Pentagon Outlines Cybersecurity Strategy for Defense Industrial Base 

March 29, 2024 at 09:24AM The US Department of Defense released a cybersecurity strategy for the defense industrial base (DIB) with four main goals for fiscal years 2024-2027. It aims to protect warfighting capabilities, strengthen DOD governance, improve DIB cybersecurity posture, preserve critical capabilities, and enhance collaboration with the DIB to defend against cyber threats … Read more

How to Apply Zero Trust to your Active Directory

February 7, 2024 at 10:27AM As remote work becomes more prevalent, organizations need to move away from traditional trust models and embrace a zero trust approach for secure access. This involves rigorous authentication for every user, device, and network component. Implementing the principle of least privilege and using multifactor authentication are recommended strategies to bolster … Read more

Dubai Cyber Force Names First Accredited Companies

January 31, 2024 at 11:00AM Eight companies, including Crowe Indonesia Teknologi and Grant Thornton Consulting CJSC, have attained accreditation as cybersecurity service providers for Dubai’s “Cyber Force” initiative. The initiative, in collaboration with CREST and Dubai’s Electronic Security Center, aims to enhance cybersecurity measures and make Dubai the safest city in the digital space. Initially, … Read more

Wait, security courses aren’t a requirement to graduate with a computer science degree?

January 26, 2024 at 04:35PM CISA urges software developers to prioritize secure coding. Many top US computer science schools don’t require cybersecurity courses, hindering workforce readiness. While engineering may naturally address secure coding, the lack of security education in computer science curricula poses a significant problem. CISA calls for industry demand to prompt necessary changes … Read more

From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks

January 23, 2024 at 07:24AM Gcore’s Q3-Q4 2023 Radar report reveals escalating DDoS attack trends. Annual peak attack capacity surged >100% from 2021 to 2023, reaching 1.6 Tbps. Attack lengths varied from minutes to nine hours, predominantly UDP floods. Global attack sources spanned multiple countries, impacting gaming and financial sectors most. Gcore emphasizes the need … Read more

F5 Names Samir Sherif as New CISO

January 23, 2024 at 06:54AM F5 announced that Samir Sherif is named Senior Vice President and Chief Information Security Officer. In the role, he will lead the enterprise cybersecurity strategy, security culture, and oversee cybersecurity standards and programs. Sherif has previously served as CISO at Absolute Software and Imperva and had a long career at … Read more

MacOS info-stealers quickly evolve to evade XProtect detection

January 16, 2024 at 04:34PM The macOS platform faces persistent challenges with information stealers evading detection, as highlighted in a report by SentinelOne that presents three malware examples circumventing XProtect. KeySteal, Atomic Stealer, and CherryPie showcase the ability of malware to evolve and avoid detection, emphasizing the need for advanced security measures beyond static detection. … Read more

CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign

January 12, 2024 at 02:38AM This blog summarizes the exploitation of CVE-2023-36025 by the Phemedrone Stealer campaign, which targets web browsers, cryptocurrency wallets, and messaging apps. The malware bypasses Windows Defender SmartScreen, allowing threat actors to execute malicious scripts. Despite Microsoft’s patch, the vulnerability continues to be exploited, posing a risk to organizations. Advanced security … Read more

I Securely Resolve: CISOs, IT Security Leaders Share 2024 Resolutions

December 29, 2023 at 09:05AM Cybersecurity leaders have outlined New Year’s resolutions for 2024. These include bolstering defenses through proactive measures, operational enhancements, and reactive capabilities. Emphasizing the importance of assessing and updating business continuity and incident response plans is coupled with a strong focus on fundamental detection, prevention, and response capabilities. New technologies, evolving … Read more

Changing How We Think About Technology

December 19, 2023 at 10:06AM Organizations often fail to adopt a holistic, long-term approach when making decisions. For instance, implementing technology for remote work during the pandemic didn’t necessarily ensure security. The book “Fossil Future” and England football manager Gareth Southgate’s approach illustrate the importance of critical thinking. To improve outcomes, organizations should challenge traditional … Read more