As CISA kicks off Critical Infrastructure Security and Resilience Month, the agency is offering advice to critical infrastructure organizations on how to remain resilient.
from Cybersecurity News https://ift.tt/ZyD4fJm
Live Player 3.2 extension and toolbar is a corrupt browser application that ruins Firefox, Google Chrome and Internet explorer, etc. The Live Player 3.2 virus comes as a free TV channel player which offers its user watch various international TV shows and programs without paying anything. But soon after this program has been installed, you,ll
As CISA kicks off Critical Infrastructure Security and Resilience Month, the agency is offering advice to critical infrastructure organizations on how to remain resilient.
Recent research shows that bots could disrupt Black Friday gaming sales.
Security leaders weigh in on the Amazon data breach, offering insights on the cause, ramifications and potential preventative measures.
As security leaders look ahead to 2025, the regulatory and compliance landscape is set to undergo a significant transformation.
Research reveals more than 6,000 domain registrations in the past 90 days, targeting the retail industry.
Research has unveiled a tool responsible for many recent GitHub phishing attacks.
Websites see a rise in bot attacks.
Cybersecurity researchers have discovered a malicious Python package.
Microsoft observed malicious activity targeting and stealing credentials from Microsoft customers.
Google announced mandatory multi-factor authentication (MFA) is coming to Google Cloud accounts. Security leaders discuss the implications.
The CISA Director, Jen Easterly, released a statement following the 2024 elections.
A new report reveals that malicious actors are exploiting APIs in DocuSign to send fake invoices.
The City of Columbus, Ohio, has notified 500,000 individuals that a ransomware attack in July 2024 stole their personal information.
A global operation called EMERALDWHALE has resulted in the theft of more than 15,000 cloud service credentials.
Two-thirds (67%) of third-party energy sector breaches were caused by software and IT vendors.
Security leaders discuss the recent Cisco security incident.
A report by Secureworks revealed a 30% year-over-year rise in active ransomware groups, which demonstrates fragmentation of an established criminal ecosystem.
According to recent data, a wave of artificial intelligence (AI) adoption is radically shifting how software goes from ideation to deployment.
Nearly all CISOs (99%) are worried about losing their positions if a breach occurs, with 77% of CISOs being very or extremely concerned.
According to a recent report, 53% of European organizations are confident employees are not properly utilizing generative AI.
A new macOS vulnerability could allow a malicious actor to evade an operating system’s Transparency, Consent, and Control (TCC) technology.
The SEC has charged four public companies with misleading disclosures about cyber risks and intrusions.
In episode 25 of the Cybersecurity & Geopolitical Discussion, our trio of hosts pull apart the rapidly deteriorating situation in the Middle East.
A survey shows that nearly half (49%) of CISOs do not believe there is a future for them in this role. CISOs are sharing their insights on this statistic.
Iranian cyber actors are targeting critical infrastructure entities via brute force.
Researchers at the University of Texas at Austin discovered a new attack method.
According to a recent report, 34% of chief information officers (CIOs) ranked securing the network as their number one priority.
Due to evidence of active exploitation, CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalogue.
Every chief information security officer knows it isn’t a matter of “if” but “when” the systems that run their business will be disrupted in some way.
93% of hackers believe AI tools used by companies have opened up a new attack vector for malicious actors to exploit.
The effect of cybersecurity incidents on healthcare organizations was analyzed in a recent Proofpoint report.
Phishing remains the primary method used by attackers to gain initial access to networks, according to a recent report.
Cybersecurity researchers have discovered that Apple’s new “Mirroring” feature could expose an employee’s personal applications.
A report found that 33.9% of tech professionals report a shortage of AI security skills, particularly around emerging vulnerabilities like prompt injection.
A report found that 53% of organizations met ransom demands of more than $500,000 USD to recover access to encrypted systems and files.
Twenty-seven percent of employed survey respondents use privacy tools and settings to protect workplace information when using generative AI.
New research has found a skills gap in AI security skills.
According to a recent Envoy report, shifting workplace dynamics such as hybrid work policies have led to outdated data management processes.
14 additional network vulnerabilities in DrayTek routers were discovered in a recent Forescout Technologies report, putting user data at risk.
2023 saw an increase in DDoS attacks.
Issues faced by IT leaders in the U.K. were analyzed in a recent Hyve Managed Hosting report, including the current cybersecurity talent gap.
Phishing attacks targeted the finance industry in H1 2024.
CISA has issued a warning regarding a known, exploited vulnerability.
Security practices were analyzed in a recent report, finding that one in two office workers admit to using personal devices to log into work networks.
