You are here

Cybersecurity

Report – 2024 Unit 42 Incident Response Report: Navigating the Shift in Cybersecurity Threat Tactics

Unit 42 published its 2024 Incident Response Report yesterday which includes incident data from over 250 organizations and more than 600 incidents. The report provides a unique perspective into the latest threat tactics being used by attackers and provides helpful resources and methods for effective defense. 

Cofense Annual Report – Malicious Emails Bypassing Secure Email Gateways - Critical Insights into the Evolving Email Security Landscape

Cofense, a leading cybersecurity firm in email security, recently released its 2024 Annual State of Email Security Report. The report reveals emerging trends in the email threat landscape, such as an increase in various phishing tactics. Most notable, the report indicates a significant (37%) increase in malicious emails that are bypassing secure email gateways (SEGs) over last year, and an overwhelming 310% increase since 2021.

Passthrough – EPA Office of Inspector General Issues BEC Fraud Alert

The U.S. EPA OIG issued a fraud alert (attached) to highlight the all-too-common and costly form of phishing known as business email compromise (BEC). In this convincing scam, criminals are using fraudulent emails that appear to come from known and trusted sources to access company email accounts and target organizations that make or receive financial transactions. These emails may originate from lookalike, or spoofed, email accounts or legitimate email accounts compromised through phishing campaigns.

Passthrough – CISA Cybersecurity Emotions

CISA recently shared its “Cybersecurity Emotions” series detailing social engineering tactics that threat actors often use when implementing various tactics against organizations and internet facing users. Organizations can add CISA’s “Cybersecurity Emotions” to security awareness training as each of the “emotions” are effectively described and explained giving relatable real-world understanding of these tactics and helping users learn the basics of “cyber hygiene.”

ICS/OT Cyber Resilience – Dragos’ 2023 OT Cybersecurity Year in Review: Insights on New Activity Groups, Industrial Ransomware, and ICS/OT Vulnerabilities

Dragos published its 2023 OT Cybersecurity Year in Review today. In its seventh iteration, this comprehensive report contains the latest threat intelligence on adversary activity targeting OT environments, industrial risk of ransomware, the state of OT vulnerabilities, and more. Dragos shares predominate insights, poignant lessons learned, and proactive recommendations in this annual data-driven analysis of ICS/OT focused cyber threats and vulnerabilities.

Ransomware Awareness – LockBit Ransomware Disrupted Following International Takedown Operation

In a joint operation known as “Operation Cronos,” international law enforcement partners collaborated in efforts to disrupt the notorious ransomware group known as LockBit. The U.S. Department of Justice Office of Public Affairs has issued a press release announcing the disruption of the gang along with indictment charges against two Russian nationals. 

A banner on LockBit’s data leak website reads:

Pages

Subscribe to Cybersecurity