UPS supplier’s password policy flip-flops from unlimited, to 32, then 64 characters

September 23, 2024 at 08:09AM A major IT hardware manufacturer faced backlash over a recent security update imposing a 32-character limit on passwords. The company, CyberPower Systems, responded to customer complaints by doubling the limit to 64 characters. The change, initiated by a third-party auditor’s recommendation, will be implemented within two weeks. Experts debate the … Read more

Bipartisan Bill to Tighten Vulnerability Disclosure Rules for Federal Contractors

August 12, 2024 at 07:12AM Senators Mark R. Warner and James Lankford introduced the bipartisan Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024, aiming to enforce vulnerability disclosure rules for federal contractors. The bill mandates adherence to National Institute of Standards and Technology (NIST) guidelines and requires implementation of formal vulnerability disclosure policies to mitigate … Read more

Cyber Insights 2024: OT, ICS and IIoT

March 6, 2024 at 08:31AM The text discusses the evolving cybersecurity challenges facing Industrial Control Systems (ICS) and Operational Technology (OT). It covers topics such as the convergence of IT and OT, cybersecurity vulnerabilities, IIoT devices, the role of AI, government interventions, geopolitical threats, and the increasing adversarial activity against OT. The industrial cybersecurity landscape … Read more

NIST Warns of Security and Privacy Risks from Rapid AI System Deployment

January 8, 2024 at 04:27AM NIST highlights AI’s security and privacy challenges, including adversarial manipulation of training data, exploitation of model vulnerabilities, and exfiltration of sensitive information. Rapid integration of AI into online services exposes models to threats like corrupted training data and privacy breaches. NIST urges the tech community to develop better defenses against … Read more