January 3, 2023

LockBit: Sorry about the SickKids ransomware, not sorry about the rest

Notorious ransomware gang LockBit “formally apologized” for an extortion attack against Canada’s largest children’s hospital that the criminals blamed on a now-blocked affiliate group, and said it published a free decryptor for the victim to recover the files. “The partner who attacked this hospital violated our rules, is blocked and is no longer in our …

LockBit: Sorry about the SickKids ransomware, not sorry about the rest Read More »

2023 Will See Renewed Focus on Quantum Computing

2022 has been a big year for quantum computing. Over the summer, National Institute of Standards and Technology (NIST) unveiled four quantum computing algorithms that will be eventually turned into a final quantum computing standard, and governments around the world boosted investments in quantum computing. 2023 may be the year when quantum finally steps into …

2023 Will See Renewed Focus on Quantum Computing Read More »

Review – OCS Publishes Monthly Update – December 2022

Today, CISA’s Office of Chemical Security, updated their CFATS Monthly Statistics website to provide information on the Chemical Facility Anti-Terrorism Standards (CFATS) program. The statistics reported involve activities for the Chemical Security Inspectors in support of the program during the month of September 2022 and the status of the facilities in the program at the …

Review – OCS Publishes Monthly Update – December 2022 Read More »

Important cyber security statistics you should know for 2023

Contributed by George Mack, Content Marketing Manager, Check Point Software. As we approach 2023, the threat landscape has completely transformed. Hackers have developed new types of cyber attacks and methods through which they target their victims. From increasingly sophisticated forms of ransomware to the rise of hacktivism, hackers are constantly and quickly improving their cyber …

Important cyber security statistics you should know for 2023 Read More »

Custom IT Configurations for Remote…

You need turnkey technology that just works out of the box. It needs to integrate into your existing infrastructure, workflows, and processes. Connection delivers custom integration services on your schedule through its Technology Integration and Distribution Center (TIDC), a world-class configuration and distribution facility.  The state-of-the-art integration lab covers more than 50,000 square feet, with …

Custom IT Configurations for Remote… Read More »

[tl;dr sec] #163 – Rebuilding Detection and IR at LinkedIn, CVEs and Misaligned Incentives, 2022 in Review and 2023 Predictions

Hey there, I hope you’ve been doing well! Welcome to 2023 🎉 If you’re reading this, you have successfully survived until 2023. Congratulations! I hope you enjoyed some good food and relaxing time with friends and family over the holidays. I did lots of working out with my siblings (including a blacklight boxing session), played …

[tl;dr sec] #163 – Rebuilding Detection and IR at LinkedIn, CVEs and Misaligned Incentives, 2022 in Review and 2023 Predictions Read More »

How governments can generate mainframe savings and delight users by “freeing their data”

Governments around the globe are looking for ways to balance books while also answering the call to improve citizen engagement and trust through enhanced digital service delivery. But how can they achieve both?  A proven way to quickly reduce cost and increase customer experience is to add an application speed layer between user-facing systems and …

How governments can generate mainframe savings and delight users by “freeing their data” Read More »

New Year’s Resolutions: Customers Share Challenges and Goals for 2023

As the new year begins, Darktrace customers are setting goals and making plans for upcoming IT and cyber security projects.  While Darktrace experts have already shared their predictions about the cyber security landscape in 2023, companies are also preparing for industry-specific threats.   “We are anticipating increased cyber security risks in the IoT space as 5G-enabled …

New Year’s Resolutions: Customers Share Challenges and Goals for 2023 Read More »

4 resolutions for state & local government leaders to reduce tool sprawl in 2023

Get organized. Spend less money. Learn a new skill. Work on your relationships. These are fairly common resolutions you hear this time of year, almost everywhere you turn. While they might be old news in your personal life, these goals can have far-reaching benefits when implemented by state and local government agencies. Taking a hard …

4 resolutions for state & local government leaders to reduce tool sprawl in 2023 Read More »

Bytesize security: Examining an insider exfiltrating corporate data from a Singaporean file server to Google Cloud  

