Content Paint

cybersecurity

The Big Interview: JPMorgan’s Global CISO, Pat Opet

"Industry has gotten good at identifying vulnerabilities in the supply chain; SBOMs and so on [but not at] at insidious backdoors and logic issues that are built into software, and update mechanisms that could cause implants..."

New report sheds light on “Scattered Spider”’s ability to take over identity providers

The group "register their own MFA tokens [and] add a federated identity provider to the victim’s SSO tenant and activate automatic account linking..."

1 Citrix bug alone triggered 13 “nationally significant” UK cybersecurity incidents

You filthy animals are **** at network architecture, and it may be "necessary to expand threat hunting" says NCSC.

Public Kubernetes API server numbers pass one million, as attackers start to consider K8s a "central target"

"Once an attacker is past the initial access, the opportunities are ample for lateral movement and privilege escalation within a cluster..."

“Security is a full contact sport”: Aerospace firm Sierra Nevada Corporation CSO Robert Daugherty

"We operate with the assumption that a sophisticated nation state threat actor is always active inside the organisation"

IT support software from SysAid being exploited in the wild

Clear IOCs, guidance and documentation: A commendable response from SysAid.

World’s Biggest Bank hacked: ICBC may have failed to patch "Citrix Bleed" vulnerability

Courier dispatched with a USB stick carrying trade settlement details after systems disrupted...

ChatGPT DDoS attack

Incident follows record HTTP2 "Rapid Reset" attack warnings as well as CISA note on exploitation of Service Location Protocol vulnerability for DDoS purposes.

Why firewalls, VPNs and hypervisors are a hacker's new favourite target

TTPs and telemetry suggest a real focus on zero days and appliances by Chinese APTs.

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.