eCommerceNews Asia - Technology news for digital commerce decision-makers

Common Vulnerabilities and Exposures (CVE) stories

Dark office night remote access shadowy hacker silent data theft

Data-only extortion surges as remote access abused

Yesterday
#
cve
Data-only extortion soars 11-fold as attackers ‘log in instead of break in’, abusing remote access tools for faster, stealthier raids.
Transparent container with cubes and magnifying glass security scan

Endor Labs buys Autonomous Plane for container security

Last week
#
cve
Endor Labs acquires Autonomous Plane to add reachability-led container image analysis, promising fewer false positives for security teams.
Looming wave digital vulnerabilities cracked software cubes

Cybersecurity teams brace for surge in global CVEs in 2026

Last week
#
cve
Cyber group FIRST warns CVE disclosures could smash records in 2026, topping 50,000 and potentially surging towards six figures.
Encs and divd sign mou to strengthen vulnerability disclosure for europe s critical infrastructure

New ENCS-DIVD pact targets energy cyber weaknesses

This month
#
cve
ENCS and DIVD have agreed a new cyber pact to uncover and disclose vulnerabilities in Europe’s high-impact energy and critical systems.
Cto reviewing enterprise dashboard third party software risk cloud

Black Kite unveils tool to analyse third-party software risk

Last month
#
cve
Black Kite launches Product Analysis tool to expose hidden risks in third-party software, from SaaS subdomains to SBOM dependencies.
Eu 2026 cybersecurity digital fortress ai threats supply chain

Codific predicts nine key cybersecurity shifts for 2026

Wed, 24th Dec 2025
#
cve
Codific sees 2026 cybersecurity shaped by shadow AI, passwordless logins, tighter regulation and a sharper focus on software supply chains.
Global cybersecurity network taiwan shielded datacenter response

Zyxel joins FIRST, boosting global product security role

Fri, 19th Dec 2025
#
cve
Zyxel becomes FIRST’s first Taiwan-based networking member, aiming to speed cyber incident response and bolster global product security.
Digital illustration crowded computer screen shopping carts locks warnings cybersecurity black friday

Retailers brace for cyber threats during Black Friday sales rush

Wed, 26th Nov 2025
#
cve
Retailers and shoppers brace for rising cyber threats as Black Friday and Cyber Monday prompt a surge in online transactions and security vulnerabilities.
Overwhelmed security professionals warning screens tangled lines vulnerabilities office

Rising software vulnerabilities strain security teams & budgets

Tue, 25th Nov 2025
#
cve
Nearly half of UK and APAC organisations report rising software vulnerabilities are straining security teams, causing burnout, delays, and regulatory fines.
Secure digital vault container stacks shield protection cloud servers

Minimus launches Image Creator for custom container images

Thu, 20th Nov 2025
#
cve
Minimus unveils Image Creator, enabling enterprises to build secure, custom container images with enhanced compliance and reduced vulnerabilities.
Rekha shenoy headshot 1200x677 2

Gaining control: The human role in AI-driven automation

Wed, 19th Nov 2025
#
cve
Many network owners fear AI automation may disrupt vital systems; experts urge human-centred control to ensure safety and trust in AI-driven operations.
Cloud security multiple padlocks open broken people keys digital network

Cloud breaches driven by identity failures & process flaws

Thu, 6th Nov 2025
#
cve
ReliaQuest reveals identity compromises and process flaws, not zero-day exploits, drive most cloud breaches, with 99% of cloud identities still over-privileged.
Cybersecurity operations center computer screens alerts shields charts

Rapid7 adds AI risk summaries to Command Platform for faster response

Thu, 30th Oct 2025
#
cve
Rapid7 has added AI-generated risk summaries to its Command Platform, helping security teams speed up prioritisation and remediation of vulnerabilities.
Magnifying glass examining software vulnerability warnings unverified flaws

Study finds CVE security scores flawed, with third unsubstantiated

Fri, 17th Oct 2025
#
cve
Nearly one-third of CVE entries are unverified, revealing flaws in how organisations assess software security risks and reliance on CVSS scores.
Interconnected abstract computer servers clouds digital locks gears security innovation global software development

Azul launches TAP Program to boost global Java innovation & security

Wed, 24th Sep 2025
#
cve
Azul launches its Technology Alliance Partner Program to enhance global Java innovation, boosting performance, security, and cost-efficiency for enterprises.
Computer shield digital data streams ai elements network web cybersecurity protection

Preemptive cybersecurity to reach 50% of IT security spend by 2030

Fri, 19th Sep 2025
#
cve
Preemptive cybersecurity is set to command 50% of IT security spend by 2030, driven by AI and machine learning to counter rising cyber threats, says Gartner.
Realistic hospital building digital padlocks hackers iot medical devices warning

Global ransomware attacks rise as healthcare faces surge in cyber threats

Fri, 22nd Aug 2025
#
cve
Ransomware attacks surge to 20 daily incidents in 2025H1, with healthcare facing increased cyber threats and hackers targeting overlooked IoT devices worldwide.
Illustration interconnected computer servers red warnings vulnerability digital supply chain network

Black Kite unveils ASI for targeted third-party cyber risk

Sat, 9th Aug 2025
#
cve
Black Kite has launched its Adversary Susceptibility Index to help firms spot which suppliers are most exposed to specific cyber threat actors, enhancing risk management.
Interconnected servers cloud symbols protective shields cybersecurity collaboration

Aqua Security unveils Trivy Partner Connect to boost open source

Tue, 8th Jul 2025
#
cve
Aqua Security launches Trivy Partner Connect to strengthen the ecosystem around its popular open source security scanner, Trivy, boosting collaboration and innovation.
Interconnected on premise servers cloud icons glowing shields network security

BackBox 8.0 automates hybrid network security & compliance

Thu, 26th Jun 2025
#
cve
BackBox 8.0 unifies and automates security and compliance across hybrid networks, helping firms manage on-premise and cloud assets with a single dashboard.