Critical Infrastructure Security: Observations From the Front Lines

April 12, 2024 at 10:08AM Organizations are facing increased attacks on critical infrastructure, but they have the necessary knowledge and tools to defend against these threats. Based on the meeting notes, the key takeaway is that while attacks on critical infrastructure are increasing, organizations have the necessary knowledge and tools to effectively defend against them. … Read more

CISA makes its “Malware Next-Gen” analysis system publicly available

April 11, 2024 at 06:27PM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new version of “Malware Next-Gen,” allowing the public to submit malware samples for analysis. This expands access beyond government agencies and aims to enhance cyber defense efforts. The platform has already identified 200 suspicious files from 1,600 submissions, encouraging … Read more

Why Intelligence Sharing Is Vital to Building a Robust Collective Cyber Defense Program

April 11, 2024 at 09:24AM Threat intelligence sharing is crucial in the relentless war against cybercriminals. It has become a business imperative for vendors and enterprise organizations to collaborate and build intelligence networks. It’s essential for safeguarding critical infrastructure against cyber threats and requires a multifaceted approach. Automated, detailed, contextualized threat intelligence can help organizations … Read more

US Cyber Force Assisted Foreign Governments 22 Times in 2023

April 11, 2024 at 09:24AM The US Cyber Command (USCYBERCOM) conducted ‘hunt forward’ operations in over a dozen countries last year, aiming to monitor and deter adversaries. General Timothy D. Haugh, commander of USCYBERCOM, shared this information with the Senate Committee on Armed Services. These missions led to the public release of 90 malware samples … Read more

NSA Updates Zero-Trust Advice to Reduce Attack Surfaces

April 10, 2024 at 04:32PM The National Security Agency has issued new guidance for implementing a zero-trust cybersecurity framework, emphasizing the prevention of unauthorized data access. Recommendations include encryption, data labeling, loss prevention strategies, and data rights management tools. These align with zero-trust concepts to counter sophisticated cyberattacks. The agency urges a proactive approach based … Read more

StrikeReady Raises $12M to Build AI-Powered Security Command Center

April 9, 2024 at 06:06AM StrikeReady, a Silicon Valley startup, secures $12 million in new financing from 33N Ventures for its technology to modernize cybersecurity command centers. The Series A round includes equity interests from Hitachi Ventures, Monta Vista Capital, and cybersecurity executives. StrikeReady plans to use AI to simplify SOC environments and automate security … Read more

Oil & Gas Sector Falls for Fake Car Accident Phishing Emails

April 3, 2024 at 04:23PM Analysts uncover a phishing campaign called Rhadamanthys, which uses a fake “Federal Bureau of Transportation” to compromise recipients. The campaign is effective in its approach to deception. Based on the meeting notes, the key takeaway is that there has been the discovery of an effective phishing campaign that is spoofing … Read more

HHS Plans for Cyber ‘One-Stop Shop’ After United Healthcare Attack

April 2, 2024 at 04:01PM The initiative aims to support healthcare entities dealing with rising cybersecurity challenges by offering additional resources and improved strategies. Based on the meeting notes, the key takeaway is that the initiative aims to offer increased resources and improved strategies to healthcare organizations dealing with growing cybersecurity challenges. Full Article

Cyberattacks Wreaking Physical Disruption on the Rise

April 2, 2024 at 08:07AM In 2023, ransomware groups targeted manufacturing and other parts of the OT sector, resulting in significant damages. The year 2024 is expected to bring even more severe attacks. Based on the meeting notes, it is clear that ransomware groups have targeted the manufacturing and other parts of the OT sector … Read more

The Golden Age of Automated Penetration Testing is Here

March 29, 2024 at 08:03AM Automated network penetration testing is a game-changer in cybersecurity, making it affordable and efficient for companies to assess their network security regularly. Benefits include finding and fixing vulnerabilities, catching what other tools miss, improving security operations, avoiding downtime and financial losses, complying with regulations, understanding attackers’ tactics, testing incident response … Read more