Global threats were analyzed in a recent Elastic report. The report focused on security tools, malware attacks and cloud environment security.
The stress of cybersecurity professionals was analyzed in a report finding that 38% of organizations are experiencing increased cybersecurity attacks.
A report found that 44% of IT security professionals rely on manual logging for service account visibility, while 10% admit to no visibility measures at all.
The use of artificial intelligence (AI) by information technology (IT) professionals in the U.S. was analyzed in a recent report by GetApp.
Survey data shows a significant rise in the prevalence of video deepfakes, with a 20% increase in companies reporting incidents compared to 2022.
During National Cybersecurity Awareness Month, cybersecurity experts are reflecting on prominent threats and how they can be mitigated.
A study found that Meta (Facebook, Instagram and Facebook Messenger), YouTube and Discord keep users’ data for 180 days after they have deleted their accounts.
A recent threat report reveals that a minimum of 14 million patients in the U.S. have fallen victim to malware breaches in this sector.
Chief Information Security Officer (CISO) concerns over artificial intelligence (AI) were analyzed in a recent report by Team8.
In 2024, ransomware attacks affected 44% of U.S. companies, with 43% of those paying a ransom according to a recent threat report.
More than 1,000 ServiceNow Knowledge Base articles were found to be misconfigured.
Security’s Top 5 from Security magazine showcases the top stories and new developments from across the security industry.
A report found that companies collected and could indefinitely retain troves of data, including information from data brokers, and about both users and non-users of their platforms.
A recent study found that the majority of people worldwide (58%) are more fearful of becoming fraud victims now than they were two years ago.
Motorists in the United Kingdom are being targeted with QR code scams.
Claims of hacked voter data are intended to cause distrust in the election process, the FBI and CISA warn.
GitLab releases a security update for a critical flaw. Security leaders share advice on how organizations can secure against this vulnerability.
New research discusses the state of email security amongst critical infrastructure organizations.
Bot security was analyzed in a recent report by DataDome, finding that more than 65% of websites are unprotected against simple bot attacks.
New research shows how the cyber threat landscape is evolving, requiring greater proactive security strategies from organizations.
A recent report also reveals that the challenge of protecting sensitive data will only get more complex with the rise of artificial intelligence (AI).
A new survey reveals IT leaders’ concerns about cybersecurity in education.
Security leaders weigh in on the Highline Public Schools cyberattack.
Security leaders discuss the maximum severity vulnerability in Progress Software products.
A report found that fraudsters are calling potential victims directly and luring them with messages containing a phone number for the target to call.
A new survey highlights the relationship between connectivity and cybersecurity.
Research identified a malvertising campaign targeting employees of Lowe’s.
A cybersecurity researcher discovered an exposed Confidant Health database containing thousands of records.
Planned Parenthood of Montana experienced a cyber attack that allegedly exposed 93 gigabytes of data.
The White House Office of the National Cyber Director has released a guide to improve the security of the Border Gateway Protocol, and security leaders are sharing their thoughts.
Research reveals the impact the global economy is having on security budgets.
New research shows the growth of a new malware campaign called “Voldemort.”
The FTC will require security camera firm Verkada to develop and implement a comprehensive information security program.
A survey reveals IT and corporate leadership attitudes toward organizational security preparedness.
New research highlights a sophisticated, ongoing phishing campaign that has targeted over 130 organizations.
Young Consulting revealed that an unauthorized actor gained access to Blue Shield of California subscriber data in April 2024.
Recent investigations reveal that the BlackByte ransomware group is deploying techniques that vary from its typical methods.
A recent cybersecurity report found that 98% of organizations attacked by bots in the past year lost revenue as a result.
In 2024, the software supply chain has faced attacks at a minimum rate of one every two days.
CISA and partners host security exercise to improve election security, called Tabletop the Vote.
As International Women in Cyber Day draws closer, security professionals are reflecting on the progress made as well as the challenges women continue to face in the industry.
Security leaders discuss the Texas Dow Employees Credit Union breach that impacted more than 500,000 members.
More than 650,000 records across various educational institutions have been exposed in the last 60 days.
MSP security was analyzed in a recent report finding that 76% of MSPs spotted a cyberattack on their infrastructure within the last 12 months.
Susan Chiang has been appointed Chief Information Security Officer at Headway, a mental health organization.
As Labor Day approaches, new data warns that cybercriminals are exploiting increased traffic to cover their attacks.
A new report highlights the rising threat of cyber incidents against critical infrastructure.
Halliburton, one of the most prominent oilfield service companies, was the subject of a recent cyberattack.
A survey shows 63% of security practitioners experience burnout and reveals the key steps to retaining security talent.