According to the ‘2021 Insider Threat Report’ by Cybersecurity Insiders, the Great Resignation and shift to a remote work culture has seen organizations report a 57% increase in insider-motivated attacks [1]. Insider attacks can be difficult to detect and respond to, (especially those perpetrated by malicious individuals who have privileged access and knowledge of internal …

Bytesize security: Examining an insider exfiltrating corporate data from a Singaporean file server to Google Cloud   Read More »

Three cybercrime technology trends to watch in 2023

By Brad Liggett, Technical Director, Americas for Technology’s rapid and relentless progress promises to continue apace in 2023, to everyone’s benefit – including cybercriminals’. The year promises a “Spy vs. Spy”-type cyberspace race as both criminals and defenders vie to gain the upper hand using new and emerging technologies. Every technology that enables our cyber …

Three cybercrime technology trends to watch in 2023 Read More »

A Few Cybersecurity Stocks Soared in 2022, But Most Stumbled

Next-Generation Technologies & Secure Development Check Point, KnowBe4 Saw Gains; Other Vendors Saw Average Stock Price Drop of 40% Michael Novinson (MichaelNovinson) • January 3, 2023     After two sensational years in the public markets during the height of the COVID-19 pandemic, 2022 was a rude awakening for the cybersecurity industry. See Also: Risk-Based …

A Few Cybersecurity Stocks Soared in 2022, But Most Stumbled Read More »

Sam Bankman-Fried Pleads ‘Not Guilty’ in Criminal Case

Blockchain & Cryptocurrency , Cryptocurrency Fraud , Fraud Management & Cybercrime Trial Date Tentatively Set for Oct. 2 Rashmi Ramesh (rashmiramesh_) • January 3, 2023     Sam Bankman-Fried testifies before a Senate Committee on Feb. 9, 2022. (Image: C-SPAN) Sam Bankman-Fried pleaded not guilty to fraud and other criminal charges in a Manhattan federal …

Sam Bankman-Fried Pleads ‘Not Guilty’ in Criminal Case Read More »

Senior Healthcare Firm Pays Breach Settlement to States

Healthcare , HIPAA/HITECH , Industry Specific Avalon Health Care Pays $200,000 to Utah and Oregon, Pledges Security Enhancements Marianne Kolbasuk McGee (HealthInfoSec) • January 3, 2023     A nursing and assisted living care firm that delayed reporting a data breach to authorities paid a $200,000 fine to two state attorneys general and pledged to …

Senior Healthcare Firm Pays Breach Settlement to States Read More »

The Price Tag for Secure Systems is Way Too High

By Motti Elloul, VP Customer Success and Incident Response, Enterprise security teams are spending astonishing amounts of time and money remediating cybersecurity incidents. A. Considering the current economic climate, and with the impact of phishing and other serious cyberthreats forecast to intensify, the price for effective cyber-protection is staggeringly high. As cybersecurity threats escalate, it …

The Price Tag for Secure Systems is Way Too High Read More »

Nvidia’s AI upscaling now works on web videos

Nvidia announced that starting in February, PCs with RTX 40 series or 30 series GPUs will upscale 1080p videos to 4K in the Google Chrome and Microsoft Edge browsers. It’s unclear why it won’t work on RTX 20 series GPUs, which have DLSS functionality similar to the 30 series.Read more

What Are Cookies? A Short Guide to Managing Your Online Privacy

As much as I’d love to, we’re not here to talk about baked goods. Cookies are commonly used on websites and an essential component of the modern-day internet. However, they can pose a risk to your privacy and personal information. In today’s post we’re going to explore what cookies are, why websites use them, how …

What Are Cookies? A Short Guide to Managing Your Online Privacy Read More »

Pa. Court Says Atty Can’t Get Gun Control Donors’ Details

By Allison Grande (January 3, 2023, 10:39 PM EST) — A Pennsylvania appellate court on Tuesday blocked an attorney from accessing the names, home addresses and other personal details of those who contributed to a fund for defending the city of Harrisburg’s gun control laws, agreeing that the donors’ privacy rights outweigh the public interest …

Pa. Court Says Atty Can’t Get Gun Control Donors’ Details Read More »

Could Double Extortion Prompt a Public Health Crisis?

