Author: Staff Writer

Avatar photo

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Fast Facts Two members of the cybercriminal group ViLE were sentenced for hacking a federal law enforcement portal in an extortion scheme, using personal data for harassment and threats, referred to as "doxing." The defendants obtained sensitive information through various illegal methods, including impersonating law enforcement and accessing government databases, demonstrating a sophisticated and calculated approach to cybercrime. Sagar Steven Singh and Nicholas Ceraolo were sentenced to 27 and 25 months, respectively, for aggravated identity theft and conspiracy to commit computer intrusion, following their guilty pleas for stealing and extorting individuals. The hacked portal, identified by reports as a DEA…

Read More

Quick Takeaways Growing Security Demands: Security teams are under increased pressure to justify large budgets, with executives seeking clarity on financial exposure and risk instead of traditional metrics like vulnerability counts. Business Value Assessment (BVA): A BVA connects security exposures to potential costs, emphasizing cost avoidance, reduction, and efficiency gains, enabling security leaders to demonstrate tangible value and align with business objectives. Risk of Inaction: Delays in addressing security vulnerabilities can significantly inflate breach costs—sometimes exceeding $500,000 monthly—highlighting the importance of proactive strategy and risk management. Alignment Across Teams: A BVA fosters collaboration between security, IT, and finance by providing…

Read More

Essential Insights Sentencing Outcome: Sagar Steven Singh (27 months) and Nicholas Ceraolo (25 months) were sentenced for conspiracy to commit computer intrusion and aggravated identity theft after pleading guilty in 2022. Doxing Scheme: The duo was part of a cybercrime group named ‘Vile’, which operated a doxing website that leaked sensitive information and extorted victims for money to have it removed, sometimes threatening them with physical harm. Criminal Methods: They accessed a law enforcement database, reportedly linked to the DEA, using stolen credentials from a law enforcement officer, significantly aiding their doxing activities. Victims and Tactics: Vile targeted victims using…

Read More

Quick Takeaways The U.S. Department of Justice seized around 145 domains and cryptocurrency linked to the BidenCash illicit marketplace, which simplified purchasing stolen credit card information and generated over $17 million in revenue since its launch in March 2022. BidenCash facilitated the trafficking of over 15 million payment card numbers and personally identifiable information, with approximately 3.3 million stolen credit cards offered for free to attract users between October 2022 and February 2023. The platform primarily targeted U.S. victims, with half of the 2.1 million compromised cards released in February 2023 belonging to American individuals or entities, while also branching…

Read More

Top Highlights Data Breach Revelation: Lee Enterprises confirmed a cyberattack earlier this year led to a data breach affecting nearly 40,000 individuals, involving personal information like names and Social Security numbers. Attack Details: The Qilin ransomware gang claimed responsibility for the incident, encrypting critical applications and stealing approximately 350 GB of files, including sensitive documents and identification scans. Response and Support: Affected individuals are being offered 12 months of free credit monitoring and identity protection services following the breach. Current Status: Lee Enterprises found no evidence of misuse of the compromised information, and the Qilin gang no longer lists Lee…

Read More

Top Highlights Legal Actions Against Taiwanese Individuals: China issued warrants for 20 Taiwanese individuals accused of conducting hacking missions in mainland China for Taiwan’s ruling Democratic Progressive Party, without disclosing specific charges. Ban on Taiwanese Company: China prohibited all commercial activities with Sicuens International Company Ltd., led by "hardcore Taiwan independence supporters" Puma Shen and his father, aligning with the Chinese government’s stance against Taiwan independence. Context of Taiwan’s Independence Movement: Shen heads the Kuma Academy, which advocates for Taiwanese self-defense and preparation against potential invasions, reflecting Taiwan’s proactive response to China’s aggressive stance. Military and Civilian Preparations in Taiwan:…

Read More

Essential Insights Cyberattack on Kettering Health: The Interlock ransomware gang recently claimed responsibility for a cyberattack on Kettering Health, disrupting operations and compromising sensitive data from over 15,000 employees and 14 medical centers in western Ohio. Data Breach Details: Interlock reportedly stole 941 GB of data, including 732,489 documents containing sensitive information such as patient data, payroll records, police files, and identity scans like passports. Operational Impact: The attack, disclosed on May 20, forced Kettering Health to revert to manual processes, cancel elective procedures, and caused significant disruptions in patient care and communication. Emerging Threat: Interlock, a newly formed ransomware…

Read More

Welcome to your Daily CyberTech Highlights! Each day, we bring you the most essential news and insightful analysis from the world of Cybersecurity, Cloud security, Data protection, Data privacy and Technology. Stay informed on the latest trends, threats, and innovations shaping the digital landscape, so you can make informed decisions and stay ahead of the curve. Let’s dive into today’s top stories! Daily CyberTech Highlights Brand Covered: Fortinet Headline: Fortinet Launches Cybersecurity Curriculum in Australia to Boost Digital Resilience in Schools Fortinet, the global cybersecurity leader driving the convergence of networking and security, announced the rollout of its Security Awareness and Training Service: Education Edition curriculum across…

Read More

In today’s cloud-first world, managing and securing sensitive data has become a priority for organizations of all sizes. Data Security Posture Management (DSPM) has emerged as the preferred solution to this growing challenge. DSPM helps enterprises gain real-time visibility into their data across multi-cloud environments, allowing them to identify and mitigate risks such as shadow data and excessive access before they lead tobreaches. DSPM has rapidly gained popularity as companies are increasingly recognizing the need to take a proactive approach to data security. Unlike traditional methods, DSPM is built for fast moving cloud and on-prem data, providing advanced data classification,…

Read More

The VAST AI Operating System, now paired with Cisco UCS and Nexus platforms, and the Hyperfabric AI solution, delivers a unified, zero-trust infrastructure blueprint to accelerate enterprise-scale intelligent systems VAST Data, the AI Operating System company, announced the expansion of its strategic partnership with Cisco to deliver a fully integrated and validated AI infrastructure stack that spans compute, networking, storage, and observability. The VAST AI Operating System is now available directly through Cisco’s Global Price List (GPL) and is fully supported by Cisco as part of the joint solution – simplifying how enterprises implement, operate, and scale modern AI environments…

Read More