- Home
- Cybercrime and Ransomware
- Emerging Tech
- Threat Intelligence
- Expert Insights
- Careers and Learning
- Compliance
Subscribe to Updates
Subscribe to our newsletter and never miss our latest news
Subscribe my Newsletter for New Posts & tips Let's stay updated!
Author: Staff Writer
John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.
Summary Points Ahold Delhaize’s ransomware attack last year compromised the data of over 2.2 million individuals, revealing sensitive personal information including Social Security numbers and financial details. The attack, attributed to the Inc Ransom group, affected several of Ahold Delhaize’s supermarkets and pharmacies, with the hackers allegedly exfiltrating data from the company’s internal systems. Affected individuals are being notified and offered two years of free credit monitoring and identity protection services due to the breach. This incident highlights a rising trend in cyberattacks targeting the retail sector, with several other grocery-related companies experiencing similar threats recently. Key Challenge In a…
Privilege escalation is a cybercriminal’s stealth weapon, often undetected but devastating. It starts small, with standard user accounts, and quietly amplifies to root-level control, leaving your sensitive data exposed and vulnerable. Imagine cybercriminals navigating your network with full-system access, turning every layer of defense you have into mere spectator mode. With domain administrator privileges, they don’t just breach your system; they own your entire network. The threat isn’t just a breach – it’s a complete network takeover. But what if you could outsmart these intruders at their own game? Join our enlightening webinar to transform your approach to cybersecurity. Key…
Jun 24, 2025Ravie LakshmananThreat Exposure Management I had the honor of hosting the first episode of the Xposure Podcast live from Xposure Summit 2025. And I couldn’t have asked for a better kickoff panel: three cybersecurity leaders who don’t just talk security, they live it. Let me introduce them. Alex Delay, CISO at IDB Bank, knows what it means to defend a highly regulated environment. Ben Mead, Director of Cybersecurity at Avidity Biosciences, brings a forward-thinking security perspective that reflects the innovation behind Avidity’s targeted RNA therapeutics. Last but not least, Michael Francess, Director of Cybersecurity Advanced Threat at Wyndham…
Have you ever wondered how your SaaS security measures compare to others? Did you keep up with the significant trends that reshaped the SaaS security landscape in 2023? Perhaps you’re seeking effective strategies to shield your organization from emerging SaaS threats in 2024—especially considering the rise of AI applications in the SaaS domain. Join us for an enlightening webinar hosted by Ran Senderovitz, COO at Wing Security. This session will unveil key strategic insights and valuable lessons gleaned from analyzing the SaaS usage of 493 companies within Wing Security’s client base. Our aim is to equip you with practical, actionable…
Fast Facts Targeting Airlines: The FBI warns that the cybercrime group Scattered Spider has expanded its focus to the airline sector, exploiting social engineering tactics and bypassing multi-factor authentication (MFA) to gain unauthorized access. Sophisticated Execution: Scattered Spider combines extensive reconnaissance with advanced social engineering to impersonate high-level targets, enabling them to breach organizations quickly and deploy ransomware, highlighting the threat of identity manipulation. Exploiting Trust: The group leverages human workflows and urgent help desk processes to manipulate IT staff, indicating a fundamental vulnerability in corporate identity verification systems that can be exploited to bypass technical defenses. Call for Enhanced…
The new partnership delivers simple and easy WireGuard VPN service to USG FLEX H Series firewall customers at no additional cost. Zyxel Networks, a leader in delivering secure and AI-powered cloud networking solutions, announced a new partnership with Tailscale, the leading identity-native connectivity platform. This integration brings simplified, scalable, and secure VPN connectivity to Zyxel Networks’ USG FLEX H Series firewalls, empowering small businesses and advanced users to build private, peer-to-peer networks with ease and at no additional cost. Now available on Zyxel Networks ‘ USG FLEX H Series firewalls running uOS v1.32 and above, Tailscale’s WireGuard-based mesh VPN network is fully…
Top Highlights Enhanced Malware Functionality: The GIFTEDCROOK malware has evolved from a basic data stealer to a sophisticated intelligence-gathering tool, capable of exfiltrating sensitive documents and browser secrets, particularly targeting Ukrainian governmental and military entities. Phishing Tactics: Utilizing military-themed phishing emails with macro-laden Excel attachments, the malware circumvents defenses, deceiving users into activating macros that deploy the malicious software. Targeted File Capture: Versions 1.2 and 1.3 of GIFTEDCROOK can now harvest files below 7 MB modified in the last 45 days across various formats, indicating a strategic focus on gathering intelligence rather than mere credential theft. Geopolitical Implications: The malware’s…
In late 2023, the Scattered Spider threat group attacked the networks of several major financial and insurance entities, resulting in the largest and possibly the most impactful ransomware attack in recent memory. By gaining access to these networks through social engineering, the group bypassed multi-factor authentication (MFA) by attaining login credentials and one-time passwords. Silverfort’s threat research team has interacted closely with the identity threats used by Scattered Spider and in fact built a response playbook in real time to respond to an active Scattered Spider attack. This webinar will dissect the real-life scenario in which they were called upon to build and execute a response plan while attackers were moving inside an…
PRE Security, the AI Native Cybersecurity Company, announced the launch of their Multi-Tenant Management System for MSSPs and multiple premises environments, as well as further expansion of the executive team with key new hires and promotions. Executive Team Expansion PRE Security is excited to announce the appointment of two accomplished executives to its global Go To Market team: Miri Varbitzky, as Vice President of Global Business Development and International Sales, and Dominic Neo, as Vice President of Sales, APAC. Cyber Technology Insights : SecurityScorecard: 5 in 6 Organizations Exposed by Weak Supply-Chain Security Miri Varbitzky brings over 20 years of global sales leadership…
Point Wild, a leading portfolio of trusted security brands for businesses and consumers, announced the launch of Lat61 by Point Wild, a modular, plug-and-play security platform that unifies the company’s specialized cybersecurity solutions under a single, integrated system. Designed to deliver total protection for both businesses and consumers, Lat61 by Point Wild enables faster deployment, deeper threat intelligence and scalable growth across a rapidly evolving threat landscape. Cyber Technology Insights : SecurityScorecard: 5 in 6 Organizations Exposed by Weak Supply-Chain Security “Lat61 is the engine behind our protection,” said Dr. Zulfikar Ramzan, Chief Technology Officer at Point Wild and Head of the Lat61…