As the election season draws closer, the increase in political donations may attract cyber criminals.
Research reveals the 5 most prominent ransomware groups and malware delivering ransomware.
A survey shows that a majority of Americans are worried about an increase in fraud.
A new report details the top threat trends observed in the first half of 2024, including the most targeted industries.
Researchers discovered 8 vulnerabilities in macOS operating system Microsoft apps, and security leaders are sharing their insights.
Security’s Top 5 from Security magazine showcases the top stories and new developments from across the security industry throughout June.
New research reveals that malicious actors are imitating tech companies in an effort to compromise corporate systems.
National Public Data experienced a breach potentially affecting 2.9 billion individuals.
Security leaders weigh in on a recently revealed authentication bypass in Microsoft Entra ID.
A survey has revealed that 2 out of 3 Americans cannot distinguish AI voices from real voices.
A recent report report found that 91% of cyberattacks – up from 69% in 2023 – targeted multiple customers using mass scanning techniques.
Security leaders weigh in on a recent ransomware encounter deploying an EDR-killing tool.
A report found that 72% of surveyed cybersecurity professionals in the U.S. have been targeted by cyberattacks in the past 18 months.
A Nashville man has been charged with aiding North Korean “laptop farms.”
A recent report reveals a sharp increase of 46% in the number of DDoS attacks compared to the same period in 2023.
AI readiness was analyzed in a report by Pluralsight. The findings show that 56% of security professionals are concerned about AI-powered threats.
The Federal Trade Commission (FTC) is working on protections against artificial intelligence (AI) based fraud.
McLaren Health Care experienced a criminal cyberattack and is working to recover functionality.
The FCC proposed a first-of-their-kind ruling on AI-generated robocalls and robotexts.
The exploitation of old common vulnerabilities and exposures (CVEs) rose by 10% from 2023 to 2024.
On behalf of the FTC, the Department of Justice sued video-sharing platform TikTok with violating the Children’s Online Privacy Protection Act.
A new report reveals an increase in ransomware incidents and shows security leaders deal with incidents an average of eight times each year.
According to a recent report, 40% of BEC emails are generated by AI.
An analysis of 17.8 million phishing emails found 62% were able to pass verification checks for domain-based message authentication, reporting and conformance (DMARC).
Security leaders respond to a report that states 86% of cyber professionals consider unknown cyber risks to be a top concern.
A recent cybersecurity report found that 83% of businesses recognize the importance of informing their supply chain about how AI is being used.
99% of Global 2000 organizations have been directly linked to a supply chain breach.
Alex Stamos has been hired as Chief Information Security Officer (CISO) at Sentinel One.
4.3 million individuals were impacted by a HealthEquity data breach, and security leaders are sharing their insights.
Security leaders share their insights on the North Korean hacker that nearly infiltrated KnowBe4.
A recent survey reveals the top sources of business payment fraud.
Cyber threats in Q2 2024 were analyzed in a recent report that indicates a 21.07% increase in exploit activity compared to Q1.
A ransomware attack caused Superior Court of Los Angeles County to close all 36 courthouse locations.
A threat intelligence report offers insights into the evolving cyber landscape surrounding the Paris 2024 Olympics.
The Play ransomware group is deploying a Linux variant that targets ESXi environments.
There is growing concern that AI may undermine democratic elections.
Research from unveils a security flaw within the popular web analytics provider, Hotjar.
With a year in the rearview mirror, security professionals are reflecting on the SEC cyber disclosure ruling.
Sensitive data, including personal and health information, was exposed in a cyber incident against MediSecure.
Security leaders have shared their thoughts about the Microsoft-Crowdstrike outage and advice for other organizations to protect themselves.
The SEC has established the Interagency Securities Council (ISC) to support collaboration between federal, state and local agencies.
A new report analyzes data breach incidents occurring in the first half 2024.
An awareness campaign displays fraud data across a range of countries, industries and categories.
Windows users are being targeted with zero-day attacks. Security leaders are sharing their insights.
A judge has dismissed a majority of the SEC lawsuit against SolarWinds.
Security leaders share their insights on a new phishing kit on the dark web.
Thursday, July 18, users worldwide experienced a technology outage affecting flights, banks, hospitals and more.
Security leaders share their insights on the recent AT&T data breach.
A recent report found that many applications contained vulnerabilities spanning various stages of the kill-chain, leaving them vulnerable to attack.
The FTC and the LA DA’s office allege that NGL actively marketed their service to kids despite being aware of the harms from similar services.
According to a report, 73% of life sciences companies are turning to artificial intelligence (AI) to address the cybersecurity skills gap.
