BankInfoSecurity.com
Cyber Defenders Save the Country of Berylia - Once Again!
5 months ago
CISO Joe Carson on How NATO's Locked Shields Sharpens Defenders for the Next Attack
Each year, the tiny northern Atlantic Ocean island country of Berylia comes under a massive cyberattack. It's all part of one of the world's largest red team-blue team exercises called Locked Shields, which has attracted thousands of cyber professionals including Joe Carson, advisory CISO, Segura.
Each year, the tiny northern Atlantic Ocean island country of Berylia comes under a massive cyberattack. It's all part of one of the world's largest red team-blue team exercises called Locked Shields, which has attracted thousands of cyber professionals including Joe Carson, advisory CISO, Segura.
Secure Code Development News to Celebrate
5 months ago
Fewer Applications Carry OWASP Top 10 Flaws
Here's secure code development news to celebrate. After five years of steady improvement, slightly more than half of software applications don't have an OWASP Top 10 security flaw, find researchers Chris Wysopal and Jason Healey. "That makes life harder for attackers," Wysopal said.
Here's secure code development news to celebrate. After five years of steady improvement, slightly more than half of software applications don't have an OWASP Top 10 security flaw, find researchers Chris Wysopal and Jason Healey. "That makes life harder for attackers," Wysopal said.
GOP Targets State AI Regulation and Export Restrictions
5 months ago
US House Republicans Back Decade Pause of State AI Statutes
Republicans in the executive and legislative branches made moves Tuesday to loosen regulations on artificial intelligence by championing a decade-long ban on state AI regulation and undoing a rule that would have limited exports of advanced chip and model weights.
Republicans in the executive and legislative branches made moves Tuesday to loosen regulations on artificial intelligence by championing a decade-long ban on state AI regulation and undoing a rule that would have limited exports of advanced chip and model weights.
Turkish Group Hacks Zero-Day Flaw to Spy on Kurdish Forces
5 months ago
Microsoft Researchers Link Turkish Spy Group to Output Messenger Zero-Day Hack
A Turkish-linked cyberespionage group known as Marbled Dust exploited a zero-day in the Output Messenger Server Manager application to spy on Kurdish military operations in Iraq. Microsoft reported the hack and called for immediate mitigation to block credential theft and malware delivery.
A Turkish-linked cyberespionage group known as Marbled Dust exploited a zero-day in the Output Messenger Server Manager application to spy on Kurdish military operations in Iraq. Microsoft reported the hack and called for immediate mitigation to block credential theft and malware delivery.
Kosovar Man in Tampa Jail for Running Online Illicit Bazaar
5 months ago
Prosecutors Say Liridon Masurica Ran BlackDB.cc
A Kosovar man is being held in a Tampa jail after being extradited on charges that he was the main administrator of an online illicit marketplace in operation since 2018. Prosecutors accused Liridon Masurica, 33, of being the force behind BlackDB.cc.
A Kosovar man is being held in a Tampa jail after being extradited on charges that he was the main administrator of an online illicit marketplace in operation since 2018. Prosecutors accused Liridon Masurica, 33, of being the force behind BlackDB.cc.
Cyberhaven Taps Product Chief Nishant Doshi as Interim CEO
5 months ago
CEO Howard Ting's Resignation Comes as Data Protection Company Hits $1B Valuation
Cyberhaven appointed product chief Nishant Doshi as interim CEO as longtime leader Howard Ting transitions to the board. With a sevenfold valuation increase and deep investment in Gen AI security and DSPM, the company is preparing to unify data controls across enterprises.
Cyberhaven appointed product chief Nishant Doshi as interim CEO as longtime leader Howard Ting transitions to the board. With a sevenfold valuation increase and deep investment in Gen AI security and DSPM, the company is preparing to unify data controls across enterprises.
