Ransomware continues to expand with double-extortion now the standard; the malware-as-a-service model is now common; and criminals are increasingly ‘living off the land’, according to data from Red Canary.
A Sheep in Wolf’s Clothing: Technology Alone is a Security Facade
The power of the technology to defend our IT systems is only as good as our ability to evolve it in the face of ever-changing adversary tradecraft
Compliance Startup Trustero Emerges From Stealth With $8 Million in Funding
Trustero, a Palo Alto, California-based startup offering Compliance-as-a-Service (CaaS) for enterprises, has emerged from stealth mode with $8 million in seed funding.
The investment round was led by Zetta Venture Partners, with participation from Engineering Capital and Vertex Ventures.
Chinese Cyberspies Seen Using macOS Variant of ‘Gimmick’ Malware
In late 2021, incident response and threat intelligence firm Volexity observed a Chinese threat actor using a macOS variant of the malware known as Gimmick.
Analysis Shows How Fast Various Ransomware Strains Encrypt 100,000 Files
Cybersecurity researchers at Splunk have conducted an analysis to determine how long it takes various ransomware strains to encrypt files on compromised systems.
Virtual Event Today: Supply Chain Security Summit & Expo
Microsoft, Okta Confirm Data Breaches Involving Compromised Accounts
Microsoft and Okta have both confirmed suffering data breaches after a cybercrime group announced targeting them, but the companies claim impact is limited.
FBI Sees Growing Russian Hacker Interest in US Energy Firms
The FBI is warning that it has seen increased interest by Russian hackers in energy companies since the start of Russia’s war against Ukraine, though it is offering no indication that a specific cyberattack is planned.
‘Secrets Sprawl’ Haunts Software Supply Chain Security
A cybersecurity startup is warning of a major, unattended weak link in the software supply chain: the vexing problem of valuable corporate secrets — API keys, usernames and passwords, and security certificates — publicly exposed in corporate repositories.
‘Serpent’ Backdoor Used in Malware Attacks on French Entities
French organizations in the construction, government, and real estate sectors have been targeted with a new backdoor in a string of malware attacks, according to a warning from Proofpoint.