At GSX, leaders will immerse themselves in a nexus of timely insights, forecasting the ominous trends that loom on the horizon.
Research has unveiled a potential vulnerability within a training platform called SkillTree.
Identity and vulnerability management were analyzed in a recent report.
Nearly 10 billion unique, plaintext passwords were uploaded to a hacker forum.
The security of unauthorized (unapproved by IT) Software as a Service (SaaS) applications were analyzed in a recent report by Next DLP.
The CISA has released its Guide to Operational Security for Election Officials.
Patelco Credit Union announced that on June 29, 2024, the company faced a ransomware attack. Hackers gained access to its systems and blocked access.
Ann & Robert H. Lurie Children’s Hospital of Chicago was impacted by a ransomware attack.
A new report finds that organizations are increasing their cyber budgets in order to keep pace with the shifting threat landscape.
A new report details 3 sophisticated nation-state campaigns, and security leaders share their insights.
1 in 3 security leaders believe that half of organizations are willing to trade their customer’s privacy in order to save money.
A recent report found that 78 percent of organizations are tracking AI as an emerging risk while simultaneously adopting the technology themselves.
Life360 was impacted by a data breach. Security leaders are sharing their insights.
New Federal Trade Commission (FTC) data reveals that government impersonation scammers are targeting consumers for payments in cash.
Nearly all Americans (87%) believe brands are responsible for protecting users’ digital privacy in the age of artificial intelligence (AI).
In episode 23 of the Cybersecurity & Geopolitical Discussion, our trio of hosts debate pull apart the scenario of the upcoming UK election to uncover what the impact could be on national and global security.
Fraud attempts have increased this year, leading to financial repercussions.
Research shows that more than 70% of organizations are increasing spending on proactive security solutions.
Security leaders respond to a new report showing only 19% of MITRE ATT&CK tactics are covered by SIEMs.
Security leaders respond to recent data showing the cybersecurity industry needs 225,000 professionals.
A Russian disinformation campaign is attempting to disrupt the Paris Olympics, and security leaders are sharing their thoughts.
A new report measures the likelihood that an organization’s employees would fall for a phishing or social engineering scam.
Research has revealed the development of a new ransomware variant called Fog.
As the Paris Olympic games draw closer, security leaders warn that the event faces a high risk of targeted cyber incidents
To close the talent gap, the cybersecurity industry needs an estimated 225,200 security professionals.
A recent survey found that half of the survey respondents reported it was more difficult to manage their attack surface today than it was a year ago.
A new report reveals current password security trends, such as password reuse and frequent password changes due to security breaches.
Although RansomHub is a relatively new Ransomware-as-a-Service (RaaS), it has quickly grown into one of the most prolific ransomware groups currently active.
A new report surveys financial service consumers with the purpose of understanding their priorities and concerns.
A new report highlights trends in AI-powered attacks and cybersecurity strategies.
The Seattle Public Library experienced a cyberattack that forced it to shut down its systems.
Artificial intelligence (AI) security and employee preparation was analyzed in a recent survey by SHI International and Dell Technologies.
A new survey reveals that account takeovers are a prominent threat.
The ShinyHunters threat operation has claimed to hack Ticketmaster, and security leaders are sharing their thoughts.
A recent report finds notable gender disparities in the cybersecurity industry.
A coordinated international operation had led to the apprehension of the alleged 911 S5 botnet administrator.
39% of MSPs state that their greatest challenge is keeping up with emerging cybersecurity solutions and technologies.
Piano-themed messages are being sent to lure targets into falling for an email scam.
New research reveals the most hacked pop culture passwords in 2024.
Security leaders respond to the claim that a ransomware group has accessed the data of at least 500,000 of Christie’s customers globally.
A Safety and Security committee has been formed by the OpenAI Board. Security leaders are sharing their thoughts.
The Federal Trade Commission (FTC) released data on which brands were most often impersonated by scammers, and which scams were the most costly.
A recent study suggests that leading LLMs may come with security concerns, and security leaders are sharing their insights.
Public sector security debt and application risk management was analyzed in a recent report by Veracode, finding 3% of applications are flaw free.
A new report discusses cyberattack trends in the United States, with healthcare and finance industries being hit the hardest.
90% of organizations reported an identity-related event in the last year.
WD Associates announced a recent data security incident involving personal information including Social Security numbers and insurance information.
A report surveyed 1,600 CISOs worldwide in order to shed light on their experiences, insights and predictions.
Security leaders respond to the announcement that the City of Wichita, Kansas, was targeted by a ransomware attack.
A study has found that increased technological and organizational complexity is contributing to new identity risks that security leaders must manage.