CISA Planned to Kill .Gov Alerts, Then It Reversed Course
5 months ago
CISA Said Its Cyber Alerts Were Moving to X on Monday. By Tuesday, the Plan Changed.
The U.S. cyber defense agency reversed plans to move cybersecurity alerts off its .gov site Tuesday and acknowledged the "confusion" the decision caused within the cybersecurity community, amid concerns that relying on platforms like X would reduce visibility and public access to critical warnings.
The U.S. cyber defense agency reversed plans to move cybersecurity alerts off its .gov site Tuesday and acknowledged the "confusion" the decision caused within the cybersecurity community, amid concerns that relying on platforms like X would reduce visibility and public access to critical warnings.
Keyfactor Bolsters Quantum Readiness With Dual Acquisitions
5 months ago
Real-Time, Deep Cryptographic Discovery Added to Certificate Automation Portfolio
Keyfactor is acquiring CipherInsights and InfoSec Global in a move designed to shift cryptographic security earlier in the lifecycle. The acquisitions offer real-time and deep discovery capabilities to help customers identify and remediate cryptographic weaknesses ahead of quantum disruption.
Keyfactor is acquiring CipherInsights and InfoSec Global in a move designed to shift cryptographic security earlier in the lifecycle. The acquisitions offer real-time and deep discovery capabilities to help customers identify and remediate cryptographic weaknesses ahead of quantum disruption.
Infostealer Targets Users Via Fake AI Video Sites
5 months ago
Noodlophile Steals Credentials and Wallets Under AI Video Guise
Hackers are targeting users into downloading infostealers by tricking them into clicking on links that claim to produce AI-generated videos. The attackers build websites and promoted them on high-visibility Facebook groups, some exceeding 60,000 views.
Hackers are targeting users into downloading infostealers by tricking them into clicking on links that claim to produce AI-generated videos. The attackers build websites and promoted them on high-visibility Facebook groups, some exceeding 60,000 views.
BianLian Claims Credit for Two Health Data Hacks
5 months ago
Alabama Ophthalmology Practice, California Dental Clinic Report Breaches
Cybercriminal gang BianLian claims to have stolen patient information in two recent hacks of an Alabama-based ophthalmology practice and a California dental clinic. The two incidents affected nearly 150,000 people and are among the extortion group's latest attacks on the healthcare sector.
Cybercriminal gang BianLian claims to have stolen patient information in two recent hacks of an Alabama-based ophthalmology practice and a California dental clinic. The two incidents affected nearly 150,000 people and are among the extortion group's latest attacks on the healthcare sector.
How AI Can Revamp Behavioral Biometrics Security
5 months ago
Machine Learning, Generative AI Bolster Continuous User Authentication
Financial institutions can use AI-fueled behavioral biometrics for real-time identity assurance. By continuously profiling how users interact with devices, firms can shift from one-time authentication to real-time identity assurance, turning every click, pause and keystroke into a frontline defense.
Financial institutions can use AI-fueled behavioral biometrics for real-time identity assurance. By continuously profiling how users interact with devices, firms can shift from one-time authentication to real-time identity assurance, turning every click, pause and keystroke into a frontline defense.
Why GSA's OneGov Strategy May Face Implementation Hurdles
5 months ago
Analysts Warn White House IT Plan Could Conflict With Deregulation Directives
Experts warn a new strategy that aims to centralize federal IT procurement under the General Services Administration with standardized terms and deep vendor discounts may actually undermine deregulation goals while excluding small vendors and clashing with agency-specific cybersecurity mandates.
Experts warn a new strategy that aims to centralize federal IT procurement under the General Services Administration with standardized terms and deep vendor discounts may actually undermine deregulation goals while excluding small vendors and clashing with agency-specific cybersecurity mandates.
