All Posts

Tips for Retaining Your Best Cyber Talent

We all have superstar employees that if we lost them would cause serious damage to the business. When you can’t always offer a ton more…

Cybersecurity News: AI generated malware, Rackspace confirms ransomware, Meta Oversight Board rules on cross-check

Are we in the age of AI generated malware? We covered yesterday that Stack Overflow temporarily banned the submission of code created with generative AI,…

They’re Young, Green, and Very Hackable

It appears we’re not providing security awareness training fast enough. That’s because hackers are specifically targeting brand new employees who don’t yet know the company’s…

Cybersecurity News: Baseboard software vulnerabilities, threat group stole COVID funds, AI generated code

Vulnerabilities found in popular baseboard software Researchers at Eclypsium Research disclosed three vulnerabilities in the MegaRAC Baseboard Management Controller software from American Megatrends. These BMCs…

Cybersecurity News: Fosshost goes dark, DHS reviews Lapsus$, Rackspace security incident

Open source software host Fosshost shutting down, CEO unreachable Fosshost project volunteers announced this development this past weekend following months of difficulties in reaching the…

Cybersecurity News Week in Review: TikTok invisible malware, Sandworm attacks Ukraine, patch gap warning

This week’s Cyber Security Headlines – Week in Review, November 28-December 2, is hosted by Rich Stroffolino with our guest, Terrance Cooley, CISO, Air Force…

Cybersecurity News: LastPass data accessed, Sirius smart car flaw, Medibank data dump

Intruders gain access to user data in LastPass incident Following up on a story we brought you in August, intruders broke into a third-party cloud…

How Should We Gauge a Company’s Cyber Health?

As an outside observer, how can you tell if a company is staying cyber healthy? While there is no financial statement equivalency to let you…

White House targeted, Google links spyware, Android app fake accounts

Elon Musk’s Starlink and White House targeted by Killnet hackers Russian-backed Killnet claimed triple denial-of-service (DDoS) attacks against Elon Musk’s Starlink, the White House, and…

“Hacking Non-Traditional Cyber Risk” – Super Cyber Friday

Please join us on Friday, December 16th, 2022 for Super Cyber Friday. Our topic of discussion will be “Hacking Non-Traditional Cyber Risk: An hour of…

What’s the Longest Your Business Can Be Offline?

While we never like to think about it, it’s important to know how long your computing systems and connectivity can be down before your business…

Cybersecurity News: TikTok Challenge malware, Cyber Monday record, Sandworm’s Ukraine attack

Hackers use trending TikTok ‘Invisible Challenge’ to spread malware Threat actors are capitalizing on a popular TikTok challenge to trick users into downloading information-stealing malware,…

Entry Level Position Available. 15+ Years Experience Required.

That headline is not a joke. An actual job listing on LinkedIn requested just that. We’re all hoping this was an error. Regardless, the community…

Cybersecurity News: Google warns of “patch gap,” Chinese spam hits Twitter

Project Zero warns of “patch gap” The researchers at Google’s security team warned of this “patch gap” problem across the Android ecosystem. It claims that…

Why Is It So Darn Hard to Get Cyber Insurance?

Cyber insurance is so new, so confusing, and as a result so difficult to get. Far too many companies, trying their hardest to build their…

Cybersecurity News: FCC China ban, Windows servers freeze, WhatsApp data leak

FCC announces ban on Chinese telecom and surveillance equipment The total ban applies to Chinese companies Huawei, ZTE, Hytera, Hikvision, and Dahua and is due…

Cybersecurity News: Twitter enlists George Hotz, $575 million crypto scheme, DrafKings $300K theft

Twitter enlists hacker George Hotz for 12 week “internship” Despite Twitter’s rapidly diminishing workforce, Elon Musk has signed on hacker and frenemy, George Hotz, for…

Get All the Stress You Want, With None of the Authority

CISOs and other security leaders have a lot of stress. But so do other C-level employees. Why does a CISO’s stress seem that much more…

Cybersecurity News: Emotet returns, Google helps with Cobalt Strike, Ticketmaster blames bots for Swift snafu

Emotet returns with a malspam vengeance  The pernicious botnet returned on the scene in early November. Researchers last spotted it in action back in July.…

What Have We Learned from 25 Years of Cybersecurity?

Twenty five years ago, we had multi-factor authentication, noted Renee Guttmann, former CISO, Coca-Cola, Time Warner, and Campbell’s. It’s one of the few technologies that…

Cybersecurity News: Ransomware infects Discord, Twitter welcomes Trump, Black Friday scams

New ransomware encrypts files, then steals your Discord account The new ‘AXLocker’ ransomware family is not only encrypting victims’ files and demanding a ransom payment…

Cybersecurity News Week in Review: The fall of FTX, Australia Medibank fallout, supply chain failures

This week’s Cyber Security Headlines – Week in Review, November 14-18, is hosted by Rich Stroffolino with our guest, John Scrimsher, CISO, Kontoor Brands Cyber…

Cybersecurity News: Musk’s ultimatum backfires, Iran breaches government using Log4Shell, Amazon RDS data leak

Musk’s ultimatum to employees leaves Twitter at risk In an email to staff entitled “A Fork in the Road,” Musk said employees had until the…

Reducing the Attack Surface

The cyber attack surface just keeps growing to the point that it seems endless. Protecting it all is impossible. Is there anything that can be…