Tag: data
-
CISOs: Stop trying to do the lawyer’s job
Tags: breach, business, ciso, compliance, cybersecurity, data, email, finance, group, guide, incident response, international, jobs, law, privacy, RedTeam, risk, risk-management, security-incident, service, skills, strategy, technology, training, updateThere’s a joke that’s been floating around boardrooms for years: “What’s the difference between lawyers and engineers? Lawyers don’t think they’re engineers.”This light-hearted jab highlights a fundamental difference between the two professions. Engineers, and by extension CISOs, focus on building and fixing things, learning a wide array of skills, sometimes sticking their hands into technologies…
-
Judge says US Treasury ‘more vulnerable to hacking’ since Trump let the DOGE out
Order requires destruction of departmental data accessed by Musky men First seen on theregister.com Jump to article: www.theregister.com/2025/02/10/doge_infosec_impact_court_order/
-
Stay Relaxed with Top-Notch API Security
Are Businesses Truly Aware of the Importance of Non-Human Identities in Cybersecurity? There’s one critical aspect that’s frequently overlooked: Non-Human Identities (NHIs). These machine identities, composed of Secrets such as tokens, keys, and encrypted passwords, play a pivotal role in maintaining top-notch API security in organizations, keeping their valuable data safe and their operations running……
-
Building an Impenetrable Framework for Data Security
Why does the Secure Framework Matter? The focus of this operation isn’t just about the immediate prevention of potential threats but ensuring we have a solid line of defense that could weather any storm thrown our way. It’s all about staying ahead of the curve and keeping your organization protected from both known and unknown……
-
UK Is Ordering Apple to Break Its Own Encryption
The Washington Post is reporting that the UK government has served Apple with a “technical capability notice” as defined by the 2016 Investigatory Powers Act, requiring it to break the Advanced Data Protection encryption in iCloud for the benefit of law enforcement. This is a big deal, and something we in the security community have…
-
Data Complexity Report: Ein entscheidendes Jahr für KI liegt vor uns
Die weltweite KI-Transformation schafft Herausforderungen in Sachen Sicherheit und Nachhaltigkeit. NetApp untersucht in seinem aktuellen Data Complexity Report, wie Unternehmen die steigende Komplexität ihres Datenmanagements für künstliche Intelligenz (KI) bewältigen [1]. Der Bericht gibt einen Überblick darüber, wie KI die globale Unternehmenswelt im Jahr 2025 und darüber hinaus beeinflussen wird und zeigt deutlich, dass… First…
-
Justifying the Investment in Cloud Compliance
Why is Cloud Compliance Investment a Necessity? I often get asked, “Why is cloud compliance investment a necessity?” The answer is simple; it’s all about securing non-human identities (NHIs) and managing secrets. By understanding the importance of NHIs and secrets management, companies can efficiently oversee the end-to-end protection of their data, thereby justifying their cloud……
-
The Wall Street Journal: Lawmakers Push to Ban DeepSeek App From U.S. Government Devices
Bipartisan Effort Seeks to Protect National Security Amid Concerns Over Chinese Data Collection WASHINGTON”, A new bill set to be introduced Thursday was initiated based on an analysis by Ivan Tsarynny , CEO of Feroot Security, which uncovered serious security risks posed by the DeepSeek chatbot application. The findings by Feroot Security, first reported by…
-
Why 24/7 Security Monitoring Matters for Your Company
Gary Perkins, CISO at CISO Global Cyber threats don’t take evenings or weekends off, and neither should your security team. Companies need peace of mind knowing that dedicated professionals are continuously monitoring their infrastructure and data, ensuring both proactive prevention and rapid response to potential incidents. The Role of Expert Analysts in Securing Your Company……
-
Ransomware attackers turn to workers for data breach access
First seen on scworld.com Jump to article: www.scworld.com/news/ransomware-attackers-turn-to-workers-for-data-breach-access
-
UK Secret Order Demands That Apple Give Access to Users’ Encrypted Data
Plus: Benjamin Netanyahu gives Donald Trump a golden pager, Hewlett Packard Enterprise blames Russian government hackers for a breach, and more. First seen on wired.com Jump to article: www.wired.com/story/uk-secret-order-apple-users-encrypted-data/
-
DeepSeek, data privacy on lawmakers’ radar
U.S. lawmakers are taking steps to ban DeepSeek from government devices, which should signal to enterprises the inherent risks of using the service. First seen on techtarget.com Jump to article: www.techtarget.com/searchcio/news/366619060/DeepSeek-data-privacy-on-lawmakers-radar
-
Asian Governments Rush to Ban DeepSeek Over Privacy Concerns
Governments Are Skeptical of Chinese A1 Platform’s Data Security Controls. Countries across Asia are racing to ban government officials, national agencies and critical infrastructure organizations from using Chinese artificial intelligence company DeepSeek’s open-source chatbot application, citing data security and privacy risks. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/asian-governments-rush-to-ban-deepseek-over-privacy-concerns-a-27476
-
Catholic Hospital Chain: 2023 Hack Affected Nearly 900,000
Midwest Chain Also Faces Multiple Federal Data Privacy Lawsuits. A Midwest chain of doctor practices and 13 Catholic hospitals has reported that a 2023 hacking incident that disrupted its IT system for several days and may have compromised the sensitive data of nearly 900,000 people. The group is also facing an assortment of data privacy…
