- Home
- Cybercrime and Ransomware
- Emerging Tech
- Threat Intelligence
- Expert Insights
- Careers and Learning
- Compliance
Subscribe to Updates
Subscribe to our newsletter and never miss our latest news
Subscribe my Newsletter for New Posts & tips Let's stay updated!
Author: Staff Writer
John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.
Sangfor Technologies, a global leader in cloud computing and cybersecurity, is thrilled to announce Sangfor Backup Platform (SBP) Powered by Veeam, the industry’s #1 backup and recovery solution. This platform combines Sangfor Hyper Converged Infrastructure (HCI) with Veeam’s cutting-edge technology, delivering advanced backupcapabilities that eliminate operational complexity, reduce costs, and safeguard critical workloads with unmatched efficiency. Sangfor Backup Platform, powered by Veeam, eliminates the need for resource-intensive backup agents, delivering a seamless experience that aligns with modern IT priorities. “Our collaboration with Veeam marks a pivotal step in redefining enterprise data protection,” said Darren Du, VP of Sangfor International Marketing Department. “By merging Sangfor…
Quick Takeaways A threat actor has re-released data from a 2021 AT&T breach affecting approximately 70 million customers, now linking Social Security numbers and birth dates directly to individual users. AT&T is investigating the situation, confirming that the data originates from the known breach and has been repackaged for sale on dark web forums. The leaked data, initially stolen in 2021 and now cleaned up, contains over 88 million lines, with 86 million unique records, including sensitive personal information such as phone numbers and encrypted Social Security numbers. This incident reiterates that the leak is not from a new data…
Barracuda Networks, Inc., a leading cybersecurity company providing complete protection against complex threats for all sized businesses, unveiled the BarracudaONE AI-powered cybersecurity platform. BarracudaONE maximizes threat protection and cyber resilience by unifying layered security defenses and providing deep, intelligent threat detection and response for managed service providers (MSPs), other channel partners and end users. Barracuda also announced the findings of a global survey highlighting the growing risk posed by security tool sprawl. According to the study conducted by Vanson Bourne, 65% of IT and security professionals say their organizations are juggling too many security tools. More than half (53%) of respondents also say their security tools…
Fast Facts State-sponsored Threat: Bitter, also known as APT-C-08 and TA397, is a state-backed hacking group linked to the Indian government, focusing on intelligence gathering primarily targeting South Asian entities and expanding into regions like Turkey and China. Sophisticated Techniques: The group employs diverse malware tools and sophisticated spear-phishing tactics, often masquerading as government entities to deploy malware via emails from compromised accounts or legitimate services like ProtonMail. Intelligence-Focused Operations: Bitter’s activities predominantly aim at governmental and diplomatic organizations to collect intelligence on foreign affairs, with a clear operational pattern aligning with Indian Standard Time. Advanced Malware Arsenal: Their toolkit…
Global data security leader Forcepoint announced the appointment of Matt Derdeyn as Chief Financial Officer. A seasoned finance executive with more than 20 years of experience in high-growth technology companies, Derdeyn joins Forcepoint’s executive team as the company scales adoption of its recently launched Data Security Cloud, a complete, AI-powered data security platform uniting visibility and control of data everywhere it’s created, stored or moved. “As enterprises look to adopt a more intelligent, adaptive approach to data security, Matt will help us scale our business and sharpen operational execution globally,” said Forcepoint CEO Ryan Windham. Cyber Technology Insights : Forcepoint Acquires Getvisibility for…
Fast Facts Play Ransomware Threat: The FBI and CISA warn that the Play ransomware gang is actively targeting U.S. critical infrastructure, having breached around 900 organizations globally since launching in June 2022. Exploiting Vulnerabilities: Recent attacks revolve around vulnerabilities in the remote support tool SimpleHelp, including a severe path traversal flaw (CVE-2024-57727) that allows unauthorized file access. Security Updates Needed: SimpleHelp has issued critical security updates to address identified vulnerabilities, emphasizing the importance for organizations to apply these fixes immediately. Healthcare Sector Impact: While only nine attacks affected healthcare, experts urge all sectors to heed the advisory and bolster defenses…
Fast Facts Victim Count: The Play ransomware gang, active since June 2022, has affected approximately 900 victims over three years, with a surge in attacks noted in 2024. Double-Extortion Tactics: Known for double-extortion methods, Play not only encrypts victims’ data but also exfiltrates it for additional leverage in extortion. Exploited Vulnerabilities: Initial access brokers associated with Play leverage multiple vulnerabilities (CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) in SimpleHelp RMM software to gain unauthorized access. Unique Communication Methods: Victims receive targeted communication via specific email domains and phone calls, where threat actors press for ransom payments while threatening to expose sensitive information. The…
BlueVoyant, the leader in integrated cybersecurity, launched its Software Bill of Materials (SBOM) management offering, which helps organizations reduce risk related to software by automating the ingestion, analysis, and tracking of software component information from third-party software vendors. The latest advancements enhance Supply Chain Defense, BlueVoyant’s next-generation third-party cyber risk management solution that continuously monitors suppliers, vendors, and other third parties, and then works with them to quickly remediate threats. BlueVoyant’s SBOM solution is powered through a partnership with Manifest, a cybersecurity company that specializes in securing software supply chains for corporate and government entities. More than 85% of applications…
Fast Facts Cybercriminals Vulnerable: Even cybercriminals face risks of malware infection when using unverified open source repositories, particularly seen in Sophos’s research on backdoored GitHub projects aimed at less experienced threat actors. Diverse Backdoors Discovered: The investigation revealed four types of backdoors—PreBuild, Python, screensaver, and JavaScript—embedded in the Sakura RAT malware project, demonstrating a sophisticated chain of infection. Widespread Malicious Operations: This campaign appears linked to a larger distribution-as-a-service (DaaS) operation, with significant overlaps in tactics and numerous instances of similar malicious repositories targeting game cheaters and inexperienced cybercriminals. Prolific Threat Actor: The creator behind the backdoored repositories, possibly using…
Security Posture Management and Passwordless Enhancements Expand RSA Identity Security Platform
RSA, the security-first identity leader, announced new Identity Security Posture Management (ISPM) and enhancements to the industry’s only complete, enterprise-grade passwordless identity platform at Infosecurity Europe 2025. These innovations will help enterprises proactively find and resolve security risks across hybrid and cloud environments and simplify users’ log-in processes with advanced, phishing-resistant security capabilities. “For identity teams overwhelmed by data, the new AI-powered dashboards from RSA provide the proactive information they need to prioritize actions and enhance their security,” said RSA Chief Product and Technology Officer Jim Taylor. RSA Announces New RSA Governance & Lifecycle ISPM Capabilities Built into the RSA Governance &…