サイバーセキュリティニュース: 最新のレポートがクラウドの主要な脅威をランク付け、CISA ガイドがソフトウェア製品のセキュリティ評価に役立つ
The Cloud Security Alliance has released its list of top cloud threats for 2024. Plus, CISA and the FBI published a guide for determining if a software product was built ‘secure by design.’ Meanwhile, find out how AI can transform offensive security. And get the latest on the Royal ransomware gang, ...
サイバーセキュリティニュース: 調査レポートによるとランサムウェア攻撃は減少、データ漏洩のコストは上昇している
IBM’s latest “Cost of a Data Breach Report” finds these data-theft incidents getting more expensive. Plus, the IT-ISAC says that ransomware attacks fell in Q2 due to law-enforcement disruptions of ransomware groups. Meanwhile, check out a Carnegie Mellon comp sci professor’s take on AI system securi...
サイバーセキュリティニュース: 北朝鮮のハッカーが核に関する機密情報を狙う、EU ではオンライン犯罪に AI の利用が拡大
Check out a CISA-FBI advisory about North Korean cyber espionage on critical infrastructure orgs. Plus, what Europol found about the use of AI for cybercrime. Meanwhile, the risk concerns that healthcare leaders have about generative AI. And a poll on water plant cybersecurity. And much more!...
サイバーセキュリティニュース: CISA が米国政府機関に侵入 - レポートが脆弱性を概説、クラウド セキュリティ アライアンスがクラウド セキュリティ ガイダンスを更新
CISA’s red team acted like a nation-state attacker in its assessment of a federal agency’s cybersecurity. Plus, the Cloud Security Alliance has given its cloud security guidance a major revamping. Meanwhile, a Google report puts a spotlight on insecure credentials. And the latest on open source secu...
サイバーセキュリティニュース: CISA が技術ベンダーにコマンドインジェクションの脆弱性を排除するように促す、OpenSSF が開発者にセキュリティスキルの強化を要請
Check out CISA’s call for weeding out preventable OS command injection vulnerabilities. Plus, the Linux Foundation and OpenSSF spotlight the lack of cybersecurity expertise among SW developers. Meanwhile, GenAI deployments have tech leaders worried about data privacy and data security. And get the l...
サイバーセキュリティニュース: Cobalt Strike の悪質なバージョンが削除される、Microsoft は Midnight Blizzard のメール侵害についてさらに多くの組織に通知
Check out the results of a multinational operation against illegal instances of Cobalt Strike. Plus, more organizations are learning that Midnight Blizzard accessed their email exchanges with Microsoft. Meanwhile, Carnegie Mellon has a new report about how to fix and mitigate API vulnerabilities. An...
サイバーセキュリティニュース: オープンソース ソフトウェアにメモリのバグが蔓延、自動車ディーラーのランサムウェア攻撃後の混乱が続く
Check out why memory vulnerabilities are widespread in open source projects. Plus, get the latest on the ransomware attack that’s disrupted car sales in North America. In addition, find out why a majority of organizations grew their cyber budgets this year. And learn how confidential data from U.S. ...
サイバーセキュリティニュース: 米連邦取引委員会(FTC)が TikTok に対する提訴を検討するよう米司法省に求める、フランスのサイバー機関が「Midnight Blizzard(別名Nobelium)」について警告
TikTok’s legal troubles in the U.S. could get thornier after the FTC refers complaint to the DOJ. Meanwhile, France says Russia-backed Nobelium / Midnight Blizzard is a major cyber espionage threat to European governments. Plus, check out a Tenable poll about dealing with vulnerabilities without pat...
サイバーセキュリティニュース: 英国 サイバー機関がソフトウェアベンダーに製品セキュリティの強化を要請、米国政府は金融機関の AI 利用に関する情報を求める
Check out the NCSC’s call for software vendors to make their products more secure. Plus, why the Treasury Department is looking at how financial institutions are using AI. And the latest on the cybersecurity skills gap in the U.S. And much more!...
サイバーセキュリティニュース: NIST プログラムは現実的なシナリオで AI がどのように機能するかを評価、FBI は LockBit の被害者を支援するため多数の復号化キーを保有していることを公表
Check out the new ARIA program from NIST, designed to evaluate if an AI system will be safe and fair once it’s launched. Plus, the FBI offers to help LockBit victims with thousands of decryption keys. In addition, Deloitte finds that boosting cybersecurity is key for generative AI deployment success...
サイバーセキュリティニュース: AI を安全かつ倫理的に実装するための 6 つのベストプラクティス
Like many organizations, yours is likely using AI – or at least thinking about deploying it soon. But how can you ensure you use it securely, responsibly, ethically and in compliance with regulations? Check out best practices, guidelines and tips in this special edition of the Tenable Cybersecurity ...
サイバーセキュリティニュース: EPA が上下水道処理処理施設にサイバーセキュリティの強化を要請、OpenSSF がオープンソースソフトウェア向けの脅威情報プラットフォームを開始
Check out the EPA’s call for water plants to beef up their cyber defenses. Plus, open source developers have a new platform to share threat intelligence. Moreover, business email compromise attacks prompt alert from U.K.’s cyber agency. And CISA tackles DNS encryption best practices. And much more!...