Author: Staff Writer

Avatar photo

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Doppel, a leading provider of multi-channel social engineering defense, has partnered with Filigran, the team behind the open-source threat intelligence platform OpenCTI. This collaboration allows organizations to integrate Doppel’s real-time alert data directly into OpenCTI, improving the speed and efficiency of threat intelligence operations across global enterprises. “Security teams are under growing pressure to detect and respond to complex social engineering attacks,” said Kevin Tian, Co-founder and CEO of Doppel. “Our integration with OpenCTI delivers a more streamlined, analyst-focused approach, turning threat data into actionable intelligence.” Cyber Technology Insights : Akamai Partners with Aptum to Speed Up Cloud Migration and Optimization Seamless…

Read More

Trellix, a leader in AI-driven cybersecurity solutions, has announced that its Trellix DLP Endpoint Complete now supports ARM-compatible devices running Windows operating systems. This update enables organizations to deploy full DLP capabilities on devices powered by Snapdragon chipsets, including laptops, PCs, and servers. Trellix has positioned itself at the forefront of ARM-compatible device protection, ensuring early adoption and robust security for emerging hardware architectures. “Our clients are increasingly incorporating ARM-based devices into their environments, but support from security vendors has been limited,” said Ted Wilson, Senior Director of Product Management, Data Security at Trellix. “Protecting data across all endpoints is…

Read More

OPTIA, a leader in ruggedized, outstanding GPU computing, and Patero, a frontrunner in post-quantum cryptography, have introduced a groundbreaking solution that integrates Patero’s CryptoQoR encryption suite into OPTIA’s NVIDIA-based systems. This collaboration results in the industry’s first GPU server equipped with post-quantum cryptography, designed for mission-critical defense and commercial applications. By embedding Patero’s quantum-safe encryption, OPTIA’s systems can now safeguard both incoming and outgoing data from current cyber threats as well as future quantum-based attacks. Built to meet the demanding computational requirements of the U.S. Department of Defense (DoD) and engineered for deployment in tactical environments, OPTIA’s portable platforms support…

Read More

Rockwell Automation, Inc., the world leader in industrial automation and digital transformation, has unveiled findings from its 10th annual State of Smart Manufacturing Report. The report, based on insights from over 1,500 manufacturing leaders across 17 leading manufacturing nations, underscores how cybersecurity is increasingly recognized as a critical business concern. About one-third of respondents hold direct responsibilities for both information technology (IT) and operational technology (OT) cybersecurity. As manufacturers expand smart operations, the growing convergence of IT and OT systems has amplified vulnerability to cyberattacks. According to the report, organizations are now turning to artificial intelligence (AI) to manage these…

Read More

ConnectWise, the world’s leading software company dedicated to the success of managed service providers (MSPs), announced the strategic retirement of IT Nation Secure™ as a standalone event, effective 2026. Instead of a single standalone event, IT Nation will integrate the acclaimed cybersecurity content from IT Nation Secure directly into its flagship IT Nation Connect™ conferences in Europe, Australia/New Zealand (ANZ), and North America annually. This transition reflects IT Nation’s commitment to delivering greater impact through fewer, more immersive events while meeting the evolving needs of MSPs in today’s integrated cybersecurity landscape. “With cybersecurity now embedded in every decision an MSP…

Read More

ConnectWise, the world’s leading software company dedicated to the success of managed service providers (MSPs), announced ConnectWise SaaS Security, the industry’s most powerful solution purpose-built for MSPs to manage and monetize Microsoft 365 security services. ConnectWise SaaS security provides MSPs with a proven blueprint for more efficient security event monitoring and management while enhancing security engagement and remediation with small to medium-sized business (SMB) customers, capitalizing on the growing demand for Microsoft 365 security services. Cyber Technology Insights : Akamai Partners with Aptum to Speed Up Cloud Migration and Optimization The demand for Microsoft 365 security services is skyrocketing. According to the ConnectWise State…

Read More

Aug 13, 2025Ravie LakshmananVulnerability / Software Security Zoom and Xerox have addressed critical security flaws in Zoom Clients for Windows and FreeFlow Core that could allow privilege escalation and remote code execution. The vulnerability impacting Zoom Clients for Windows, tracked as CVE-2025-49457 (CVSS score: 9.6), relates to a case of an untrusted search path that could pave the way for privilege escalation. “Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access,” Zoom said in a security bulletin on Tuesday. The issue, reported by its own Offensive…

Read More

Fortinet, whose technologies are a popular target for attackers, has disclosed a critical, unauthenticated remote code execution vulnerability in its FortiSIEM platform. A proof-of-concept exploit for the flaw is already circulating in the wild, signaling the potential for imminent attacks.Adding to the concern, researchers at GreyNoise have detected a sharp uptick in malicious activity targeting Fortinet SSL VPNs and the FortiManager centralized management platform that many organizations use for centralized device management. Such traffic in the past has often preceded the discovery and disclosure of new vulnerabilities in the affected products.Unauthenticated Remote AttacksThe new vulnerability that Fortinet disclosed this week,…

Read More

Summary Points Critical Vulnerability Alert: Fortinet reports a remote unauthenticated command injection flaw (CVE-2025-25256) in FortiSIEM, rated critical (CVSS: 9.8), with functional exploit code actively in the wild, prompting immediate updates from administrators. Impact Scope: The flaw affects FortiSIEM versions 5.4 to 7.3, widely used by governments, enterprises, and healthcare providers for security monitoring, making it essential for security operations. Exploit Characteristics: Attackers can execute unauthorized code via crafted CLI requests without authentication, and the exploitation leaves no distinctive indicators of compromise (IOCs) for detection. Mitigation Recommendations: Users must upgrade to actively supported FortiSIEM versions (7.3.2 and others listed) and…

Read More

Summary Points Collaboration on Guidance: U.S., Australia, Canada, Germany, the Netherlands, and New Zealand agencies issued a joint document to aid critical infrastructure organizations in managing operational technology asset inventories. Asset Inventory Importance: The guidance emphasizes creating detailed asset inventories to enhance security by identifying vulnerable tools and assessing lifecycle status. Mitigating Cyber Risks: Poor asset visibility can worsen cyberattack impacts; thus, prioritizing security based on critical risks and evaluating maintenance plans are recommended. Cost-Benefit Analysis: Organizations should compare the costs of upgrading outdated systems against potential outages, ensuring they procure secure systems and maintain up-to-date inventories. Essential Steps in…

Read More