- Home
- Cybercrime and Ransomware
- Emerging Tech
- Threat Intelligence
- Expert Insights
- Careers and Learning
- Compliance
Subscribe to Updates
Subscribe to our newsletter and never miss our latest news
Subscribe my Newsletter for New Posts & tips Let's stay updated!
Author: Staff Writer
John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.
Top Highlights Failed Breaches by China-Linked Hackers: SentinelOne reported attempts by China-backed hackers to breach their security by targeting an IT vendor and conducting server reconnaissance. Extensive Targeting of Global Organizations: The attackers focused on a wide variety of entities, including government, finance, and media organizations, revealing security firms as prime targets. Identified Attack Clusters: The report identified two main activity clusters, PurpleHaze and ShadowPad, linked to Chinese cyber espionage, with significant overlaps in infrastructure and tactics. Highlighting Cybersecurity Vulnerabilities: SentinelOne emphasizes the vulnerability of cybersecurity companies to attacks due to their sensitive roles and visibility into client systems, urging…
Quick Takeaways Critical Vulnerabilities: Google has released urgent patches for a high-severity Chrome 0-day vulnerability exploited in the wild, highlighting the importance of timely updates to protect against potential attacks. New Malware Attacks: Notable cyber threats include PathWiper malware targeting Ukrainian infrastructure and the BladedFeline group attacking Iraqi officials, indicating rising regional cyber hostilities and the increasing sophistication of threat actors. Exploited Trust: New tactics like vishing, involving fake IT support impersonation to breach Salesforce, and bogus WordPress plugins to harvest credentials, show attackers are increasingly manipulating user trust rather than exploiting software vulnerabilities directly. Global Cybersecurity Alerts: Alerts on…
Essential Insights Kingsley Uchelue Utulu, a Nigerian national, has been sentenced to 63 months in prison for participating in a hacking scheme targeting US tax preparation companies since 2019, resulting in identity theft and fraudulent tax returns. The cybercriminals stole personal information from thousands of individuals, leading to attempted fraudulent tax returns valued at approximately $8.4 million, of which at least $2.5 million was successfully obtained. The stolen identities were also exploited to file deceptive claims with the SBA’s Economic Injury Disaster Loan program, yielding around $819,000 for the fraudsters. In addition to his prison sentence, Utulu must pay over…
Fast Facts Malware Development and Security Breaches: OpenAI banned ChatGPT accounts linked to Russian-speaking threat actors and Chinese hacking groups that used AI to enhance malware capabilities, including developing Windows malware and automating social media. ScopeCreep Campaign: The Russian threat actor’s malware campaign, dubbed ScopeCreep, involved creating trojanized software that escalates privileges, avoids detection, and exfiltrates sensitive data, using techniques like PowerShell obfuscation and DLL side-loading. Chinese Hacking Activities: Accounts associated with Chinese groups engaged in activities like open-source research, FTP server brute-forcing, and developing scripts for social media automation, exploiting AI for infrastructure setup and penetration testing. Wider Global…
Traditional incident response plans are no longer enough. Cybercriminals are relentlessly targeting identities, exploiting stolen credentials and weak access points to wreak havoc. While there’s a well-trodden path for handling malware and network breaches, the identity piece of the puzzle is often missing. Organizations lack the clear procedures to quickly identify compromised accounts and stop attackers from spreading like wildfire. That’s where a robust Identity Incident Response (IR) Playbook comes in. It’s the essential tool for fortifying your defenses and protecting your organization’s most valuable assets. In this webinar, you’ll discover: Why identity is the new frontline in the…
We’re bombarded with massive amounts of information every day. From daily news and stock updates to the latest box scores, keeping up with it all feels like a full-time job. Your IT infrastructure is no different. Millions of logs circulate through your systems—firewall data, system logs, and endpoint events, to name a few. Security Information and Event Management (SIEM) was designed to make sense of it all. Centralizing logs is at the heart of what SIEM was meant to do. But does simply having an SIEM and organizing your data help if there’s still too much noise to make sense…
Against a backdrop of uncertainty, employers across the economy continue to build their cybersecurity capacity through talent acquisition and skills development, according to new data from CyberSeek, the most comprehensive source of information on the U.S. cybersecurity workforce. Employers in the private and public sectors deployed 514,359 job listings over the past 12 months in recruiting for dedicated cybersecurity jobs and adjacent technical positions with a heavy cybersecurity skills requirement. This represents an increase of nearly 57,000 listings, or 12% over the lull in hiring activity during the prior 12-month reporting period. Cyber Technology Insights : Cisco, NTT DATA Team Up to Simplify 5G…
GuidePoint Security, a cybersecurity solutions leader enabling organizations to make smarter decisions and minimize risk, announced the opening of its new global headquarters at 1900 Reston Metro Plaza in Reston, VA. The new location marks a pivotal milestone in the company’s evolution and continued expansion—representing its third office opening this year—and underscores GuidePoint’s rapid growth, expanding service portfolio and deepening cybersecurity market leadership. This headquarters is more than a new address—it’s a launchpad for the next chapter of GuidePoint Security. Strategically located at Reston Station in the heart of Northern Virginia’s tech corridor, GuidePoint Security’s new state-of-the-art headquarters is purpose-built…
RSA, the security-first identity leader, announced new innovations that expand RSA’s complete passwordless solutions, including support for Microsoft Entra ID-joined desktops and legacy, RADIUS-based environments at Identiverse. These innovations help organizations accelerate deployment of phishing-resistant passwordless solutions across their entire environment, reducing risks, modernizing authentication, and driving efficiency. “Not all passwordless is created equal: government agencies, finance, energy and healthcare providers, and other security-first organizations need a passwordless solution for all users, environments, and devices,” said RSA CEO Rohit Ghai. Available as part of RSA ID Plus, the only complete passwordless identity security platform, new passwordless features include: Cyber Technology Insights : Varonis at…
The ransomware threat is escalating. Attacks are up 17.8%, and ransom payouts are reaching record highs. How can you protect your organization in this evolving landscape? Join us for an exclusive webinar featuring Emily Laufer, Director of Product Marketing at Zscaler, as she unpacks the latest findings from the Zscaler ThreatLabz 2024 Ransomware Report. In this insightful session, you will: Gain a deep understanding of the current threat landscape: Learn which industries and regions are most targeted, and uncover the dynamics behind the alarming rise in ransom demands. Identify emerging threats: Discover the new ransomware families that are posing…