As of April 2024, the ransomware groups Alphv and LockBit have ceded the top spot to a smaller ransomware group.
Malicious actors are utilizing overdue invoice lures, open redirects and LotL tactics in order to bypass cybersecurity defenses.
An investigation by the EPA reveals that a majority of water systems do not meet compliance standards. Security leaders are sharing their thoughts.
A new report examines how security budgets and compliance strategies are impacted by the shifting regulatory landscape.
There has been an increase in malicious emails, including a rise in BEC, phishing and other message-based attacks driven by generative AI.
According to a recent healthcare cybersecurity report, more than 25% of ransomware attacks directly impact patient care, including lost data.
New research highlights the cybersecurity risks that organizations are facing due to the rise in sophistication among malicious actors.
A recent report found that the top drivers for cloud-based backup are the desire to integrate cyber technologies with data protection and backup.
Generative AI bots can be manipulated by users of any skill level — not just cyber experts.
A concentration of cyber risk and an increase in the exploitation of third-party vulnerabilities may pose a threat to national security and the global economy.
The CISA announced that 68 leading software manufacturers voluntarily committed to CISA’s Secure by Design pledge.
59% of organizations experienced a software supply chain attack, with 54% of these respondents having experienced one in the past year.
A sophisticated phishing campaign is bypassing multi-factor authentication in order to target Meta business accounts.
According to a cybersecurity and threat intelligence report, the U.S. was the 4th most targeted country in the world regarding phishing attacks.
A global consumer research study reveals consumer attitudes about generative AI, showing that many are concerned about being fooled by deepfakes.
The Federal Trade Commission (FTC) has ordered Cerebral, Inc. to restrict how the company can use and/or disclose sensitive consumer data.
A report detailing tech CISO compensation, mobility and job position satisfaction shows that a quarter of CISOs are unhappy with their compensation.
A survey of 700 IT decision-makers reveals the state of identity fraud. Notably, almost all organizations face challenges with identity verification.
There has been an increase in “selfie spoofing” scams, or scams in which a fraud actor takes a target’s selfie in order to authenticate a stolen identity and open fraudulent accounts.
Companies experience a rise in data breaches.
A new report reveals that a majority of data experts agree that artificial intelligence is increasing data security challenges.
An analysis of more than 40 million exposures provides a view the current exposure landscape, revealing 80% are driven by misconfigurations.
The 2024 Data Breach Investigations Report reveals the role that the human element plays in cyber threats, and security leaders are weighing in.
Organizations are utilizing data to promote innovation; however, less than 2% can access sensitive data within a week’s time.
A new report shows that within the last 12 months, a majority of organizations reworked cybersecurity strategies.
New data analyzing ransomware group activities has found that activity from the ransomware gang RAGroup has risen by 300% since December.
In this edition of Security’s Top 5 from Security magazine, we showcase the top stories and new developments from across the security industry throughout March.
An evaluation of nearly 4,900 ransomware attacks reveals information about malicious actors and their new techniques, their evolving operations and their global impact.
Many organizations are vulnerable to risk, yet a majority of cyber leaders express confidence that their organization can manage risk.
MITRE Corporation announced that it was the target of a nation-state cyberattack, and security leaders are sharing their insights.
LabHost, a notable phishing-as-a-service platform, was disrupted by international investigations. Security leaders respond.
A new report surveyed more than 400 CISOs from the United States and the United Kingdom to gauge their challenges, priorities and initiatives.
Security leaders predict that AI will become a more prevalent tool in the tool kit of cybercriminals, potentially powering a range of cyberattacks.
In episode 22 of the Cybersecurity & Geopolitical Discussion, our trio of hosts debate the geopolitical and security dimensions of the current global space industry.
The FTC issues refunds after a settlement with Ring over charges the company allowed employees and contractors to access consumers’ private videos.
Many small and medium-sized enterprises lack the resources and abilities to properly handle the large volume security alerts received.
According to a recent study, 80% of cybersecurity decision makers say accelerating AI adoption is critical to their organization’s resilience.
Research has discovered a vulnerability in an Apache project that could lead to remote code execution inside of the production environment.
Security leaders in small and medium-sized enterprises are overwhelmed by the volume and complexity of security demands.
In a recent report, two-thirds of IT leaders express a lack of confidence in the United States government's ability to defend against cyberwarfare.
The number of victims experiencing ransomware incidents has risen since Q1 of 2023, rising by nearly 20% by Q1 of 2024.
A recent report has emphasized the prevalence and importance of pentesting among enterprise security teams.
The widespread financial burden of cybercrime in the U.S. was recently analyzed by NoDepositRewards using data from the 2023 FBI crime report.