Live Masterclass | Enterprise Data Sanitization & Disposition: What 2,000 Global Leaders Reveal About 2025 Trends
5 months ago
Google Reaches $1.4 Billion Privacy Settlement With Texas
5 months ago
State Accused Tech Giant of Geolocation, Incognito Search, Biometric Violations
Texas has reached a nearly $1.4 billion settlement agreement with technology giant Alphabet after accusing its Google subsidiary of violating state privacy laws via its geolocation, incognito search and biometric data capture and retention practices.
Texas has reached a nearly $1.4 billion settlement agreement with technology giant Alphabet after accusing its Google subsidiary of violating state privacy laws via its geolocation, incognito search and biometric data capture and retention practices.
Russian FSB Hackers Deploy New Lostkeys Malware
5 months ago
Malware Targets Western Officials, NGOs and Journalists
Russian cyber espionage hackers are using a new malware strain dubbed "Lostkeys" in a targeted espionage campaign aimed at Western officials, NGOs and journalists. Google researchers attribute Lostkeys to the threat group Coldriver, an operational unit within the Federal Security Service.
Russian cyber espionage hackers are using a new malware strain dubbed "Lostkeys" in a targeted espionage campaign aimed at Western officials, NGOs and journalists. Google researchers attribute Lostkeys to the threat group Coldriver, an operational unit within the Federal Security Service.
New KnowBe4 CEO Bryan Palma Combats Human Risk Via AI Agents
5 months ago
Strategic Plan Includes Human Risk Management Platform Expansion, IPO Preparation
Bryan Palma outlines his vision to grow KnowBe4 beyond security awareness training by investing in agentic AI, expanding email and behavioral tools and positioning the company for IPO readiness. He highlights Vista Equity's support and platform depth as key assets.
Bryan Palma outlines his vision to grow KnowBe4 beyond security awareness training by investing in agentic AI, expanding email and behavioral tools and positioning the company for IPO readiness. He highlights Vista Equity's support and platform depth as key assets.
ISMG Editors: CISA Cuts and US Cyber Plan Raise Alarms
5 months ago
Also: Cyber IPOs and the Investment Climate, the Urgency of AI Explainability
In this week's update, ISMG editors unpacked Trump's teased "grand cyber plan" amid budget cuts to the Cybersecurity and Infrastructure Security Agency, key business takeaways from RSAC Conference 2025 and why explainability in artificial intelligence is becoming critical to trust and security.
In this week's update, ISMG editors unpacked Trump's teased "grand cyber plan" amid budget cuts to the Cybersecurity and Infrastructure Security Agency, key business takeaways from RSAC Conference 2025 and why explainability in artificial intelligence is becoming critical to trust and security.
CyberUK 2025: Resilience and APT Threats Loom Large
5 months ago
Government Officials Sound 'Wake Up' Alarms
A rash of cyber incidents felt by British businesses add up to a wake-up call that cybersecurity is an absolute priority, top government officials warned during an annual conference hosted by the National Cyber Security Centre. The NCSC unveiled cyber resilience measures timed for the conference.
A rash of cyber incidents felt by British businesses add up to a wake-up call that cybersecurity is an absolute priority, top government officials warned during an annual conference hosted by the National Cyber Security Centre. The NCSC unveiled cyber resilience measures timed for the conference.
AWS Pushes AI-Powered Threat Detection With Key Partners
5 months ago
Partners Use Bedrock, SageMaker for Threat Detection, Response, Vital to Innovation
AWS is enabling cybersecurity firms to enhance detection, triage and response capabilities by embedding generative AI into services like Bedrock and SageMaker, while reinforcing its position as a partner-centric cloud security leader, said Managing Director Rohan Karmarkar.
AWS is enabling cybersecurity firms to enhance detection, triage and response capabilities by embedding generative AI into services like Bedrock and SageMaker, while reinforcing its position as a partner-centric cloud security leader, said Managing Director Rohan Karmarkar.
Checked
5 hours 23 minutes ago
BankInfoSecurity.com RSS News Feeds on bank information security news, regulations, blogs and education
BankInfoSecurity.com feed