Skip to main content

Topic

Perspectives

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS
Feb 21, 2024

Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.

Image of a bandage on a motherboard that represents the necessity of patch management
Feb 15, 2024

A recent survey shows significant delays in patching critical software vulnerabilities. Here’s why it happens, why security teams are sometimes encouraged to let it happen, and the policies that can reverse this (increasingly dangerous) trend.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise
Feb 14, 2024

Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram
Feb 7, 2024

DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

Closeup photo of a brown football with white laces and a blue sky beyond.
Feb 6, 2024

The wisdom and practices of legendary NFL coach Bill Belichick could be the outline for a winning cybersecurity playbook.

Closeup image of a foosball table, with plastic figures on metal rods facing off in blue and red jerseys.
Feb 1, 2024

The SEC is on a tear over cyber risk, with new rules and a SolarWinds lawsuit that have shaken the CISO community. Experts say this is just the start of regulators demanding more cybersecurity transparency. Here’s how CISOs need to adapt.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware
Jan 31, 2024

Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

A photo of the head and shoulders of a knight in silver armor with a helmet bearing thin slits over the eyes.
Jan 26, 2024

As hackers get more sophisticated and software more complex, CISOs must improve their ability to identify, isolate, and mitigate malicious software attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware
Jan 24, 2024

Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack
Jan 18, 2024

AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.

CISO Success Story: Predicting Cyber Risk (Accurately) Is Easier With This Guy’s Formula
Jan 17, 2024

Ash Hunt of Apex Group piloted a statistic-driven model for predicting cyber risk events. Here’s why playing the numbers is better than hunches.

Photo of a hand passing a wad of cash to another hand.
Jan 10, 2024

SLCGP funds might not be around for long, so entities that prepare for its next phase will have the best shot at protecting their networks and constituents.