Author: Staff Writer

Avatar photo

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Fast Facts Data Exposure Risk: Asana’s new Model Context Protocol (MCP) feature contained a logic flaw, leading to potential cross-organization data exposure among users due to improper AI-powered integration. Limited Exposure Scope: The flaw did not leak entire Asana workspaces; however, sensitive information, including task details and comments, could still be visible to other MCP users from different organizations. Timeline and Impact: The issue persisted for over a month before discovery on June 4, affecting around 1,000 customers and causing privacy and regulatory concerns for impacted entities. Recommended Actions: Asana urges administrators to review access logs, restrict LLM integration, and…

Read More

Improved margin, accelerated sales cycle and complete end-user proposition delivered through joint offering Arctera, a global leader in data management, Wasabi Technologies, the hot cloud storage company, and TD SYNNEX, a leading global distributor and solutions aggregator for the IT ecosystem, announced a joint channel-ready data protection solution to simplify sales for channel resellers. The new offering combines Arctera Backup Exec with Wasabi Hot Cloud Storage into a single offering available to channel partners through TD SYNNEX. The purpose-built integration makes comprehensive data protection easier for both end users and for channel partners. End users can enjoy end-to-end protection for…

Read More

Google announced a collaboration with CTC Global Corporation (CTC Global) to accelerate the deployment of next-generation transmission technology for the U.S. power grid. Together, Google and CTC Global will help scale the use of CTC Global’s high-capacity, U.S.-manufactured advanced conductors, a proven technology demonstrated to boost grid capacity and reliability at unparalleled speed. Google and CTC Global will identify high-impact transmission lines through a Request for Information (RFI) to states, utilities, and transmission developers interested in collaborating on solutions to unlock grid capacity across the country. Deployment of advanced conductors like CTC Global’s has the potential to double transmission capacity in months,…

Read More

In 2023, cyber threat actors (CTAs) intensified their efforts to target organizations with ransomware, distributed denial of service (DDoS) attacks, and other malicious activities. These threats present opportunities for CTAs to leak or steal your sensitive data, potentially leading to reputational damage, regulatory fines, and loss of customers. To protect your organization and strengthen your systems, it’s essential to establish robust cyber hygiene. Implementing the CIS Critical Security Controls® (CIS Controls®) and the CIS Benchmarks™, security best practices from the Center for Internet Security® (CIS®), can aid in this process. In this webinar, you’ll learn: Which trends are shaping the…

Read More

TechMD, a leading provider of cybersecurity and IT managed services, announced that it has been acquired by Integris, a national leader in IT managed services. TechMD has been backed by ClearLight Partners, a private equity firm based in Newport Beach, California. Integris is backed by OMERS Private Equity. The financial terms of the transaction were not disclosed. Cyber Technology Insights : Trellix Accelerates Organizational Cyber Resilience with Deepened AWS Integrations “We are excited for this new chapter at TechMD,” Kevin Blake, TechMD’s CEO, shared. “We are impressed with the Integris team and know they will be a world-class partner. We are…

Read More

Firmware security has emerged as a critical component of software supply chain security (SSCS), driven by increasing regulatory requirements and rising supply chain vulnerabilities, according to a new comprehensive market analysis from Omdia. The market is experiencing significant transformation as organizations across industries adopt firmware and SSCS solutions to manage these escalating pressures. “The growing awareness of software security and increasingly stringent legislation requires device manufacturers to fully understand the firmware embedded within their products, ensuring robust security from design, throughout the entire lifecycle,” notes Hollie Hennessy, Principal Analyst, Omdia. “Alongside this, asset owners face heightened concerns about supply chain security, which…

Read More

Fortinet, the global cybersecurity leader driving the convergence of networking and security, announced powerful updates to Lacework FortiCNAPP, making it easier than ever for customers to secure applications and workloads across hybrid and multi-cloud environments. The company also announced that the FortiAppSec Cloud service, FortiMail Workspace Security, FortiNDR Cloud, FortiSIEM, and Fortinet Incident Response services are now available in AWS Marketplace, a digital catalog that helps you find, buy, deploy, and manage software, data products, and professional services from thousands of vendors. “Fortinet is committed to accelerating secure cloud transformation for our customers,” said Nirav Shah, Senior Vice President, Products…

Read More

Partnership Helps MSPs Resolve Vulnerabilities 80% Faster Vicarius, a Vulnerability Remediation company, and Atera, an IT Management platform, announced a strategic partnership to provide Atera customers with seamless access to vRx by Vicarius, the industry’s first autonomous end-to-end vulnerability remediation platform. “There’s been a massive and much-needed shift in the industry from simply detecting vulnerabilities to actually resolving them. Our partnership with Atera brings together two powerful platforms to help MSPs not only identify risks but fix them fast, with minimal manual effort. This integration will help Managed Service Providers (MSPs) scale their remediation offerings while also boosting business efficiency.” – Tanya Alfonso,…

Read More

AvePoint, the global leader in data security, governance and resilience, announced new capabilities for the AvePoint Elements Platform that enable managed service providers (MSPs) to enhance data security offerings, streamline IT management, and provide optimization services at scale. Through seamless marketplace integration, deep risk user insights, and license and storage optimization, AvePoint is reinforcing its commitment to accelerating profitability and efficiency for MSPs, making their security practices more robust and efficiently organized. With nearly a third of small and midsized businesses (SMBs) falling victim to cyberattacks and 81% of SMBs believing AI is increasing the need for additional security controls, MSPs are in the…

Read More

NuHarbor Security is among the Best Places to Work in Vermont for the sixth time, and has been certified as a Most Loved Workplace by the Best Practice Institute NuHarbor Security, trusted managed security service provider to hundreds of public and private sector clients, has again been recognized for its exceptional workplace culture and employee satisfaction with two prestigious awards. For the sixth time, NuHarbor Security has been named one of the Best Places to Work in Vermont by VermontBiz and the Vermont Chamber of Commerce, and, for the second consecutive year, has won the category for medium-sized business. The selection process…

Read More