Ransomware Gang Files SEC Complaint
November 18 2023A ransomware gang, annoyed at not being paid, filed an SEC complaint against its victim for not disclosing its security breach within the required four days.
This is over...
Read moreNew York Increases Cybersecurity Rules for Financial Companies
November 3 2023Another example of a large and influential state doing things the federal government won’t:
Boards of directors, or other senior committees, are charged with overseeing cybersecurity risk management, and...
Read more
EPA Won’t Force Water Utilities to Audit Their Cybersecurity
October 24 2023The industry pushed back:
Despite the EPA’s willingness to provide training and technical support to help states and public water system organizations implement cybersecurity surveys, the move garnered opposition...
Read more
On the Cybersecurity Jobs Shortage
September 20 2023In April, Cybersecurity Ventures reported on extreme cybersecurity job shortage:
Global cybersecurity job vacancies grew by 350 percent, from one million openings in 2013 to 3.5 million in 2021,...
Read more
Remotely Stopping Polish Trains
August 28 2023Turns out that it’s easy to broadcast radio commands that force Polish trains to stop:
…the saboteurs appear to have sent simple so-called “radio-stop” commands via radio frequency to...
Read more
White House Announces AI Cybersecurity Challenge
August 21 2023At Black Hat last week, the White House announced an AI Cyber Challenge. Gizmodo reports:
The new AI cyber challenge (which is being abbreviated “AIxCC”) will have a...
Read more
China Hacked Japan’s Military Networks
August 14 2023The NSA discovered the intrusion in 2020—we don’t know how—and alerted the Japanese. The Washington Post has the story:
The hackers had deep, persistent access and appeared to be...
Read more
Microsoft Signing Key Stolen by Chinese
August 7 2023A bunch of networks, including US Government networks, have been hacked by the Chinese. The hackers used forged authentication tokens to access user email, using a stolen...
Read moreNew SEC Rules around Cybersecurity Incident Disclosures
August 2 2023The US Securities and Exchange Commission adopted final rules around the disclosure of cybersecurity incidents. There are two basic rules:
- Public companies must “disclose any cybersecurity incident they determine... Read more
Recent Comments