Although cybersecurity is vital to an organization’s financial success, many companies do not have a designated cyber expert.
A recently detected vulnerability in many Linux distributions may open the door for malicious actors to gain unauthorized access.
The White House held a press call in regard to the federal government's approach to AI, and security leaders are sharing their thoughts.
Almost a third of Americans surveyed (31%) admitted to either not following best practices to avoid check fraud or being unsure whether they do so.
The U.S. Department of the Treasury released a report regarding cybersecurity threats in the financial sector, specifically related to AI.
A new report discusses trends in automation and outsourcing within IT teams.
Security leaders respond to the proposed critical infrastructure rules set forth by the DHS.
With rapidly changing restrictions and guidelines, security leaders have to be careful when protecting personally identifiable information.
Recent research has identified a campaign that spans several years and targets end-of-life devices.
The FTC denied an application for approval of a new mechanism for obtaining parental consent under the Children’s Online Privacy Protection Rule.
The CISA and the FBI have partnered with the Multi-State Information Sharing and Analysis Center (MS-ISAC) to release a guideline for organizations to defend against DDoS attacks.
Florida Pediatric Associates (FPA) announced that a data breach experienced by Bowden Barlow Law may have affected FPA health information.
A new phishing-as-a-service platform has been discovered, and researchers are discussing how it works.
Cyberattacks are growing in volume and sophistication, and security leaders must adapt to face increasingly complex threats.
The White House has stated that critical infrastructure may be targeted by malicious actors, and security leaders are sharing their insights on the situation.
A recent report found that fewer women technology professionals reported receiving an increase in pay over the last year compared to men.
New research provides key insights and classifications regarding the threats that identity security teams face.
March Madness, like any other major public event, may provide a platform for malicious actors to work.
Ransomware protection is top of mind for both CXOs and practitioners but most organizations continue to struggle in the wake of attacks.
The CISA has released a set of guidelines to ensure that software developers are creating secure software systems for the government.
Security leaders discuss the actions of the Magnet Goblin threat actor group.
In episode 21 of the Cybersecurity & Geopolitical Discussion, our trio of hosts discuss how modern forces manifest, how much power is truly being wielded, and what effect it is likely to have on a year of elections.
Payment and financial scams were analyzed in a recent report by Visa, finding that adults were losing more money to scams from June to December 2023.
A recent report has analyzed emerging threat trends as well as potential trends that may grow in influence in the coming months.
Experts share their insights on the newly discovered phishing campaign that encourages targets to download a malicious Java downloader.
Charles Henderson was hired as EVP of Cyber Security at Coalfire with experience in threat intelligence, incident response and penetration testing.
Security leaders offer their insights now that the proposed TikTok ban has passed in the House of Representatives.
Phishing emails were on the rise in 2023, and security leaders should ensure their organization can spot the signs of a scam.
Around 13,000 fraudulent investment domains were detected and blocked, revealing a continued trend in consumer fraud.
New research discloses the areas in ChatGPT plugins that could have been exploited.
Distributed denial of service (DDoS) attacks were analyzed in a recent report by Link11, finding a 70% increase in DDoS attacks in the last year.
Patches have been released to address vulnerabilities that could possibly lead to security system breaches.
Rockwell Automation announced that Stephen Ford is joining the company as Vice President and Chief Information Security Officer (CISO).
The CISA announces new plans to secure the open source ecosystem.
Following a cyberattack from Midnight Blizzard, Security leaders share their thoughts.
A statement released by the CISA discusses the importance of election security as well as the organization’s measures to support election officials.
A recent report surveyed 1,000 MSPs, revealing attitudes about the value of cybersecurity.
Staffing shortages and limited skillsets negatively impact security.
A recent announcement from the CISA warns that malicious actors are exploiting vulnerabilities within VPN services.
American Express announced that card members' account and financial data may have been affected by a data breach involving third party partners.
Data loss caused by insider events costs an average of $15 million, highlighting the importance of information protection.
According to a report, 69% of consumers rank good fraud protection in their top three considerations when choosing a financial service provider.
A partnership between the Boston Red Sox and Centripetal seeks to bolster the stadium's cyber network security.
DDoS attacks increased globally in 2023, with the Americas being a common target.
UnitedHealth Group recently experienced a cyberattack caused by Blackcat, and experts are offering their insights on the ransomware group's behavior.
A recent report indicates that malicious actors broadened their techniques and may present more threats to security leaders.
According to a report, 85% of organizations are investing in AI technologies with transformative potential in 2024, despite economic uncertainty.
