Tips for Preventing Breaches in 2025

December 11, 2024 at 09:59AM In 2024, significant data breaches impacted major companies, costing US businesses over $9 million on average. With 98% of companies working with breached vendors, proactive security measures, including regular vendor reviews, audits, and advanced protections like encryption and access controls, are essential for mitigating risks and safeguarding data in 2025. … Read more

Governments, Telcos Ward Off China’s Hacking Typhoons

December 11, 2024 at 02:06AM Telecommunications firms globally, including in the US, Asia-Pacific, and MENA regions, are targets of Chinese-sponsored cyberattacks, such as those from Salt Typhoon and Volt Typhoon. Experts warn that nations should enhance security measures and adopt encryption to protect communications, as foreign intrusions threaten network privacy and integrity. ### Meeting Takeaways … Read more

T-Mobile US CSO: Spies jumped from one telco to another in a way ‘I’ve not seen in my career’

December 4, 2024 at 07:58PM T-Mobile US swiftly thwarted cyber-espionage attempts by a Chinese-backed group, Salt Typhoon, which compromised a connected network but accessed none of T-Mo’s sensitive customer data. T-Mobile emphasized its layered defenses and the use of advanced authentication methods to prevent further intrusions. US officials recommend strong encryption for communications. **Meeting Takeaways:** … Read more

Dark Reading Confidential: Quantum Has Landed, So Now What?

November 5, 2024 at 09:13AM Becky Bracken and Kelly Jackson Higgins discuss the implications of quantum computing on cybersecurity in the podcast “Quantum Has Landed: So Now What?” The episode emphasizes the urgency for organizations to prepare for quantum threats, shifting from reactive to proactive measures in encryption and cyber risk management. **Meeting Takeaways: Dark … Read more

New Qilin.B Ransomware Variant Emerges with Improved Encryption and Evasion Tactics

October 24, 2024 at 01:35PM Cybersecurity researchers have identified a sophisticated variant of Qilin ransomware, named Qilin.B, featuring advanced encryption methods like AES-256-CTR and Chacha20. This ransomware disrupts backup systems and evades detection, posing significant threats, particularly to U.S. healthcare institutions, which face substantial financial losses from such attacks. ### Meeting Takeaways – October 24, … Read more

New Qilin ransomware encryptor features stronger encryption, evasion

October 24, 2024 at 11:22AM The new Qilin.B ransomware, identified by Halcyon, features advanced encryption techniques and evasion strategies, targeting critical systems and processes to obstruct data recovery. It utilizes AES-256-CTR, ChaCha20, and RSA-4096 for robust encryption. The malware poses significant threats to networks, building on previous high-profile attacks. ### Meeting Takeaways: 1. **Introduction of … Read more

China’s top messaging app WeChat banned from Hong Kong government computers

October 24, 2024 at 01:17AM Hong Kong’s government has revised infosec guidelines, banning the use of Chinese app WeChat, along with Meta and Google products, on official computers due to concerns over security risks associated with encryption. The restrictions take effect at the end of October, with some exceptions allowed through departmental approval. ### Meeting … Read more

NotLockBit Ransomware Can Target macOS Devices

October 23, 2024 at 07:57AM A new file-encrypting malware resembling LockBit ransomware has been detected targeting macOS systems, raising concerns for cybersecurity. The threat highlights the evolving landscape of malware that can affect multiple operating systems. **Meeting Notes Takeaways:** 1. **Malware Identification**: A new file-encrypting malware, referred to as NotLockBit, has been identified. 2. **Target … Read more

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers

October 21, 2024 at 03:12AM Cybersecurity researchers identified serious cryptographic vulnerabilities in end-to-end encrypted cloud storage platforms (Sync, pCloud, Icedrive, Seafile, Tresorit) that allow malicious servers to leak sensitive data, tamper with files, and access plaintext. Some providers acknowledged the issues, while Icedrive has not taken corrective action. ### Meeting Takeaways: October 21, 2024 **Topic: … Read more

Chinese Researchers Tap Quantum to Break Encryption

October 16, 2024 at 05:52PM Researchers at Shanghai University have shown that quantum mechanics can threaten current encryption systems, using a D-Wave quantum computer to factor a 50-bit integer. While this does not endanger existing 2048-bit keys, it highlights potential cryptographic vulnerabilities, emphasizing the need for organizations to adopt quantum-resistant encryption soon. ### Meeting Takeaways … Read more