Tag: resilience
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Peers propose report into Computer Misuse Act reform
After previous proposals were brushed aside, Computer Misuse Act reform may be back on the agenda under a new amendment to the Cyber Security and Resilience Bill. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649543/Peers-propose-report-into-Computer-Misuse-Act-reform
-
UK’s small power plants face higher cyber risk into 2030s despite Iran-linked hack
Decision not to improve resilience sooner described as ‘unacceptable gamble with our national security’Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which is understood to have shut…
-
UK’s small power plants face continued cyber risk after Iran-linked hack
Government measures to improve resilience are not due until 2030 and July’s hack has not altered this timeline<br><br> Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which…
-
UK government set to adjudicate on ‘risky’ tech purchases
New proposals for amendments to the Cyber Security and Resilience Bill would enable the UK government to clamp down on purchases of technology from suppliers linked to hostile foreign countries. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649781/UK-government-set-to-adjudicate-on-risky-tech-purchases
-
Kritische Schwachstellen zur Ausweitung von Active-Directory-Rechten
‘ResetNightmare” und ‘KerberLoss” nutzen Schwächen von Identitätssystemen in der Interpretation von Benutzer- und Dienstnamen aus, wodurch Angreifer möglicherweise Dienste stören, die Authentifizierung untergraben oder sich als privilegierte Benutzer ausgeben können. Der Experte für identitätsbasierte Cyber-Resilienz und Krisenbewältigung, Semperis, gab bekannt, dass Shai Laron, Sicherheitsforscher bei Semperis, zwei kritische Sicherheitslücken in Active-Directory (AD) entdeckt hat, die…
-
Ab dem 11. September steht Europas Software-Lieferkette unter einer 24-Stunden Meldefrist
Ab dem 11. September 2026 gilt die Anwendung von Artikel 14 des Cyber-Resilience-Act (CRA). Dann müssen Software-Hersteller aktiv schwerwiegende Sicherheitsvorfälle und ausgenutzte Schwachstellen über die Single-Reporting-Platform der <> melden. Diese Plattform ist zwar noch nicht geöffnet. Dennoch können fast alle Entscheidungen, die für eine reibungslose Erstellung des ersten Berichts gemäß den von ENISA im Juli…
-
NIS2, BCM und Audit: Warum viele Projekte feststecken Endlich in die Umsetzung kommen
Strukturen, Anforderungen und Tools sind vielerorts vorhanden dennoch stockt die operative Umsetzung. Es sind zumeist organisatorische Hürden die NIS2-, ISMS- und BCM-Initiativen ausbremsen. Unternehmen können mit klarer Governance, verbindlichen Verantwortlichkeiten und kontinuierlicher Steuerung echte Resilienz schaffen. First seen on ap-verlag.de Jump to article: ap-verlag.de/nis2-bcm-und-audit-warum-viele-projekte-feststecken-endlich-in-die-umsetzung-kommen/107035/
-
Cyberangriffe auf Energieversorger: Wenn Manipulation wichtiger wird als Datendiebstahl
Cyberangriffe auf Energieversorger zielen zunehmend auf Manipulation und Betriebsstörungen. OT-Sicherheit und Resilienz werden damit entscheidend. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cyberangriffe-auf-energieversorger-wenn-manipulation-wichtiger-wird-als-datendiebstahl/a46248/
-
The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take
As you can imagine, concerns about AI-driven threats have come up often in our recent discussions with our clients here at ColorTokens. And for good reason. AI has revolutionized the threat landscape. It can quickly reverse-engineer services, processes, and applications, discover multiple vulnerabilities faster than human attackers ever could, and use automation to chain 30,……
-
The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take
As you can imagine, concerns about AI-driven threats have come up often in our recent discussions with our clients here at ColorTokens. And for good reason. AI has revolutionized the threat landscape. It can quickly reverse-engineer services, processes, and applications, discover multiple vulnerabilities faster than human attackers ever could, and use automation to chain 30,……
-
The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take
As you can imagine, concerns about AI-driven threats have come up often in our recent discussions with our clients here at ColorTokens. And for good reason. AI has revolutionized the threat landscape. It can quickly reverse-engineer services, processes, and applications, discover multiple vulnerabilities faster than human attackers ever could, and use automation to chain 30,……
-
NIS2 macht Cyber-Resilienz zur Vorstandspflicht – Abwarten wird bei NIS2 zum Haftungsrisiko
First seen on security-insider.de Jump to article: www.security-insider.de/nis2-umsetzung-haftungsrisiko-management-a-50acd4ecb8cb7d2cf089f5a2c8aad888/
-
Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/water-healthcare-cyberattacks-credit-ratings-fitch/828384/
-
Backup, Recovery, Cyber-Resilienz und Storage-Optimierung – Pink Elephant stärkt neue TDN-Einheit ‘Data Resilience Services”
First seen on security-insider.de Jump to article: www.security-insider.de/pink-elephant-staerkt-neue-tdn-einheit-data-resilience-services-a-0a50766c05258d5246c7a2bacc0ab1ab/
-
Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/water-healthcare-cyberattacks-credit-ratings-fitch/828384/

