Author: Staff Writer

Avatar photo

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

ThreatConnect, maker of leading threat and risk-informed defense solutions, announced that it has achieved FedRAMP Authorization status for its threat intelligence platform. This marks a significant milestone in the company’s efforts to meet the rigorous security standards required for federal government cloud services. FedRAMP, the Federal Risk and Authorization Management Program, is a government-wide program designed to provide a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. Cyber Technology Insights : LevelBlue Agrees to Acquire Aon’s Cybersecurity and IP Litigation Consulting Groups The FedRAMP Authorized designation indicates that government agencies can confidently…

Read More

Bridge LMS has been accredited with the stringent SOC 2 Type II compliance and ISO 27001/27701 certifications, underlining its commitment to security and trust. Bridge, an all-in-one learning management system and performance platform, announced that it has achieved SOC 2 compliance and adherence to ISO 27001/27701 certification standards. These rigorous information security standards cement Bridge’s standing as a safe, reliable learning platform for organizations across the globe and sets the LMS apart from many competitors in the market. SOC 2 Type II ComplianceThe SOC 2 Type II audit is a detailed investigation into the internal controls and security practices of a software…

Read More

Edge AI processing with Double Key Encryption addresses enterprise privacy concerns for confidential meeting transcription csky.ai and DuoKey announced at Vivatech the launch of their integrated secure transcription solution for Microsoft 365. The solution combines csky.ai’s offline AI transcription technology with DuoKey’s Double Key Encryption (DKE) to enable organisations to transcribe confidential meetings while maintaining complete control over sensitive data in the Microsoft cloud. The solution processes meeting transcriptions entirely offline using csky.ai’s ClearMind device, which runs a large language model locally without internet connectivity. This edge computing approach means sensitive audio never leaves the organisation’s premises during transcription. The system…

Read More

Top Highlights Machine Identity Blind Spot: Non-human identities (NHIs), including service accounts and API keys, now outnumber humans by up to 100:1, creating significant security vulnerabilities with orphaned credentials and "zombie" secrets especially amidst increasing cloud adoption and automation. Secrets Sprawl Threat: GitGuardian’s research reveals that 70% of valid secrets in public repositories remained active over three years, fueling security breaches in major organizations, underscoring that compromised credentials are linked to over 80% of breaches. Insufficient Traditional Solutions: Existing secrets managers fail to address comprehensive NHI governance; they can inadvertently increase risks of secrets leakage, with GitGuardian noting higher risks…

Read More

KDAN, a leading global Software-as-a-Service (SaaS) provider, announced the launch of LynxPDF, a comprehensive enterprise PDF management solution that combines artificial intelligence-driven document processing with self-hosted deployment options. The platform addresses critical business challenges including data security compliance, workflow efficiency, and digital transformation for enterprises worldwide, offering advanced features like intelligent document processing (IDP), offline capabilities, and enterprise-grade encryption. LynxPDF offers core PDF functions such as editing, conversion, signing, and encryption, while supporting advanced enterprise features, including offline capabilities, self-hosted deployment, batch processing, and single sign-on (SSO). Leveraging AI-driven Intelligent Document Processing (IDP), LynxPDF can automatically extract data from documents,…

Read More

Essential Insights Fog Ransomware’s Unique Tools: Fog ransomware utilizes an unusual toolkit, including open-source pentesting tools and Syteca, a legitimate employee monitoring software that captures keystrokes and screen activity, enabling attackers to gather sensitive information undetected. Attack Methodology: Initially observed in May 2022, Fog hackers exploit compromised VPN credentials for network access, use "pass-the-hash" techniques for admin privileges, and employ vulnerabilities in Veeam Backup and SonicWall SSL VPN servers to execute attacks. Discovery and Analysis: Recent investigations by Symantec and Carbon Black revealed new attack tools during a financial sector incident in Asia, highlighting software like GC2 for command-and-control operations…

Read More

CyberArk, the global leader in identity security, announced console and partner program updates designed to help Managed Services Providers (MSPs) drive profitable identity security-based growth. CyberArk MSP Hub is an evolved SaaS-based management console that offers a one-stop-shop entry point for MSPs to offer the CyberArk Identity Security Platform to their customer base, and will be supported by a new MSP-optimized partner program. “In a hyper-connected world, selecting the right MSP is about finding a trusted partner that strengthens both daily operations and cybersecurity posture,” said Micheal Steele, Sr. Security Operations Manager, Optiv. “With CyberArk MSP solutions, we have maximized efficiency, enabling us to focus on…

Read More

Essential Insights Operation Secure: Interpol’s multi-month initiative, involving over two dozen countries, targeted infostealer malware campaigns originating in Asia, leading to significant law enforcement actions. Massive Takedown: Authorities dismantled 20,000 IP addresses and domains, seized 41 servers, and confiscated over 100 GB of data, resulting in the arrest of 32 suspects, primarily in Vietnam and Sri Lanka. Victim Notification: Over 216,000 potential victims were informed of their compromised data due to infostealer malware, prompting them to take corrective action. Focus on Infostealers: The operation concentrated on nearly 70 malware variants, including Lumma, Vidar, and META Stealer, highlighting a continuous threat…

Read More

CrowdStrike expands protection for NVIDIA Enterprise AI Factories, integrates Falcon Cloud Security with NVIDIA universal LLM NIM microservices and NeMo Safety for secure cloud deployment CrowdStrike announced the integration of Falcon Cloud Security with NVIDIA universal LLM NIM microservices and NeMo Safety, delivering full lifecycle protection for AI and over 100,000 large language models (LLMs) in collaboration with NVIDIA. Expanding CrowdStrike’s protection for Enterprise AI Factories with NVIDIA, this new integration enables customers to safely run and scale diverse LLM applications across hybrid and multi-cloud environments from day one. From build, to runtime, to posture management, the CrowdStrike Falcon® platform is securing every stage of AI innovation powered…

Read More

Unique AI Vulnerability Research Yields Breakthrough ‘EchoLeak’ Discovery: First Zero-Click AI Vulnerability in Microsoft 365 Copilot Aim Security, the fastest-growing AI Security Platform, announced the launch of Aim Labs, a new advanced vulnerability research division dedicated to uncovering and mitigating the most sophisticated threats targeting AI technologies. Led by former Google leaders and top alumni from Israel’s elite Unit 8200, Aim Labs unites a rare combination of deep AI research and advanced cybersecurity expertise to drive innovation and set new standards for real-time defense through the proactive sharing of high quality threat intelligence. Cyber Technology Insights : CyberArk Empowers MSPs with New Console…

Read More