Skip to main content

Topic

Perspectives

Image of a bandage on a motherboard that represents the necessity of patch management

A recent survey shows significant delays in patching critical software vulnerabilities. Here’s why it happens, why security teams are sometimes encouraged to let it happen, and the policies that can reverse this (increasingly dangerous) trend.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise

Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram

DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

Closeup photo of a brown football with white laces and a blue sky beyond.

The wisdom and practices of legendary NFL coach Bill Belichick could be the outline for a winning cybersecurity playbook.

Closeup image of a foosball table, with plastic figures on metal rods facing off in blue and red jerseys.

The SEC is on a tear over cyber risk, with new rules and a SolarWinds lawsuit that have shaken the CISO community. Experts say this is just the start of regulators demanding more cybersecurity transparency. Here’s how CISOs need to adapt.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware

Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

A photo of the head and shoulders of a knight in silver armor with a helmet bearing thin slits over the eyes.

As hackers get more sophisticated and software more complex, CISOs must improve their ability to identify, isolate, and mitigate malicious software attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware

Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack

AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.

CISO Success Story: Predicting Cyber Risk (Accurately) Is Easier With This Guy’s Formula

Ash Hunt of Apex Group piloted a statistic-driven model for predicting cyber risk events. Here’s why playing the numbers is better than hunches.

Photo of a hand passing a wad of cash to another hand.

SLCGP funds might not be around for long, so entities that prepare for its next phase will have the best shot at protecting their networks and constituents.

CTI Roundup: Remcos RAT Phishing Attacks, New Meduza Stealer Found on Dark Web

CISA adds two bugs to the KEV catalog, UAC-0050 distributes Remcos RAT with phishing tactics, and an updated version of Meduza Stealer launches on the dark web.