-
Worker distraction is on the rise. Digital employee experience (DEX) platforms can help
With the dramatic increase in remote work in the last few years, many of us are actually working longer hours, ricocheting between communication platforms, learning new systems on the fly, and struggling to fix our own tech issues.It’s all adding up to a new kind of burnoutIt’s also focusing renewed attention on the digital employee experience…
-
Randall Munroe’s XKCD ‘Rotary Tool’
via the comic humor & dry wit of Randall Munroe, creator of XKCD Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2025/02/randall-munroes-xkcd-rotary-tool/
-
Label maker Avery says ransomware investigation also found credit-card scraper
An investigation into a ransomware attack led label-maker Avery Products to also find malware that was skimming credit card details from transactions on its website, according to a data breach notification by the company. First seen on therecord.media Jump to article: therecord.media/avery-products-ransomware-data-breach-notification
-
Many state privacy laws fail to protect consumer data, report finds
First seen on scworld.com Jump to article: www.scworld.com/brief/many-state-privacy-laws-fail-to-protect-consumer-data-report-finds
-
Report reveals security failures in PowerSchool data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/report-reveals-security-failures-in-powerschool-data-breach
-
Accounts compromised in data breaches spike
First seen on scworld.com Jump to article: www.scworld.com/brief/accounts-compromised-in-data-breaches-spike
-
Attackers hide malicious code in Hugging Face AI model Pickle files
Tags: ai, data, github, malicious, ml, open-source, programming, remote-code-execution, risk, service, software, threat, tool, vulnerabilityLike all repositories of open-source software in recent years, AI model hosting platform Hugging Face has been abused by attackers to upload trojanized projects and assets with the goal of infecting unsuspecting users. The latest technique observed by researchers involves intentionally broken but poisoned Python object serialization files called Pickle files.Often described as the GitHub…
-
ISMG Editors: AI Security Wake-Up Call From DeepSeek
Tags: ai, api, ciso, data, data-breach, governance, leak, open-source, risk, risk-management, vulnerabilityAlso: Addressing AI Vulnerabilities and Governance Challenges. DeepSeek, an advanced open-source AI model, is under scrutiny for its safety guardrails failing multiple security tests and a data leak that exposed user information and API keys. Sam Curry, CISO at Zscaler, discusses AI security, risk management and upcoming U.S. policy changes. First seen on govinfosecurity.com Jump…
-
HPE notifies employees of data breach after Russian Office 365 hack
Hewlett Packard Enterprise (HPE) is notifying employees whose data was stolen from the company’s Office 365 email environment by Russian state-sponsored hackers in a May 2023 cyberattack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hpe-notifies-employees-of-data-breach-after-russian-office-365-hack/
-
10 Common Mistakes in Managing Your Splunk Environment (and how to avoid them)
Tags: dataSplunk is essential for data management and security, but optimizing its implementation and maintenance can be challenging. Avoid these ten common mistakes that can weaken your Splunk environment with practical tips for success. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/02/10-common-mistakes-in-managing-your-splunk-environment-and-how-to-avoid-them/
-
Behavioral Analytics in Cybersecurity: Who Benefits Most?
As the cost of data breaches continues to climb, the role of user and entity behavioral analytics (UEBA) has never been more important. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/behavioral-analytics-cybersecurity-who-benefits-most
-
Yahoo Finance: U.S. Lawmakers Push to Ban China’s DeepSeek AI Over Security Risks Feroot Security Analysis
Washington, D.C. U.S. lawmakers announced a bill to ban DeepSeek, the Chinese AI chatbot app, from government devices following a security analysis by Feroot Security that revealed alarming privacy and national security risks. The research suggests that DeepSeek collects user data, including digital fingerprints, login credentials, and behavioral information, potentially sending it to servers…The post…
-
US health system notifies 882,000 patients of August 2023 breach
Hospital Sisters Health System notified over 882,000 patients that an August 2023 cyberattack led to a data breach that exposed their personal and health information. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-health-system-notifies-882-000-patients-of-august-2023-breach/
-
Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks
Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is transmitted by focusing on the meaning of data rather than raw content. Unlike traditional communication methods, these systems encode semantic features such as text, images, or speech into low-dimensional vectors, significantly reducing bandwidth usage while maintaining the integrity of transmitted information.…
-
DeepSeek App Transmits Sensitive User and Device Data Without Encryption
A new audit of DeepSeek’s mobile app for the Apple iOS operating system has found glaring security issues, the foremost being that it sends sensitive data over the internet sans any encryption, exposing it to interception and manipulation attacks.The assessment comes from NowSecure, which also found that the app fails to adhere to best security…

