Unit 42 recently reported that it has identified “Jumpy Pisces, a North Korean state-sponsored threat group associated with the Reconnaissance General Bureau of the Korean People’s Army, as a key player in a recent ransomware incident.” Its investigation indicates “with moderate confidence that Jumpy Pisces, or a faction of the group, is now collaborating with
cybersecurity
Microsoft Report Highlights Attacks Against Healthcare Organizations
On October 22, 2024, Microsoft issued a threat trend research report entitled “US Healthcare at risk: Strengthening resilience against ransomware attacks.” In it, Microsoft declares that ransomware attacks against the healthcare sector are “emerging as one of the most significant” cybersecurity threats to healthcare organizations. The attack surface of hospitals “grows more complex” with digital…
Four Companies Settle Allegations of Deceptive Cyber Disclosures with SEC
- Unisys, $4 million
- Avaya, $1 million
- Check Point, $995,000
- Mimecast, $990,000
NYDFS Issues Industry Letter on Risks Arising from Artificial Intelligence
On October 16, 2024, the New York Department of Financial Services (DFS) issued an Industry Letter to regulated entities entitled “Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks.”
The letter “is intended to be a tool to assist Covered Entities in understanding and assessing cybersecurity risks associated with the use of…
Three More States Sue TikTok Alleging Harm to Young Users
Following in the footsteps of Nebraska, the Attorneys General of North Carolina, California, and New Jersey filed complaints against TikTok and its owner, ByteDance, Ltd., on October 8, 2024.
The suits are lengthy and full of allegations against TikTok and how it is responsible for a “profound mental health crisis” of American teenagers. The…
T-Mobile’s $31.5 Million Data Protection and Cybersecurity Settlement with the FCC
- Remediate security flaws;
- Improve the company’s cyber hygiene;
Russian Military Cyber Actors Targeting Critical Infrastructure Sector
The Cybersecurity and Infrastructure Security Agency (CISA), along with the Federal Bureau of Investigation (FBI), the National Security Agency, and other international partners, issued an Alert on September 5, 2024, warning that cyber actors affiliated with the Russian military are targeting critical infrastructure, government services, financial services, transportation systems, energy, and healthcare sectors of NATO…
Privacy Tip #413 – NIST Releases Recommendation for Consumer Routers
The National Institute of Standards and Technology (NIST) has issued helpful recommendations for consumers to consider when securing home routers.
The publication, issued on September 10, 2024, emphasizes how important it is to secure the router in your home, particularly with the expansion of the smart home, Internet of Things devices, and remote work.
According…
Department of Defense’s Proposed Amendment to DFARS for Inclusion of Cybersecurity Maturity Model Certification in Contracts
Last week, the U.S. Department of Defense (DoD) released a proposed amendment to the Defense Acquisition Regulations Supplement (DFARS) that would require a Cybersecurity Maturity Model Certification (CMMC) program to become a required part of the DoD’s contracting process. The CMMC program is a DoD program that helps businesses meet security requirements for their work…
Now Is the Time to Schedule a Tabletop Exercise on AI
We have previously suggested that conducting cybersecurity tabletop exercises are an important part of testing your incident response program and response to different scenarios.
A scenario that we strongly recommend including in your next scenario toolbox is one that focuses on the use of AI in your organization. If you have not yet developed and…