Topic
Perspectives

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS
Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.

The Essential Guide to Slow Patching: The Reasons, the Risks, the Remedies
A recent survey shows significant delays in patching critical software vulnerabilities. Here’s why it happens, why security teams are sometimes encouraged to let it happen, and the policies that can reverse this (increasingly dangerous) trend.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise
Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram
DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

What Football Coach Bill Belichick Can Teach Us About Cybersecurity
The wisdom and practices of legendary NFL coach Bill Belichick could be the outline for a winning cybersecurity playbook.

As SEC SolarWinds Case Plays Out, CISOs Shift Into Defensive Mode
The SEC is on a tear over cyber risk, with new rules and a SolarWinds lawsuit that have shaken the CISO community. Experts say this is just the start of regulators demanding more cybersecurity transparency. Here’s how CISOs need to adapt.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware
Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

7 Ways to Defend Your Software Supply Chain
As hackers get more sophisticated and software more complex, CISOs must improve their ability to identify, isolate, and mitigate malicious software attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware
Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack
AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.

CISO Success Story: Predicting Cyber Risk (Accurately) Is Easier With This Guy’s Formula
Ash Hunt of Apex Group piloted a statistic-driven model for predicting cyber risk events. Here’s why playing the numbers is better than hunches.

The SLCGP Is Another Year Older. Here’s What You Need to Know About Federal Cyber Grants
SLCGP funds might not be around for long, so entities that prepare for its next phase will have the best shot at protecting their networks and constituents.