TL;DRMulti-factor authentication blocks 99.9% of automated account takeover attacks, according to Microsoft Azure AD data.Phishing simulation click rates fall 50-65% after 6-12 months of repeated feedback loops, per pooled SANS...
TL;DRRansomware operators most often gain initial access by exploiting publicly known, unpatched vulnerabilities in internet-facing Microsoft systems such as Exchange, Remote Desktop Services, or VPN appliances.The WannaCry outbreak in May...
Entering 2020, cybersecurity experts expected ransomware to remain the dominant threat, cloud misconfigurations to widen the attack surface, and the November election to face state-sponsored interference. What they did not...
On 1 October 2018 the Financial Conduct Authority fined Tesco Bank £16.4 million for failures that allowed a cyber attack in November 2016. Over 48 hours, attackers stole £2.26 million...
2018 was the year data privacy moved from a compliance footnote to a boardroom liability. Eight major incidents exposed the personal information of more than two billion people across social...
A flaw in DJI's cloud systems let unauthorized parties pull personal data and flight records from drone operators. The weakness laid bare flight logs, telemetry data, camera metadata, and user...
On May 7, 2021, Colonial Pipeline discovered a ransomware attack on its IT systems and proactively shut down its 5,500-mile fuel pipeline from Texas to New Jersey. The company paid...
In 2023, Stina Ehrensvärd stepped down as CEO of Yubico, the hardware authentication firm she co-founded in 2007, and handed the reins to a Silicon Valley veteran with enterprise software...
Tony Scott served as the third Chief Information Officer of the United States, appointed by President Barack Obama from February 2015 to January 2017. His term closed with the change...
Microsoft joined the steering committee of the Coalition for Content Provenance and Authenticity (C2PA) in early 2021, adding its weight to a technical effort to certify the origin and editing...
Between 2013 and 2015, a Lithuanian fraudster named Evaldas Rimasauskas persuaded employees at Google and Facebook to wire more than $100 million into his bank accounts. He impersonated Quanta Computer,...