Tag: corporate
-
Google Cloud Security Threat Horizons Report #11 Is Out!
Tags: access, api, apt, attack, authentication, breach, business, cloud, corporate, credentials, cybersecurity, data, detection, exploit, extortion, google, identity, intelligence, leak, mfa, password, phishing, ransomware, service, tactics, theft, threat, tool, vulnerabilityThis is my completely informal, uncertified, unreviewed and otherwise completely unofficial blog inspired by my reading of our next Threat Horizons Report, #11 (full version) that we just released (the official blog for #1 report, my unofficial blogs for #2, #3, #4, #5, #6, #7, #8, #9 and #10). My favorite quotes from the report follow below:…
-
Cybersecurity is tough: 4 steps leaders can take now to reduce team burnout
Tags: ai, attack, breach, business, ciso, compliance, control, corporate, cybercrime, cybersecurity, group, incident response, international, jobs, risk, soc, tactics, threatWorking in cybersecurity is only getting harder. Cybercriminals continue to up their game as security teams scramble to catch up with attack tactics and techniques. Organizations put near-impossible demands on their security departments, often with little or no support.The “always-on” nature of many roles in cybersecurity (from SOC analyst to incident response to the CISO)…
-
Security chiefs whose companies operate in the EU should be exploring DORA now
Tags: attack, business, ciso, compliance, conference, corporate, cyber, cybersecurity, data, detection, dora, finance, framework, GDPR, incident, network, regulation, resilience, risk, service, technology, threat, vulnerabilityIf your enterprise operates in Europe, you should care about the Digital Operational Resilience Act (DORA), which took effect on January 17. DORA, also known as Directive (EU) 2022/2555 of the European Parliament, aims to enhance and build the EU’s cybersecurity capabilities and it has been hanging like the Sword of Damocles over the heads…
-
Russian telecom giant Rostelecom investigates suspected cyberattack on contractor
Russia’s Rostelecom said that it was responding to a cyberattack on a contractor that helps to run its corporate website and procurement portal.]]> First seen on therecord.media Jump to article: therecord.media/rostelecom-russia-contractor-data-breach
-
Almost 10% of GenAI Prompts Include Sensitive Data: Study
A study by cybersecurity startup Harmonic Security found that 8.5% of prompts entered into generative AI models like ChatGPT, Copilot, and Gemini last year included sensitive information, putting personal and corporate data at risk of being leaked. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/almost-10-of-genai-prompts-include-sensitive-data-study/
-
How Much of Your Business is Exposed on the Dark Web?
The dark web is a thriving underground market where stolen data and corporate vulnerabilities are openly traded. This hidden economy poses a direct and growing threat to businesses worldwide. Recent breaches highlight the danger. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/how-much-of-your-business-is-exposed-on-the-dark-web/
-
CISOs embrace rise in prominence, with broader business authority
Tags: ai, attack, business, ceo, cio, ciso, compliance, control, corporate, cyber, cyberattack, cybersecurity, data, governance, healthcare, infrastructure, intelligence, network, privacy, regulation, risk, risk-management, security-incident, strategy, technology, threat, updateIt’s a familiar refrain: As cybersecurity has become a core business priority, it is no longer a siloed operation, and the responsibilities of CISOs have grown, giving them greater prominence within the organization.According to CSO’s 2024 Security Priorities Study, 72% of security decision-makers say their role has grown to include additional responsibilities over the past…
-
CISA director reiterates prior calls for C-suites, boards to take cyber risk ownership
Jen Easterly said companies need to consider cybersecurity threats as core risks that need to be fully incorporated into corporate business strategy. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-director-boards-cyber-risk/737042/
-
China hacked US Treasury’s CFIUS, which reviews foreign investments for national security risks
The hackers targeting the Treasury are dubbed Silk Typhoon, and previously mass-hacked thousands of corporate email servers. First seen on techcrunch.com Jump to article: techcrunch.com/2025/01/10/china-hacked-us-treasurys-cfius-which-reviews-foreign-investments-for-national-security-risks/
-
Digital Wallets: From Consumer Convenience to Corporate Security
Tags: corporateFrom storing state IDs, driver’s licenses and passports to managing payment information, digital wallets have revolutionized the way we handle personal credentials. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/digital-wallets-from-consumer-convenience-to-corporate-security/
-
Space Bears ransomware: what you need to know
The Space Bears ransomware gang stands out from the crowd by presenting itself better than many legitimate companies, with corporate stock images and a professional-looking leak site. First seen on tripwire.com Jump to article: www.tripwire.com/state-of-security/space-bears-ransomware-what-you-need-know
-
4 cybersecurity trends to watch in 2025
Critical industries are up against;never before seen challenges to remain secure and operational, while regulatory pressures have completely upended the role of the CISO in corporate America. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cybersecurity-trends-outlook-2025/736929/
-
2025 Prediction 1: The Rise In Physical Threats To Corporate Executives Will Continue In 2025
