The AI Wild West: Unraveling the Security and Privacy Risks of GenAI Apps

September 5, 2024 at 10:24AM The use of Generative AI in workplaces is widespread, with about a quarter of employees using or having tried it. Research on 1,000 enterprise employees revealed that once users start using GenAI, they heavily engage with an average of 8.25 apps per month. Content creation is the dominant use case, … Read more

Human Nature Is Causing Our Cybersecurity Problem

August 19, 2024 at 10:07AM Cyberattacks have become the biggest threat to businesses, despite significant consequences. The human tendency to procrastinate, known as temporal discounting, leads to the delay in adopting modern security practices. Governments can combat this by enforcing penalties and regulations, similar to the automotive and food safety industries. Furthermore, guidance like automatic … Read more

8 Strategies for Enhancing Code Signing Security

March 22, 2024 at 10:04AM Code-signing best practices are crucial for fostering trust in the development process and enhancing software supply chain security. The key takeaway from the meeting notes is the importance of strong code-signing best practices in establishing trust in the development process and enhancing the security of the software supply chain. Full … Read more

NIST updates Cybersecurity Framework after a decade of lessons

February 27, 2024 at 01:50PM NIST has released version 2.0 of its Cybersecurity Framework (CSF), expanding its scope to offer security tips for all organizations. Newly introduced resources include quick-start guides, implementation examples, and a new core risk management function called “govern.” NIST plans to continue enhancing the framework and encourages users to share feedback … Read more

Saudi Aramco CEO Warns of New Threat of Generative AI

November 2, 2023 at 01:43PM The CEO of Saudi Aramco warned that the energy sector is vulnerable to attacks, especially with the introduction of new technologies like generative AI. Amin H. Nasser emphasized that any disruption to the global energy supply would have significant consequences. He stressed the need for assessing these technologies and addressing … Read more

CISA, HHS Release Cybersecurity Healthcare Toolkit

October 26, 2023 at 12:21PM The US cybersecurity agency CISA and the Department of Health and Human Services (HHS) have released a cybersecurity toolkit for healthcare and public health organizations. The toolkit provides guidance on cyber hygiene, threat landscape, best practices, and offers risk assessment tools and recommended resources. It also suggests accessing grants and … Read more

The Rise of S3 Ransomware: How to Identify and Combat It

October 25, 2023 at 08:04AM Around 60% of corporate data is stored in the cloud, with Amazon S3 being a popular choice. However, S3 remains vulnerable to ransomware attacks as leaked access keys can be used to compromise sensitive data. To combat these threats, organizations need visibility into their S3 environment through CloudTrail and Server … Read more

The Most Popular IT Admin Password Is Totally Depressing

October 18, 2023 at 03:07PM Researchers found that out of over 1.8 million admin portals, 40,000 had “admin” as the password, making it the most popular password among IT administrators. The study also revealed an increase in the use of default passwords. The top 10 passwords included common defaults and easy-to-guess options. This highlights the … Read more