Originally published by CXO REvolutionaries on November 15, 2022. Written by Kyle Fiehler, Senior Transformation Analyst, Zscaler. Ransomware actors targeting Australia’s most prominent healthcare insurer have taken the gloves off. After Medibank refused to pay a ransom for the return of data belonging to 9.7 million customers this October, the hackers started to selectively leak …

Could Double Extortion Prompt a Public Health Crisis? Read More »

PII of more than 200 million Deezer users from 10 countries was hacked and published

Share this… After a hacker offered data from more than 200 million Deezer subscribers for sale on a hacking site, the music streaming service Deezer has confessed that its database was hacked by a third party. An email sent by Deezer verified the event and provided an explanation that the company is cooperating with French …

PII of more than 200 million Deezer users from 10 countries was hacked and published Read More »

Definitive Guide to Hybrid Clouds, Chapter 3: Understanding Network Visibility in the Hybrid Cloud

Originally published by Gigamon. Written by Stephen Goudreault, Gigamon. Editor’s note: This post explores Chapter 3 of the “Definitive Guide™ to Network Visibility and Analytics in the Hybrid Cloud.” Read Chapter 1 and Chapter 2, and check back for future posts covering Chapters 4–7. Migrating to the cloud can create tremendous opportunity, letting your organization …

Definitive Guide to Hybrid Clouds, Chapter 3: Understanding Network Visibility in the Hybrid Cloud Read More »

YouTuber fought back against Nintendo DMCA notice and won

Last October, video-gaming history channel DidYouKnowGaming (DYKG) posted a 20-minute documentary on a formerly unknown and unpublished Nintendo DS game, Heroes of Hyrule. As the name connotes, it was a Zelda spinoff planned for Nintendo’s popular portable. The video remained on YouTube for nearly 90 days before DYKG received a…Read more

New technique of hacking Android Pin & iPhone Passcode exploits phone sensor data

Share this… According to a research conducted by NTU, hackers are able to guess the PIN on your phone by exploiting its sensor data. Hackers may be able to unlock a smart phone by guessing the security PIN using data obtained from the many physical sensors included inside the device. According to researchers from Nanyang …

New technique of hacking Android Pin & iPhone Passcode exploits phone sensor data Read More »

ASW #224 – Keith Hoodlet

Paul’s Security Weekly Tue, 03 Jan 2023 22:00:00 +0000 Tue, 03 Jan 2023 22:10:34 +0000 Libsyn WebEngine 2.0 http://securityweekly.com/ en http://securityweekly.com/ sw_production@cyberriskalliance.com (sw_production@cyberriskalliance.com) https://ssl-static.libsyn.com/p/assets/2/3/1/7/231716b9da792464/PSW_1400x1400.png Paul’s Security Weekly Security Weekly hacking,security false sw_production@cyberriskalliance.com 01:16:36 false podcast full Read more

More than 200 U.S. institutions hit with ransomware in 2022: report

More than 200 local governments, schools and hospitals in the U.S. were affected by ransomware in 2022, according to research conducted by cybersecurity firm Emsisoft. The annual “State of Ransomware in the US” report found that 105 local governments; 44 universities and colleges; 45 school districts; and 25 healthcare providers operating 290 hospitals dealt with …

More than 200 U.S. institutions hit with ransomware in 2022: report Read More »

Google Cybersecurity Action Team Threat Horizons Report #5 Is Out!

This is my completely informal, uncertified, unreviewed and otherwise completely unofficial blog inspired by my reading of our fifth Threat Horizons Report (full version) that we just released (the official blog for #1 report, my unofficial blogs for #2, #3 and #4). My favorite quotes from the report follow below: “Identity and trust relationships in and between …

Google Cybersecurity Action Team Threat Horizons Report #5 Is Out! Read More »