A survey of more than 1,000 security professionals worldwide has been conducted to gain valuable insights into the energy and utilities sector.
Security leaders weigh in on the recent announcement by the ONCD, which encourages technological manufactures to develop software with memory safety in mind.
A study reveals that 92% of companies surveyed had experienced a breach in the prior year due to vulnerabilities of applications developed in-house.
A recent report studies consumer trends after an organization experiences a data breach, highlighting a breach's impact on reputation and customer base.
Security experts offer their perspective on the recent Biden-Harris executive order, which is intended to secure the nation's ports.
Security experts weigh in on the CISA's advisory, which reveals that cyberattackers are adapting to the increased use of cloud infrastructure.
Cloud storage was analyzed in a recent report finding that 93% of organizations plan to grow their public cloud storage capacity in 2024.
A recent report reveals that third-party attack vectors are involved in at least 29% of breaches, emphasizing the importance of third-party risk management.
A recent survey has revealed that less than half of IT leaders are assured in their IoT security plans.
The Federal Trade Commission (FTC) has banned software company Avast from selling or licensing web browsing data for advertising purposes.
According to a report, nearly 75% of commercial codebases assessed for risk contain open source components impacted by high-risk vulnerabilities.
New information shows that the energy and infrastructure industry is experiencing more cyberattacks utilizing social engineering tactics.
According to the report, more than 90% of enterprises are currently experiencing limitations integrating AI into their technology stack.
A recent report discusses the rise in attacks on higher education institutions in the UK, highlighting the need for cybersecurity strategies.
Though historically isolated, OT systems are now experiencing increased connectivity that introduces new risks.
Organizations have been working to adjust to the new SEC expectations with mixed results.
A survey shows that many Americans would willingly impart identifiable data in exchange for a bargain.
A recent report reveals an increase in initial ransom demand amounts. Furthermore, vulnerabilities detected in 2022 are continuing to be exploited.
Web application attacks were analyzed in a recent report by Edgio. The report found that the most prevalent attack mitigated was path traversal.
Confidence in biometric technology and the security of organizations that store biometric data is declining, according to a new report.
According to a recent cybersecurity report, the total number of common vulnerabilities and exposures (CVEs) is expected to increase by 25% in 2024.
Cyberattackers are getting past defenses quicker than they were in previous years, leaving security leaders with a small window of time to respond.
Industrial cybersecurity was analyzed in a recent report by Dragos Inc, finding that ransomware attacks increased 50% over the last year.
The report uncovers the latest information in email security and malicious email threats, emphasizing emerging techniques that security leaders must defend against.
A recent report reveals how cyberattacks utilizing AI technology were carried out by state adversaries, highlighting the global threat landscape and importance of cybersecurity vigilance.
The 2024 priorities of the Joint Cyber Defense Collaborative aim to secure against immediate and evolving cyber risks.
The malicious email trends seen in 2023 are expected to influence the threats security leaders will see in 2024.
Attack methods used by cybercriminals in Q4 of 2023 reveal evolving trends.
This Valentine's Day, the FBI warns online users about romance scams and the associated losses.
Kent Goodrow has been appointed Chief Information Security Officer at Systems Engineering. Goodrow is pursuing a Master's in Cybersecurity Management.
A recent report analyzes the trends regarding generative AI usage and how it may influence organizational security.
Info-Tech research group analyzed the priorities of several chief information security officers (CISOs) for 2024 in their recent report.
According to a recent cybersecurity report by Data Theorem, 91% of organizations experienced a software supply chain attack over the last year.
Millions of users of the LectureNotes Learning App have had their sensitive information leaked in this data breach.
A new report reveals that 2023 saw the highest amount of phishing emails sent globally.
The United States Department of State is offering monetary rewards for those who can aid in the location and apprehension of Hive ransomware members.
CISA published a cybersecurity advisory alongside other agencies due to malicious activity by a PRC state-sponsored cyber actor known as Volt Typhoon.
A recent ruling by the FCC has made AI-generated voices in robocalls illegal, providing more opportunities for law enforcement to bring scam artists to justice.
Fraud calls around the globe were analyzed in a recent report. According to the report, there were 7.3 billion unwanted calls globally in Q3 2023.
According to a recent report, ransomware attacks almost doubled from 2,200 to 4,200 in 2023. The United States faced the highest number of attacks.
The number of blocked IP addresses suspected of malicious traffic such as DDoS attacks surged from 18.5 million to 40.15 million from Q2 to Q3.
Governor Laura Kelly recently announced that John Godfrey is the new Chief Information Security Officer (CISO) for the State of Kansas.
According to a recent report, 79% of respondents said their company had been the ‘victim of a ransomware attack’ between June and December 2023.