On January 7, we published a press release to share our five predictions for cybersecurity in 2025. Over the next few weeks, we’ll publish a blog series that provides additional commentary on each prediction. This is the first blog in the series. Prediction Key Takeaways: Neglecting personal cybersecurity practices can lead to actual physical harm……
-
How initial access brokers (IABs) sell your users’ credentials
Initial Access Brokers (IABs) are specialized cybercriminals that break into corporate networks and sell stolen access to other attackers. Learn from Specops Software about how IABs operate and how businesses can protect themselves. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-initial-access-brokers-iabs-sell-your-users-credentials/
-
Six Tech Trends Shaping the Future of Brand Experiences
Six Tech Trends Shaping the Future of Brand Experiences madhav Wed, 01/08/2025 – 12:38 Business success relies on balancing positive brand experiences and maintaining consumer trust. Consumers want efficiency”, 2024 research from Thales found that 22% of consumers will give up after less than a minute if they’re having a frustrating customer experience”, but they…
-
The secret to your Artifactory: A Deep Dive into Critical Exposures
While Artifactory tokens aren’t the most common leaked secrets, GitGuardian’s research reveals their critical nature in corporate environments. Recent investigations across major industries show how these tokens frequently expose sensitive resources through build configurations and DevOps code. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/the-secret-to-your-artifactory-a-deep-dive-into-critical-exposures/
-
Personal liability sours 70% of CISOs on their role
Tags: breach, business, ceo, ciso, control, corporate, cybersecurity, group, insurance, jobs, ransomware, risk, technologyWith legal accountability tightening around those charged with maintaining enterprise cybersecurity, security leaders appear to be increasingly frustrated with their roles, eyeing the exit, and hesitant to pursue CISO gigs in the future. More than two thirds (70%) of CISOs recently surveyed said that “stories of CISOs being held personally liable for cybersecurity incidents has negatively…
-
Corporate cover-up behind world-beating cyber security record in Middle East
Report ranking Gulf corporations ahead of US and EU counterparts for cyber security has sparked debate about the region’s tendency for secrecy and state control First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366617675/Corporate-cover-up-behind-world-beating-cyber-security-record-in-Middle-East
-
Top Data Breaches in December 2024
December 2024 wrapped up the year with a chilling reminder of how vulnerable we all are to data breaches. From personal information to corporate secrets, it seemed like no one… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/12/top-data-breaches-in-december-2024/
-
792 Syndicate Suspects Arrested in Massive Crypto and Romance Scam: The Rise of Cybercrime as a Corporate Enterprise
The Economic and Financial Crimes Commission (EFCC) recently executed a landmark operation in Lagos, Nigeria, arresting 792 suspects for their alleged involvement in a cryptocurrency investment fraud and romance scam. The raid, conducted at an imposing seven-storey building in Victoria Island, sheds light on the systematic infrastructure and advanced methods employed by these fraud networks…
-
Cybercriminals Go Mobile: Executives Targeted in Advanced Phishing Campaigns
Cybercriminals are targeting corporate executives with highly advanced mobile spear phishing attacks, leveraging sophisticated evasion techniques and exploiting the inherent vulnerabilities of mobile devices, a new report reveals. In today’s... First seen on securityonline.info Jump to article: securityonline.info/cybercriminals-go-mobile-executives-targeted-in-advanced-phishing-campaigns/
-
Fake DocuSign docs used to secure corporate credentials in mishing campaign
First seen on scworld.com Jump to article: www.scworld.com/news/fake-docusign-docs-used-to-secure-corporate-credentials-in-mishing-campaign
-
US eyes ban on TP-Link routers amid cybersecurity concerns
Tags: attack, business, china, compliance, computer, corporate, country, cyber, cyberattack, cybercrime, cybersecurity, ddos, defense, espionage, exploit, flaw, government, hacking, infrastructure, intelligence, law, malicious, microsoft, network, risk, router, technology, threat, vulnerability, wifiThe US government is investigating TP-Link, a Chinese company that supplies about 65% of routers for American homes and small businesses, amid concerns about national security risks. Reports suggest these routers have vulnerabilities that cybercriminals exploit to compromise sensitive enterprise data.Investigations by the Commerce, Defense, and Justice Departments indicate that the routers may have been…
-
IAM Predictions for 2025: Identity as the Linchpin of Business Resilience
Tags: access, ai, apple, attack, authentication, banking, breach, business, cloud, compliance, corporate, credentials, crime, data, deep-fake, detection, finance, iam, identity, malicious, microsoft, mobile, office, passkey, password, privacy, regulation, resilience, risk, service, supply-chain, theft, threat, tool, vulnerabilityIAM Predictions for 2025: Identity as the Linchpin of Business Resilience madhav Thu, 12/19/2024 – 05:33 As we look toward 2025, the lessons of 2024 serve as a stark reminder of the rapidly evolving identity and access management (IAM) landscape. The numbers tell the story: The latest Identity Theft Resource Center report indicates that consumers…

