The battle against Log4Shell is proceeding very slowly due to a confluence of factors. It remains buried in a number of assets, particularly legacy systems that are tougher to address. But it also continues to affect organizations via new devices.
A new report from ad evaluation firm Adalytics finds that some of YouTube’s targeted ads are still slipping through the cracks, and potentially violating federal child privacy law. The revelation has prompted two US Senators to write a letter to the FTC.
A large chasm of cultural disconnect remains in the realm of security. Employee engagement is a particular problem, with less than half saying that they were very likely to report a cybersecurity incident.
Details of UK’s data protection reform plans are solidifying with the release of the first public version of the Data Protection and Digital Information Bill (DPDIB), which is accompanied with a set of new proposals for AI regulation.
Montenegro is dealing with a brutal ongoing campaign of ransomware attacks that appears to be coming from criminal groups in Russia. Government agencies in Chile have also been hit by a new form of ransomware that targets Linux servers.
Scrambling to find a way around Apple's new app tracking rules, publishers have come up with a server-to-server fingerprinting technique that is able to fly below the radar.
DevSecOps Overwhelmed by Backlogs, Significant Time and Money Being Lost to Vulnerability Management
The State of Vulnerability Management in DevSecOps" study included over 16,500 IT leaders and experts. 66% of these firms say they have a backlog of more than 100,000 vulnerabilities.
The Department of Homeland Security (DHS) has issued a bulletin to law enforcement agencies warning that Russian cyber attacks in the US are possible if Ukraine is invaded.
The CSRB found that the security breach was preventable, and that a "a corporate culture that deprioritized enterprise security investments and rigorous risk management" ended up leaving open doors for the Chinese hackers.
Ransomware is the current king of the cybersecurity threat landscape, in part because of willingness to escalate to real-world damage to infrastructure. The DHS Secretary thinks that things are poised to go a step further in that direction in the very near future.









