Author: Staff Writer

Avatar photo

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Cybersecurity Veteran who Led the Company to FedRAMP High Authorization Will Spearhead Cyber Strategy Through Next Phase of Growth  RegScale, the leading provider of Continuous Controls Monitoring (CCM), announced the promotion of Dale Hoak to Chief Information Security Officer (CISO). A U.S. Navy veteran and accomplished cybersecurity leader, Hoak joined RegScale as its first security hire and one of the first employees. Since then, he has been instrumental in building the company’s security foundation and guiding it through a period of rapid growth, leading to the successful attainment of our FedRAMP High authorization. Cyber Technology Insights : FTI Consulting Expands Cybersecurity Capabilities in Australia with…

Read More

Training Uses Lessons from Historic Disasters to Teach Modern AI Red-Teaming Cignal, a company founded by former FBI operational and intelligence experts, announced it has been selected to deliver a premier two-day artificial intelligence (AI) security training course at Black Hat USA 2025, one of the world’s leading cybersecurity conferences. The hands-on course provides security professionals with critical skills for testing and securing a variety of AI systems, including classification systems, generative models, vision models, agentic architectures, and AI systems-of-systems. Cyber Technology Insights : FTI Consulting Expands Cybersecurity Capabilities in Australia with Natasha Passley The training, titled “A Black Box: Lab-Based AI Security and…

Read More

Security Validation | SecValMSSP welcomes Michael D. Molinaro as Chief Information Security Office, VP of Security Architecture Security Validation | SecValMSSP, a leading provider of Managed Cybersecurity Services announces a landmark appointment with Michael D. Molinaro joining as Chief Information Security Officer, VP of Security Architecture. Michael’s exceptional career encompasses groundbreaking achievements in cybersecurity and technology leadership. As an architect of enterprise-scale security solutions, he has successfully managed technology portfolios exceeding $250 million and led global teams of more than 500 professionals. His innovative approaches to cybersecurity have resulted in the successful protection of critical national infrastructure and high-profile events, including the development of a pioneering…

Read More

Seceon, a leading provider of comprehensive cybersecurity solutions, is pleased to formalize a global partnership with The Calculus Group, a fast-growing Managed Security Services Provider (MSSP) known for delivering exceptional security operations and risk management services. This collaboration marks Calculus as a Global MSSP Partner of Seceon, leveraging the Seceon OTM platform to deliver next-generation, enterprise-grade cybersecurity solutions to enterprises across the world. Cyber Technology Insights : FTI Consulting Expands Cybersecurity Capabilities in Australia with Natasha Passley Through this partnership, Calculus will offer its global clientele advanced threat detection, rapid incident response, automated remediation, and simplified compliance, powered by Seceon’s award-winning AI-driven cybersecurity…

Read More

65 root domain indicators of compromise identified in growing campaign DNSFilter researchers have discovered that the Tycoon 2FA phishing-as-a-service (PhaaS) platform has significantly expanded its operations, including surging use of Spanish (.es) domains. This expansion marks a strategic evolution in Tycoon 2FA’s infrastructure design, demonstrating enhanced obfuscation techniques and highly targeted subdomain usage patterns. Understanding this shift is critical for defenders aiming to disrupt these operations, as traditional detection methods may fail against such ephemeral and compartmentalized infrastructure. Tycoon 2FA is a sophisticated PhaaS platform that has been active since August 2023, specializing in adversary-in-the-middle attacks to bypass multi-factor authentication. Tycoon…

Read More

Fast Facts Arrest of Xu Zewei: Italian authorities and FBI have arrested Xu Zewei, alleged hacker for China’s Hafnium group, involved in cyberattacks targeting U.S. COVID-19 research and exploiting Microsoft Exchange vulnerabilities. Charges and Consequences: Xu faces up to 20 years in prison for wire fraud and conspiracy; another co-conspirator, Zhang Yu, remains at large. Government Ties: The indictment claims both men operated under China’s Ministry of State Security, with Xu reportedly linked to a hacking firm, Shanghai Powerock Network Co. Ltd. Broader Cyber Campaign: Xu’s hacking facilitated a global attack on Microsoft Exchange servers, prompting an emergency warning from…

Read More

Welcome to your Daily CyberTech Highlights! Each day, we bring you the most essential news and insightful analysis from the world of Cybersecurity, Cloud security, Data protection, Data privacy and Technology. Stay informed on the latest trends, threats, and innovations shaping the digital landscape, so you can make informed decisions and stay ahead of the curve. Let’s dive into today’s top stories! Daily CyberTech Highlights Brand Covered: NTT DATA Headline: NTT DATA Appoints Anne-Sophie Lotgering as Europe CEO NTT DATA, a global leader in digital business and technology services, announced the appointment of Anne-Sophie Lotgering as the new Chief Executive Officer for Europe at NTT…

Read More

Quick Takeaways Impersonation Breach: M&S was breached through a sophisticated impersonation attack on April 17, where attackers tricked a third-party into resetting an employee’s password, enabling access to their network. Ransomware Involvement: The attack was linked to the DragonForce ransomware operation, believed to be based in Asia, employing double-extortion tactics—encrypting data and threatening its publication unless a ransom is paid. Data Compromise: The attack resulted in the encryption of numerous VMware ESXi servers and an estimated theft of 150GB of data, prompting M&S to shut down their systems to contain the breach. Ransom Negotiations: M&S opted not to engage directly…

Read More

South Korean telco SK Telecom invested ₩700 billion ($500 million USD) in cybersecurity. It was as part of its long-term vision to build artificial intelligence and strengthen infrastructure. Investors consider the investment as one of the largest telco-related cybersecurity investments in Asia. And reflects the industry’s broader shift toward security-first operations. SK Telecom is increasing its focus on AI, cloud, and edge technologies as part of its broader digital strategy. The $500 million investment will be used to build an end-to-end cybersecurity stack. That protects both its own digital assets and the infrastructure of partner firms and public sector organizations.…

Read More

Due to automation and a high-reward, low-risk threat environment, open source malware increased 188% year over year in the second quarter of this year.Supply-chain security vendor Sonatype today published its second quarter 2025 “Open Source Malware Index” report, dedicated to malicious open source packages published to popular repositories such as npm and PyPl.In many cases, attackers will publish files claiming they’re a different, more trusted software package (see typosquatting), and when the end user downloads and runs the package, the malware harvests the victim’s data and credentials. In others, like with XZ Utils last year, an attacker will poison a…

Read More