Topic
Perspectives

Why Organizations Should Be Tracking IT Risk by Business Unit
Read how Organizational Risk Scoring with Benchmark can help you measure, report on, and remediate issues.

CVE-2024-3094: XZ Utils Backdoor Threatens Linux Systems
A look at the recently discovered backdoor hiding in the open source XZ Utils compression service.

How to Prepare for the EU’s AI Act: Start With Your Risk Level
The new EU AI Act, adopted in March, helps firms invest in responsible AI by noting which uses are prohibited, high-risk, or minimal to no risk.

CTI Roundup: Tycoon Phishing-as-a-Service and TheMoon Malware Update
Researchers discover a new version of the Tycoon 2FA AiTM kit, a phishing attack disguises keylogger as bank payment notice, and TheMoon malware targets ASUS routers.

CTI Roundup: Fake Google Sites Pages, Hackers Target Global Governments
Hackers spread malware through fake Google Sites pages, cybercriminals exploit APIs, and an APT campaign targets global government entities.

As Feds Warn of Hacking Wave on Water Systems, Here’s Our Roundup of Cybersecurity Resources
Attacks on water systems by Iran-backed hackers and future threats from Chinese groups have prompted calls for better security. We offer tips and resources.

As Congress Debates TikTok Ban, Here Are 3 Ways Enterprise Leaders Can Prep for New Regs
The U.S. House just passed a bill to (possibly) ban TikTok. As the Senate weighs in, here’s how business owners, boards, and other enterprise heads must respond.

CTI Roundup: Linux Servers Target of New Malware Campaign
New Linux malware campaign targets misconfigured servers, ransomware actors diversify their exfiltration tools, and Cado reveals its top cloud threat findings report for 2H23.

A Cyber Seat at the Oscars: Hollywood’s Best (and Worst) Films About Hackers and Cybersecurity
We salute a handful of standouts from the silver screen – some we love, and some we love to hate – that illuminated hackers and their world in new, powerful, or cringey ways.

CTI Roundup: CVEs on the Rise, TimbreStealer Malware, and a New Phishing Report
Researchers predict a 25% rise in CVEs, TimbreStealer malware spreads through phishing, and Proofpoint releases its 2024 State of the Phish report.

Racing to Deploy GenAI? Security Starts With Good Governance
GenAI adoption is moving fast, so enterprises must set good governance policies first. Here's what you need to know to keep your deployments secure.

Shadow IT Is ‘Out of Control.’ Here’s How to Manage the Risk
It’s easier than ever for employees to find their own quick IT solutions—which can exponentially expand an organization’s risk landscape. We highlight four critical steps to help ferret out shadow IT – and its newest iteration, “shadow AI” – to limit the threat.