBOMs will be key to dealing with the next big vulnerability and incredibly useful in the fight to minimise the effects of smaller weaknesses.
Gettyimages 1363253197

Microsoft Exchange and Log4j continue to be top points of compromise

Fri, 24th Mar 2023
#
mfa
#
advanced persistent threat protection
#
email security
Arctic Wolf, a global specialist in security operations, has published its annual Arctic Wolf Labs Threat Report, revealing a year of turbulence.
Gettyimages 1221761167

FortiGuard Labs reports an increase of 50% in wiper malware

Fri, 24th Feb 2023
#
malware
#
firewalls
#
ransomware
Ransomware threats remain at peak levels with no evidence of slowing down globally with new variants enabled by Ransomware-as-a-Service (RaaS).
Gettyimages 1359303694

Iran-sponsored group using GitHub to deploy custom malware

Tue, 13th Dec 2022
#
advanced persistent threat protection
#
apm
#
software development
The Secureworks Counter Threat Unit (CTU) has uncovered a subgroup of Iranian Cobalt Mirage using GitHub to store and deploy malware.