Network SecurityFCA urges firms to boost operational resilience post-CrowdStrike disruptionDan RaywoodNovember 4, 2024According to the UK's FCA, third-party related issues were the leading cause of operational incidents reported between 2022 and 2023.
Network SecurityMore safety, trust and friction needed to overcome 2024’s challengesDan RaywoodOctober 16, 2024Lessons learned from CrowdStrike, Snowflake incidents, and Microsoft report.
Governance, Risk and ComplianceMarriott faces $52 million FTC fine and reprimand over data breachesDan RaywoodOctober 15, 2024Hotel giant instructed to develop comprehensive information security program and certify compliance as part of reprimand.
Vulnerability ManagementVulnerable instances of Log4j still being used nearly 3 years laterDan RaywoodOctober 14, 2024Critical vulnerabilities take over 500 days to be fixed.
RansomwareParis Olympics deals with ransomware attackDan RaywoodAugust 9, 2024Attack hit a computer system which handles data for 40 museums.
Critical Infrastructure SecurityCrowdStrike confirms faulty update is tied to massive global IT outage: ‘Fix has been deployed’Dan RaywoodJuly 19, 2024Transport, broadcasters, and financial systems reportedly affected by Microsoft outage.
RansomwareVictims of cyber extortion and ransomware increase in 2024Dan RaywoodJuly 8, 2024Ransomware victims can be hit multiple times by affiliate gangs in "re-victimization."
AI/MLGenAI an enhancement for cyberattackers and defendersDan RaywoodJune 13, 2024Perception Point official says the “highest bar is full automation of the attack process.”
RansomwareSecurity industry has ransomware-as-a-service model wrong, says expertDan RaywoodJune 6, 2024BitDefender research demonstrates RaaS model of operators and affiliates.
API securityTen years of Heartbleed: Lessons learnedDan RaywoodApril 29, 2024A look back at the Heartbleed bug and measuring its’ legacy, impact and how some view one of cybersecurity’s biggest headaches as an important learning moment.