Security leaders share their thoughts on the recent Schneider Electric ransomware attack and how other organizations can protect themselves.
Yoav Kalati, VP Product at Wing Security, discusses the security challenges and red flags organizations face when it comes to offboarding employees.
ChloƩ Messdaghi has been appointed Head of Threat Intelligence at HiddenLayer. Messdaghi is focused on sharing the latest security for AI research.
According to a report, while Q4 ransomware attacks were down slightly from Q3 2023, ransomware activity for the year surpassed 2022 totals by 68%.
According to a report, the number of organizations claiming to have been a victim of ransomware in the past 12 months more than doubled.
A new report shows ransomware attacks are increasing again and reveals a change in strategy among cybercriminals.
Following an executive order aimed to manage the risk of artificial intelligence (AI), the Biden-Harris administration recently announced key AI actions.
According to a recent report, government industries saw a 151% increase in vulnerability submissions in 2023, making it the fastest growing sector.
With the ever-changing threat landscape, Data Privacy Day looks a little different each year as technology such as artificial intelligence develops.
Growing cybersecurity and data privacy concerns have influenced recent litigation, according to a recent survey by Norton Rose Fulbright.
Cybersecurity conferences provide security leaders around the world with an opportunity to connect with one another, from students to executives.
Critical infrastructure attacks were analyzed in a recent report. The report found more than 420 million attacks between January and December 2023.
Browser security was analyzed in a recent report. The report uncovered a 198% increase in browser-based phishing attacks in the second half of 2023.
According to a threat report by Expel, identity-based incidents accounted for 64% of all investigated, a volume increase of 144% from 2022 to 2023.
According to a recent password report by Specops Software, passwords remain the primary authentication method for 88% of organizations.
As the ransomware attack continued that day, hour by hour, Fremont County’s inter-departmental safety services were brought securely back online.
According to a recent cybersecurity report by Armis, geopolitical issues are affecting the cybersecurity landscape, including increased cyberattacks.
The Federal Trade Commission (FTC) has banned Texas company InMarket Media from selling precise location data for advertising purposes.
According to a recent data privacy report, 43% say their privacy budget is underfunded and 51% of respondents expect a decrease in budget.
A report found that 68% of IT workers feel overwhelmed by the number of technical resources that are required to access the data they need to work.
According to the Allianz Risk Barometer, cyber incidents (ransomware, data breaches and IT disruptions) are the top global concern of 2024.
According to a recent report, there 2343 4,368 ransomware victims in 2023, a 55% surge from 2022. Business services suffered the most attacks.
An Alabama-based law firm announced that the company experienced a data breach affecting client information, including insurance information.
The FTC has prohibited X-Mode Social and Outlogic from selling or sharing sensitive data to settle allegations regarding precise location data.
According to a recent Forescout report, the second wave of 2023 Danish energy sector cyberattacks took advantage of unpatched firewalls.
Data privacy within the automotive industry was analyzed in a report, finding that 72% of drivers are uncomfortable automakers sharing their data.
In episode 19 of The Cybersecurity and Geopolitical Discussion, our trio of hosts examine how compelling world events could impact global security.
According to a Mark43 report, 82% of first responders worry that their organization’s data could be stolen or fall victim to ransomware.
Jadee Hanson has been hired as CISO at Vanta. Hanson will oversee security, enterprise engineering, privacy and governance, risk and compliance.
According to a recent report, 87% of organizations indicate plans to enhance vulnerability and exposure remediation efforts within the next year.
In July of 2023, Welltok was alerted to a data breach affected by MOVEit Transfer software, affecting health data and Social Security Numbers.
According to a recent cybersecurity report, the number of organizations confirming five or more breaches jumped by 53% between 2021 and 2022.
According to reports, the personal information of nearly 6.9 million users has been accessed by hackers of 23andMe. Security leaders discuss.
A recent report found that 75% of consumers expressing their readiness to sever ties with a brand in the aftermath of any cybersecurity issue.
The Federal Trade Commission (FTC) announced proposed changes to the Children’s Online Privacy Protection Rule (COPPA Rule), including ed tech.
In December 2023, Court Services Victoria was alerted to a cybersecurity incident impacting Victoria's courts and tribunals, including recordings.
Cyberattacks, data breaches and newly exploited vulnerabilities across the globe were analyzed in a recent report by Check Point Research.
In an ever-evolving digital age, how can CISOs prepare themselves and their employees? What should they take into consideration for the new year?
Bunker Hill Community College (BHCC) in Boston, Massachusetts experienced a data breach in May 2023 that included Social Security Numbers.