All Posts

The Perfect Gift for a Cyber Crook

What do you give to the person who wants to learn how to steal everything? This week’s episode is hosted by me, David Spark (@dspark), producer of…

Cybersecurity News – January 4, 2022

Broward Health discloses major data breach The Florida-based healthcare system disclosed the breach impacted over 1.3 million individuals, dating back to a cyberattack on October…

Cybersecurity News – January 3, 2022

Microsoft Exchange year 2022 bug breaks email delivery According to numerous reports from Microsoft Exchange admins worldwide, a bug in the FIP-FS engine started blocking…

Cybersecurity News – December 30, 2021

Defense bill includes cybersecurity provisions for private-sector President Biden signed the National Defense Authorization Act of 2022 into law this week, which includes new cybersecurity…

Cybersecurity News – December 29, 2021

LastPass confirms credential stuffing attack against its users Password manager app LastPass confirmed Tuesday that a threat actor has launched a credential stuffing attack against…

Cybersecurity News – December 28, 2021

Study looks at ransomware market share Research ers at Intel 471 analyzed 612 ransomware attacks between July and September 2021, finding them attributed to 35…

Cybersecurity News – December 27, 2021

Rook ransomware is yet another spawn of the leaked Babuk code A new ransomware operation named Rook has appeared recently on the cyber-crime space, declaring…

Cybersecurity News – December 24, 2021

CISA releases free scanner to spot Log4j exposure CISA posted the Log4j Scanner to GitHub yesterday. It claimed it’s a “project derived from other members…

Cybersecurity News – December 23, 2021

Five Eyes issues Log4Shell advisory The United States, United Kingdom, Australia, Canada, and New Zealand issued a joint advisory on the emerging threat of the…

Cybersecurity News – December 22, 2021

Hack DHS program expanded to include Log4j  On Tuesday, Homeland Security Secretary Alejandro Mayorkas announced that DHS would broaden its new bug bounty program to…

“I Love Being Monitored Online,” Said No Employee Ever

What do you do if your boss gave you a corporate laptop and you fear they installed some tracking software? Should you wipe the drive…

Cybersecurity News – December 21, 2021

Mobile network vulnerability goes back to 2G A new paper from researchers at New York University Abu Dhabi discloses a security vulnerability in mobile network…

Cybersecurity News – December 20, 2021

Log4J – New patch and a field day for ransomware Fallout from the Log4j zero-day continues to appear by the hour. Since its discovery last…

Cybersecurity News – Week in Review – Dec 13-17, 2021

This week’s Cyber Security Headlines – Week in Review, Dec 13-17, is hosted by Rich Stroffolino with our guest, Patti Titus, Chief Privacy and Information…

Cybersecurity News – December 17, 2021

Hackers begin exploiting second Log4j vulnerability as a third flaw emerges Web infrastructure company Cloudflare on Wednesday revealed that threat actors are actively attempting to…

Defense in Depth: When Social Engineering Bypasses Our Cyber Tools

Your tools can only handle so much defense when it comes to social engineering attacks. What types of social engineering can’t a rule set catch?…

Cybersecurity News – December 16, 2021

Log4J vulnerability used by APTs Microsoft and the security firm Mandiant report they observed groups with ties to China, Iran, Turkey, and North Korea launching…

Best moments from “Hacking Zero Trust” – CISO Series Video Chat

Here are five minutes of our best moments from CISO Series Video Chat: “Hacking Zero Trust: An hour of critical thinking of how to simplify…

Cybersecurity News – December 15, 2021

Kronos ransomware outage drives widespread payroll chaos On Saturday, Workforce-management provider, Kronos, whose customers include companies such as Tesla, Puma, and YMCA, had its private…

If We Don’t Talk About Cyber Risk, Will It Go Away?

Risk is scary. Cyber risk is scarier. Not because it’s worse, but mostly because we barely understand it. We’ve gone this long not understanding it.…

Cybersecurity News – December 14, 2021

New details on the Log4Shell attacks Researchers at Cisco and Cloudflare report that the first attacks on the Log4J utility were actually observed on December…

CISO Series Is Looking for an Associate Producer

UPDATE (12-22-21): This position has been filled CISO Series is seeking a full-time Associate Producer with excellent communication and written skills to assist in production…

Five Explanations of Security in a Virtualized Environment in Just One Minute

Explaining virtualization is not easy to do even for experts (as I proved while attending VMworld 2013). But I challenged Sandy Wenzel (@malwaremama), cybersecurity transformation engineer…

Cybersecurity News – December 13, 2021

German cybersecurity watchdog issues red alert on Log4j Germany’s federal cybersecurity watchdog, the BSI, on Saturday issued a red alert warning, its highest, regarding the…