All Posts

Cybersecurity News: 3CX’s NK connection, WordPress Elementor hack, DISH faces lawsuits

More evidence ties 3CX supply-chain attack to North Korean hacking group There is more evidence that shows the supply-chain attack on phone technology company 3CX…

Cybersecurity News Week in Review: supply-chain attack on 3CX, AI pause request,  WiFi protocol flaw

This week’s Cyber Security Headlines – Week in Review, March 27-31, is hosted by Rich Stroffolino with our guest, Brett Conlon, CISO, American Century Investments…

Cybersecurity News: 3CX supply chain attack, Vulkan files leaked, Bing hijacked

Supply-chain attack on business phone provider 3CX impacts some big names A supply-chain attack on enterprise phone company 3CX may have exposed the networks of…

Security That Accounts for Human Fallibility

We expect our users to be perfect security responders even when the adversaries are doing everything in their power to trick them. These scams are…

Cybersecurity News: 802.11 flaw, activists targeted in threat campaign, call for an AI “pause”

Flaw found in WiFi protocol According to a technical paper published by researchers at Northeastern University, the IEEE 802.11 protocol contains a fundamental security flaw,…

Cybersecurity News: Microsoft unveils OpenAI-based cyber tools, Google accused of destroying antitrust evidence, A million pen tests show security is getting worse

Microsoft unveils OpenAI-based chat tools to combat cyberattacks On Tuesday, Microsoft announced its new AI Security Copilot, which brings generative AI capabilities to its in-house…

Why Aren’t You On Slack Where I Can Interrupt You?

In order to get any work done we try to shut out all possible distractions. That includes messaging apps. But those people who want to…

Cybersecurity News: Pinduoduo malware, CFTC sues Binance, Twitter takes down source code

Pinduoduo malware confirmed Last week we covered that Google suspended the app for the ecommerce giant Pinduoduo from the Play Store, over alleged malware in…

Cybersecurity News: UK bans TikTok, Windows Snipping patch, Puerto Rico hack

UK bans TikTok from government mobile phones Britain is moving to ban TikTok, the Chinese-owned video-sharing app, the phones of ministers and civil servants. This…

Cybersecurity News Week in Review: post-ransomware lawsuits, cybersecurity as a hindrance, ChatGPT imposters

This week’s Cyber Security Headlines – Week in Review, March 20-24, is hosted by David Spark with our guest, Kurt Sauer, VP, Information security, Workday…

Cybersecurity News: Dole data breach, Nexus banking trojan, Pwn2Own Vancouver 2023

Dole discloses data breach after February ransomware attack Last month, the food multinational Dole Food Company announced that it has suffered a ransomware attack that…

Why YOU Should Be Your Company’s Next CISO

How do you make the argument that your company needs a CISO, and that YOU should be that leader? What do you need to demonstrate…

Cybersecurity News: More markup leaks, Clop victims go public, Big Tech lobbies on spy law

Another image editor leaks data Earlier this week, security researchers revealed that the Markup tool on Pixel devices allowed people to partially recover content edited…

Cybersecurity News: BreachForums to shut down, Zero-day used to drain Bitcoin ATMs, DC Health Link hacker motivated by Russian patriotism

BreachForums to shut down amidst law enforcement concerns The new administrator of BreachForums said they plan to shut down the popular cybercriminal platform after the…

Fast Track Burnout for Your Cyber Team with Layoffs

What happens to your team after the layoffs? Your overextended team now realizes they’re going to have to pick up the slack for those who…

Cybersecurity News: China leads zero-days, HinataBot DDoS attacks, screenshot vulnerability

China led zero-days in 2022 Mandiant released a report on the use of zero-days in 2022. It found that use of zero-days significantly decreased on…

Cybersecurity News: NBA data breach, Emotet in OneNote, Dutch shipping ransomware

NBA warns of data breach after a third-party newsletter service hack The NBA has launched an investigation into this security breach to determine the extent…

Cybersecurity News Week in Review: Critical Outlook bug PoC, CISA Plex warning, YouTube AI infostealers 

NOTE: If the video above is not playing, go to the source on YouTube. This week’s Cyber Security Headlines – Week in Review, March 13-17,…

Cybersecurity News: Telerik breaches Government, Critical Outlook bug, LockBit threatens SpaceX

US Government IIS server breached via Telerik software flaw According to InfoSecurity Magazine, “CISA has disclosed information regarding a .NET deserialization vulnerability (CVE-2019-18935) in the…

How to Become a CISO

How do you become a CISO? It doesn’t follow a linear pattern as many other professions. There are many different paths and there are many…

Cybersecurity News: Suspects charged in DEA hack, Americans lose billions to scams, TikTok divestment

Two charged in DEA portal hack Prosecutors charged two US men with illegally accessing an online portal for the US Drug Enforcement Agency. This portal…

Cybersecurity News: Microsoft phishing warning, Amazon Ring hacked, CISA’s vulnerability program

Microsoft warns of large-scale use of phishing kits to send millions of emails daily Microsoft Threat Intelligence is tracking a threat actor behind the development…

We Look for Candidates Who Already Know Everything

Future cybersecurity talent is frustrated. The industry demand for cybersecurity professionals is huge, but the openings for green cyber people eager to get into the…

Cybersecurity News: North Korea targets security researchers, the UK’s National Protective Security Authority, bank failures hit crypto

North Korea targets security researchers Mandiant reports it spotted the North Korea-linked threat actors UNC2970 operating a phishing campaign since June 2022. The campaign uses…