Ireland fines LinkedIn €310 million over targeted advertising

October 24, 2024 at 02:21PM LinkedIn was fined €310 million by the Irish Data Protection Commission for GDPR violations related to data processing for targeted advertising. The inquiry revealed failures in obtaining valid consent, transparency, and legitimate interests. LinkedIn must comply with EU regulations and amend its advertising systems following the ruling. ### Meeting Takeaways: … Read more

New Qilin.B Ransomware Variant Emerges with Improved Encryption and Evasion Tactics

October 24, 2024 at 01:35PM Cybersecurity researchers have identified a sophisticated variant of Qilin ransomware, named Qilin.B, featuring advanced encryption methods like AES-256-CTR and Chacha20. This ransomware disrupts backup systems and evades detection, posing significant threats, particularly to U.S. healthcare institutions, which face substantial financial losses from such attacks. ### Meeting Takeaways – October 24, … Read more

New Qilin ransomware encryptor features stronger encryption, evasion

October 24, 2024 at 11:22AM The new Qilin.B ransomware, identified by Halcyon, features advanced encryption techniques and evasion strategies, targeting critical systems and processes to obstruct data recovery. It utilizes AES-256-CTR, ChaCha20, and RSA-4096 for robust encryption. The malware poses significant threats to networks, building on previous high-profile attacks. ### Meeting Takeaways: 1. **Introduction of … Read more

Why Cybersecurity Acumen Matters in the C-Suite

October 24, 2024 at 10:09AM CEOs must enhance their understanding of generative AI and cybersecurity as threats evolve and cybercriminals become more sophisticated. Improved cybersecurity knowledge among C-suite leaders fosters better decision-making, resource allocation, and collaboration, ultimately protecting companies from risks and ensuring compliance with regulations. Proactive leadership is essential for safeguarding data and assets. … Read more

New Fortinet Zero-Day Exploited for Months Before Patch

October 24, 2024 at 07:41AM The ICS Cybersecurity Conference is broadcasting live from Atlanta, offering remote sessions on various cybersecurity topics, including threats, incident response, and data protection. SecurityWeek provides news, webcasts, and virtual events focused on cybersecurity, and encourages subscriptions to their daily briefing newsletter for the latest insights. ### Takeaways from the Meeting … Read more

Penn State Settles for $1.25M Over Failure to Comply With DoD, NASA Cybersecurity Requirements

October 24, 2024 at 06:54AM Penn State University will pay $1.25 million to settle claims of not meeting cybersecurity requirements for Department of Defense and NASA contracts. This settlement addresses alleged compliance failures related to security standards essential for these federal contracts. ### Meeting Takeaways: 1. **Settlement Amount**: Penn State University will pay $1.25 million. … Read more

Ransomware’s ripple effect felt across ERs as patient care suffers

October 24, 2024 at 06:46AM This year, ransomware impacted 389 US healthcare organizations, risking patient safety and costing up to $900,000 daily in downtime. Attacks led to increased emergency cases and dwindling survival rates. Organized groups, primarily Iranian, have intensified these intrusions, facilitated by ransomware-as-a-service and geopolitical factors. **Meeting Takeaways:** 1. **Ransomware Impact on Healthcare:** … Read more

Cisco Patches Vulnerability Exploited in Large-Scale Brute-Force Campaign

October 24, 2024 at 05:08AM The ICS Cybersecurity Conference is being broadcast live from Atlanta, allowing remote participation. It focuses on various cybersecurity topics, including threats, vulnerabilities, risk management, and compliance. Attendees can connect, subscribe to newsletters for updates, and explore multiple cybersecurity aspects, from malware to incident response. ### Meeting Takeaways from the ICS … Read more

Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation

October 24, 2024 at 04:06AM Fortinet has identified a critical vulnerability (CVE-2024-47575) in FortiManager, affecting multiple versions and potentially exploited by remote attackers. The flaw allows unauthorized code execution. Fortinet recommends workarounds and has included the issue in the U.S. CISA’s Known Exploited Vulnerabilities catalog, requiring federal agencies to act by November 13, 2024. ### … Read more

China’s top messaging app WeChat banned from Hong Kong government computers

October 24, 2024 at 01:17AM Hong Kong’s government has revised infosec guidelines, banning the use of Chinese app WeChat, along with Meta and Google products, on official computers due to concerns over security risks associated with encryption. The restrictions take effect at the end of October, with some exceptions allowed through departmental approval. ### Meeting … Read more