All Posts

Cybersecurity News: Cloudflare’s power outage, Apache HelloKitty attempt, Boeing incident continues

Power outage darkens Cloudflare dashboard and APIs As of this recording, Cloudflare continues to struggle with an outage that has affected its customers’ ability to…

People Are the Top Attack Vector (Not the Weakest Link)

In increasingly complex technical defenses, threat actors frequently target the human element. This makes them a top attack vectors, but are they actually the weak…

Cybersecurity News: UK summit pledge to tackle AI risks, ‘Kill switch’ shuts down Mozi botnet, EU regulator bans Meta’s ad practices

Countries at UK summit pledge to tackle AI risks On Wednesday, at the global AI safety summit at Bletchley Park, UK, countries including the UK,…

Join Us 11-17-23 for “Hacking US Data Privacy” – Super Cyber Friday

Please join us on Friday November 17, 2023 for Super Cyber Friday. Our topic of discussion will be Hacking US Data Privacy: An hour of…

Cybersecurity News: Canada bans WeChat, no ransom pledge, India’s opposition sees state-sponsored attacks

Canada bans WeChat on government devices The Treasury Board of Canada announced the move, saying that the country’s chief information officer determined the Chinese messaging…

I Taught DeNiro Security Theater, I Can Teach You

In principle, we can generally all agree that security theater is a waste of time for security teams. But the reality is that these are…

Cybersecurity News: AI Executive Order, Russia’ VirusTotal, Roaming leaks locations

Executive order outlines generative AI rules in the US President Biden signed the order, which outlines eight goals for the emerging tech. NIST will develop…

SOC 2 Will Tell You More About Your Security and Data Management

You don’t have to get everything perfect to get a SOC 2. You don’t pass or fail. You can’t get rejected. This was the sage…

Cybersecurity News: DC Elections breach, LockBit Boeing breach, StripedFly’s stealthy sting

DC Board of Elections breach may include entire voter roll This fact was revealed in a statement released Friday by the District of Columbia Board…

Cybersecurity News Week in Review: Okta’s compromise issues, Cisco’s additional headache, CISA protests cuts

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Arvin Bansal, former CISO, Nissan Americas Cyber Security Headlines…

Cybersecurity News: iLeakage threatens Apple, CISA’s catastrophic cuts, HTTP DDoS surge

iLeakage attack steals emails, passwords from Apple devices and browsers A team of academics from Georgia Tech, University of Michigan, and Ruhr University Bochum, have…

What’s Entry Level in Cybersecurity?

We often talk about the contradiction of seemingly entry-level security jobs requiring years of experience. But maybe that’s because entry-level jobs don’t actually exist. Check…

Cybersecurity News: SMIC advanced chips, Roundcube exploit, Philadelphia email access

SMIC making advanced chips with ASML tech Bloomberg’s sources say China’s largest domestic chip producer used ASML’s immersion deep ultraviolet machines to produce advanced chips…

Upskilling Into People Management

Upskilling talent is a laudable goal for any organization, but getting there requires some careful consideration. Part of this needs to be finding a commonality…

Cybersecurity News: Cisco IOS XE infections remain high, California sidelines GM’s driverless cars, Canada accuse China of ‘Spamouflage’ campaign

Cisco IOS XE Update: Number of infected devices via zero-day remains high  Following up on a story we have been following on Cyber Security Headlines,…

A CEO’s Guide To Ignoring Your Security Program (LIVE in Santa Monica)

Usually the buck stops with the CEO. But for a CISO, what do you do when a CEO wants to exempt themselves from your security…

Cybersecurity News: Chrome IP Protection, Microsoft Security Copilot, Cisco patches IOS XE

Chrome testing IP Protection Google plans to test this new feature in Chrome. This will route third-party traffic from specific domains through proxies, hiding the…

Shadow IT Is Now Business As Usual

People want to get their jobs done. Often if a SaaS app can help them do that, they’ll just throw down a credit card without…

Cybersecurity News: Okta system attacked, another Cisco vulnerability, RagnarLocker arrest

Okta HAR support system attacked An advisory from Okta states that last week’s attack involved threat actors gaining access to customers’ HTTP Archive files, short…

Cybersecurity News Week in Review: Water cyber-regs rescinded, Cisco zero-day attacks, Signal debunks zero-day

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andrew Wilder, CISO, Community Veterinary Partners Cyber Security Headlines…

Cybersecurity News: Cops sting RagnarLocker, more 23andMe leaks, Casio discloses breach

International sting operation brings down RagnarLocker Agencies from the US, Japan and the EU have successfully seized the dark web portal used by the gang.…

New SEC Rules for Cyber Security

The Securities and Exchange Commission issued new cyber rules. What do these new rules mean for CISOs and will they ultimately improve our cybersecurity posture?…

Cybersecurity News: WinRAR exploitation, Five Eyes warns about China, ServiceNow data exposure

State-backed attackers exploit WinRAR zero-day Security researchers at Google found evidence that state-sponsored threat actors linked to China and Russia began exploiting a vulnerability in…

The Human Cost of Generative AI

Like any new technology, generative AI can seem miraculous at first glance. Regardless of how impressive things like ChatGPT are, they are just tools. They…