All Posts

“Hacking Conferences” – Super Cyber Friday

Please join us on Friday, August 18, 2023 for Super Cyber Friday. Our topic of discussion will be “Hacking Conferences: An hour of critical thinking…

Cybersecurity News: Israel refinery cyberattack, TSA pipeline guidelines, CISA’s IDOR warning

Israel’s largest oil refinery website goes offline amid cyber attack claims The website of Israel’s largest oil refinery operator, BAZAN Group, became inaccessible to most…

Cybersecurity News Week in Review: Stolen Microsoft key, government Maximus breach, Clop on clearweb

This week’s Cyber Security Headlines – Week in Review, July 24-28, is hosted by Rich Stroffolino  with guest, TC Niedzialkowski‌, CISO, Nextdoor Cyber Security Headlines…

Cybersecurity News: Maximus breach, Ubuntu Linux vulnerabilities, Cardio company cyberattack

Millions affected by data breach at US government contractor Maximus Maximus, a provider of services to the U.S. government has revealed that hackers stole the…

Securing SaaS Applications

With the growth of business-led IT, does SaaS security need to be a specific focus in a CISO’s architectural strategy? Check out this post for…

Cybersecurity News: Cyber exec convicted, SEC disclosure, how the government gets breached

Russian court convicts cyber security executive of treason A Russian court found Group-IB’s former CEO and co-founder Ilya Sachkov guilty of treason, sentencing him to…

How is Cyber Security Headlines Part of Your Daily Routine?

We’re just a few weeks away (August 17th, 2023) from celebrating the three-year anniversary of Cyber Security Headlines, the fastest growing and most popular show…

Cybersecurity News: TETRA encryption flaws, Zenbleed strikes, Norway’s government hit with Ivanti flaw

Vulnerability found in TETRA encryption Three Dutch security researchers from the firm Midnight Blue discovered severe flaws in the encryption algorithms for TETRA, a European…

Vendors Are From Mars. Their Security Is From Venus.

There are so many third party vendors we want to work with, but uggh, their security and privacy is so troublesome. Is it only the…

Cybersecurity News: Clop leaks on clearweb, EU pushes back on CSA centralization, rising data breach costs

Clop moves leaked data to clearweb sites Like many threat groups, typically the Clop ransomware organization publishes leak data on their own dedicated sites on…

Simple Misconfigurations Are Often the Result of Systemic Problems

We hear so many stories of breaches happening from what appears to be a simple mistake. A permission was granted that shouldn’t have, or something…

Cybersecurity News: Azure hack deepens, JumpCloud is Lazarus, DHL MOVEIt victim

Microsoft key stolen by Chinese hackers provided access far beyond Outlook In a blog post published Friday, Shir Tamari, head of research at Wiz, stated…

Cybersecurity News Week in Review: Fast acting Gamaredon, WormGPT AI weapon, Microsoft Azure mystery

This week’s Cyber Security Headlines – Week in Review, July 17-21, is hosted by Rich Stroffolino with our guest, Dimitri van Zantvliet, CISO, Dutch Railways…

Cybersecurity News:  New Redis worm, more ColdFusion confusion, Estée Lauder breached

New P2PInfect worm targeting Redis servers on Linux and Windows systems A new cloud targeting, peer-to-peer (P2P) worm called P2PInfect is targeting vulnerable Redis instances…

How Do We Get Better Control of Cloud Data?

When it comes to data, compliance, and reducing risk, where are we gaining control? Where are we losing control? And what are we doing about…

Cybersecurity News: A rise in complex DDoS attacks, Mi6 warns of data traps, Microsoft expands log access

Complex DDoS attacks on the rise According to a new report from Cloudflare, the number of DDoS requests in Q2 increased 15% on the quarter…

Cybersecurity News: US IoT security labeling program, Renewable tech could pose grid risk, US blacklists spyware firms

US government launches IoT security labeling program The Biden administration has launched its long-awaited  “U.S. Cyber Trust Mark” program which aims to protect Americans from…

We’re So Special Gartner Hasn’t Even Thought Of Our Category Yet

Do you know which security categories were created this year? I have no idea. Do you know which ones were deleted? Is category growth designed…

Cybersecurity News: JumpCloud Breach, LockBit attacks Wisconsin, Typos leak military emails

JumpCloud breached by APT Last week, we reported that the enterprise software company JumpCloud reset all customer API keys, in what it referred to as…

Getting a Grasp on the Excitement and Fear of 5G

As we’re watching the onboarding of 5G there’s a lot of excitement of the possibilities, but for security professionals it seems like it’s going to…

Cybersecurity News: Fast-acting Gamaredon, WormGPT improves phishing, Microsoft email mystery

Russia-linked Gamaredon starts stealing data 30 to 50 minutes after initial compromise Ukraine’s Computer Emergency Response Team has discovered new abilities within the Russia-linked APT…

Cybersecurity News Week in Review: Threat actors access government email, USB drive attacks spiking, cloud environment breaches

This week’s Cyber Security Headlines – Week in Review, July 10-14, is hosted by Sean Kelly with our guest, Yaron Levi, CISO, Dolby Cyber Security…

Cybersecurity News: USB malware spikes, Honeywell, Rockwell vulnerabilities, ransomware remains profitable

USB drive malware attacks spiking again in first half of 2023 Mandiant is describing the proliferation of two USB drive-based malware campaigns have been active…

Finding Your Security Community

If you’re struggling to get your first job in security or you’re trying to get back into the industry after being laid off, you need…