This appears to be the first time that the SEC has sent a Wells Notice to a CISO. While novel, this Wells Notice furthers the SEC’s recent enforcement and rulemaking focus on meaningful and timely cybersecurity-related disclosures, as well as holding individual liable for their roles in company violations.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Documents leaked to Vice's Motherboard magazine indicate that, between 2018 and 2020, Google fired at least 80 employees for data misuse. At least a few involve employees accessing user accounts and manipulating or deleting the data of other employees.
The Mailchimp security breach appears to have lasted for less than a full day. The company says that client login information was not compromised, but customer support tools were used to send phishing emails.
The announcement has raised questions in some circles as to what the extent of the cyber task force's plans are. "Hacking back" is a very contentious concept that exists in a murky international water of cyber engagement norms and unspoken rules.
Trend Micro finds the Chinese APT group has compromised at least 70 government organizations over the last two years, in 23 different countries. But the group's logs indicate it has targeted over 110 organizations in 10 additional nations.
A stronger IoT security posture is critical with a recent Kaspersky report showing a nine-time increase of attacks on IoT devices in the first half of 2019 compared to the first half of 2018.
There are two pieces of legislation already in front of Congress that would set reporting requirements for ransomware payments, each proposing different time windows for different industries and company sizes. A third now seeks a 48-hour limit.
The now-public whistleblower allegations that Twitter may have active foreign spies on its payroll are sure to raise concerns about insider threats at companies everywhere. But focusing only on potential spies is a mistake.
Just a few simple strings on malware are all it takes to defeat Cylance antivirus software. This is a crushing blow for those who predicted AI and machine learning are the future of antivirus protection.
A new vulnerability chain discovered by Oasis Security can compromise the Claude AI chatbot and does not require the target to have the app installed or even have an account with the service. The attack chain instead begins with a malicious webpage doctored up to place highly in search results for Claude, which passes the user to a pre-filled chat URL that exploits other vulnerabilities in the AI agent.










