Posts

US-CERT - CISA Adds Single-Factor Authentication to list of Bad Practices

from CISA All NCAS Products https://us-cert.cisa.gov/ncas/current-activity/2021/08/30/cisa-adds-single-factor-authentication-list-bad-practices

Rapid 7 - [The Lost Bots] Episode 4: Deception Technology

Image
Welcome back to The Lost Bots, a vlog series where Rapid7 Detection and Response Practice Advisor Jeffrey Gardner talks all things security with fellow industry experts. This episode is a little different, as it’s Jeffrey talking one-on-one with you about one of his favorite subjects: deception technology! Watch below to learn about the history, special characteristics, goals, and possible roadblocks (with counterpoints!) of what he likes to call “HoneyThings,” and also learn practical advice about the application of this amazing technology. Stay tuned for future episodes of The Lost Bots! Coming soon: Jeffrey tackles insider threats — where the threat is definitely inside your organization, but maybe not in the way you think. from Rapid7 Blog https://blog.rapid7.com/2021/08/30/the-lost-bots-episode-4-deception-technology/

KnowBe4 - [FREE Resource Kit] Cybersecurity Awareness Month 2021 Now Available

Image
Cybersecurity Awareness Month is right around the corner, but we’ve got you covered! from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/free-resource-kit-cybersecurity-awareness-month-2021-now-available

Schneier - Excellent Write-up of the SolarWinds Security Breach

Robert Chesney wrote up the Solar Winds story as a case study, and it’s a really good summary. from Schneier on Security https://www.schneier.com/blog/archives/2021/08/excellent-write-up-of-the-solarwinds-security-breach.html

Threat Post - T-Mobile’s Security Is ‘Awful,’ Says Purported Thief

John Binns, claiming to be behind the massive T-Mobile theft of >50m customer records, dissed the security measures of the US's No. 2 wireless biggest carrier. T-Mobile is "humbled," it said, announcing new partnerships with security heavyweights on Friday. from Threatpost https://threatpost.com/t-mobile-security-awful-thief/169011/

US-CERT - Microsoft Azure Cosmos DB Guidance

from CISA All NCAS Products https://us-cert.cisa.gov/ncas/current-activity/2021/08/27/microsoft-azure-cosmos-db-guidance

Schneier - Friday Squid Blogging: Tentacle Doorknob

It’s pretty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Read my blog posting guidelines here . from Schneier on Security https://www.schneier.com/blog/archives/2021/08/friday-squid-blogging-tentacle-doorknob.html