Vulnerabilities are running out of places to hide, thanks to frontier AI models, and it could create problems for those that sell software. The “vulnpocalypse,” or the onslaught of vulnerabilities surfaced through the proliferation of AI, is having far-reaching consequences… Read More "AI Will End the Era of Hidden Vulnerabilities. Are Vendors Ready?"
Top 10 Features to Look For in Vendor Risk Assessment Reports
Utilizing third-party vendors can provide numerous benefits, such as cost savings, expertise, and efficiency. Still, it also introduces a range of risks that can significantly impact an organization’s security, compliance, and overall operational integrity. Vendor Risk Assessments allow organizations to… Read More "Top 10 Features to Look For in Vendor Risk Assessment Reports"
Companies Have 6 Months to Prepare for Automated Attacks
With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses. On Sept. 2,… Read More "Companies Have 6 Months to Prepare for Automated Attacks"
Free NIST CSF Vendor Questionnaire Template (PDF Download)
This NIST CSF questionnaire template will help you understand the degree of each vendor’s alignment with the high-level function of the NIST CSF framework – Identity, Protect, Detect, Respond, and Recover. Though this assessment only offers a superficial understanding of… Read More "Free NIST CSF Vendor Questionnaire Template (PDF Download)"
ClickFix Campaigns Abuse Legitimate Services for Persistence
Two recently uncovered campaigns use ClickFix-style attacks to steal credentials and cryptocurrency as well as to go deeper into the enterprise network to maintain long-term persistence in compromised systems. The attacks, while separate, demonstrate how threat actors continue to evolve… Read More "ClickFix Campaigns Abuse Legitimate Services for Persistence"
How to Create an Effective Vendor Onboarding Policy
Forming partnerships with new vendors can be a complicated and risk-intensive process for any organization. The best way to manage the risks associated with new partnerships and establish successful vendor management practices is to create an effective vendor onboarding policy.… Read More "How to Create an Effective Vendor Onboarding Policy"
Attackers Use Multi-Hop Google Redirects for Phishing
UPDATE Attackers are chaining together multiple Google services in order to get phishing links past security gateways. Cybersecurity vendor KnowBe4 published research on Sept. 4 concerning an ongoing phishing campaign observed in the wild. To some extent, the mechanics of… Read More "Attackers Use Multi-Hop Google Redirects for Phishing"
Vendor Risk Management Assessment Matrix (Clearly Defined)
A vendor risk management assessment matrix could enhance your visibility into vendor risk exposure, helping you make more efficient risk management decisions. The matrix is one artifact in a TPRM program. In this post, explain what a vendor risk assessment… Read More "Vendor Risk Management Assessment Matrix (Clearly Defined)"
Patch Tuesday Sets Another Record With 974 CVEs
Microsoft released fixes for 974 unique vulnerabilities in its scheduled security update for September, which until recently would have represented a full year’s worth of CVEs. Of these, the highest-priority vulnerabilities include two that are already under active exploitation. Additionally,… Read More "Patch Tuesday Sets Another Record With 974 CVEs"
How to Identify Vulnerable Third-Party Software (Quickly)
Third-party software security risks are on the rise, and so are the significant cyber attacks they facilitate. According to a CrowdStrike report, 45% of surveyed organizations said they experienced at least one software supply chain attack in 2021. In 2023,… Read More "How to Identify Vulnerable Third-Party Software (Quickly)"