Security News

The challenges healthcare CISOs face in an evolving threat landscape
2021-08-10 06:30

Organizations in the healthcare sector - and especially those engaged in delivering healthcare services - have always been juicy targets for cyber attackers. While in the past they were mostly after patients' personal, health and financial data these organizations store to be able to provide services, the advent of ransomware has dramatically changed the threat landscape they must face.

Behind the scenes: A day in the life of a cybersecurity "threat hunter"
2021-08-09 12:00

Here's how one security operations analyst, an expert at incident reporting, began her career, collaborates with her colleagues and prioritizes incoming threats. Cha attended the National University of Singapore and studied computer science with a focus in cybersecurity, where she learned "The theory behind all of the things we take for granted." She first got a security job in a consulting firm, where she worked in identity and access management, then she worked at a bank, as a security operations center analyst before landing her current job, as a "Threat hunter" at ExpressVPN. SEE: Security incident response policy.

Why ransomware is such a threat to critical infrastructure
2021-08-09 05:30

A recent spike in large-scale ransomware attacks has highlighted the vulnerabilities in the nation's critical infrastructure and the ease with which their systems can be breached. Cyberattacks and ransomware pose a greater risk to critical infrastructure than a non-digital external threat like a nation-state does, and the size and scale of the infrastructure has little to do with the scope of the risk; ransomware is just as much as threat to a water treatment plant in downtown Smallville, USA, as it is to a large-scale energy grid or gasoline pipeline.

The Week in Ransomware - August 6th 2021 - Insider threat edition
2021-08-06 21:16

Yesterday, after being banned from the Conti ransomware operation, a Conti affiliate leaked the training material for the ransomware operation on the XSS hacking forum, giving security researchers and defenders an inside look at the tools being used by the group. A new ransomware gang named BlackMatter is purchasing access to corporate networks while claiming to include the best features from the notorious and now-defunct REvil and DarkSide operations.

The Week in Ransomware - August 6th 2021 - Insider threats
2021-08-06 21:16

Yesterday, after being banned from the Conti ransomware operation, a Conti affiliate leaked the training material for the ransomware operation on the XSS hacking forum, giving security researchers and defenders an inside look at the tools being used by the group. A new ransomware gang named BlackMatter is purchasing access to corporate networks while claiming to include the best features from the notorious and now-defunct REvil and DarkSide operations.

Threat Detection Provider ReversingLabs Raises $56 Million
2021-08-06 17:44

Threat detection startup ReversingLabs has raised $56 million in a Series B funding round. The new funding round was led by private equity firm Crosspoint Capital Partners.

Cybercriminals are manipulating reality to reshape the modern threat landscape
2021-08-05 04:30

VMware released a report which analyzes how cybercriminals are manipulating reality to reshape the modern threat landscape. "Today, we're seeing a nexus between nation-states and cybercriminals continue to rapidly advance the development of increasingly sophisticated and destructive cyberattacks, combined with the broadening of the attack surface as a result of COVID-19," says Tom Kellermann, head of cybersecurity strategy, VMware.

Elastic Limitless XDR prevents threats at cloud scale on a single platform
2021-08-05 02:15

Part of Elastic Security, Elastic Limitless XDR modernizes security operations by unifying the capabilities of security information and event management, security analytics, and endpoint security. Elastic Limitless XDR is anchored in SIEM and enriched by a single agent for endpoint security to eliminate data silos, reduce alert fatigue, and arm practitioners to stop threats at cloud scale.

NetWitness Ransomware Defense Cloud Services combats threat actors in IT environments
2021-08-05 02:00

NetWitness, an RSA business, unveiled NetWitness Ransomware Defense Cloud Services, a managed cloud service that monitors endpoints without traditional deployment and administration requirements. Ransomware Defense Cloud Services also includes detection intelligence developed from in-depth ransomware research and development, combined with experienced threat hunting in enterprise environments.

Cyware and RiskIQ provide threat intelligence necessary to stay ahead of attackers
2021-08-03 23:50

Cyware announced a partnership with RiskIQ. The partnership combines advanced global threat intelligence automation with enriched, high-fidelity threat intelligence data to enable customers to...