Skip to main content

Tag: cyber security

4316 articles

AI Cybersecurity Threats: Must-Have Best Practices

AI Cybersecurity Threats: Must-Have Best Practices

AI can be both defender and threat—and NIST’s NCCoE is leading virtual sessions to shape the Cyber AI Profile, offering practical guidance to spot AI-enabled risks and harden defenses. Whether you’re a technologist, policymaker, or business leader, this essential guide shows how to harness AI safely and stay ahead of evolving cyber threats.

Analyst 207
DevSecOps: Must-Have Best Practices for Ultimate Security

DevSecOps: Must-Have Best Practices for Ultimate Security

Join NIST NCCoE’s virtual event on August 27, 2025 to learn practical DevSecOps best practices from leading experts and discover how to weave security into every step of your software lifecycle. With cybercrime costs soaring, this is your chance to balance speed and safety through automation, compliance tips, and real-world lessons that make your software more resilient.

Analyst 207
Secure Software Development: Must-Have Best Practices

Secure Software Development: Must-Have Best Practices

Worried about the security of the software we all depend on? Join NIST NCCoE’s interactive DevSecOps virtual event on August 27, 2025, to hear experts, learn practical secure development practices, and help turn security from an afterthought into a foundation for every project.

Analyst 207
AI Cyber Defense: Must-Have Strategies for Best Security

AI Cyber Defense: Must-Have Strategies for Best Security

Join NIST NCCoE’s virtual working sessions to explore how the Cyber AI Profile can harness AI to sharpen threat detection, cut alert fatigue, and strengthen defenses—while tackling the ethical and security risks that come with it. Technologists, policymakers, and practitioners are invited to collaborate and shape trustworthy, practical AI-driven cybersecurity solutions.

Analyst 207
TETRA Radio Encryption Flaws: Shocking Risk to Police

TETRA Radio Encryption Flaws: Shocking Risk to Police

Researchers have uncovered critical flaws in TETRA’s end-to-end encryption—dubbed 2TETRA:2BURST—that could let attackers eavesdrop on or manipulate emergency radio traffic, putting officers and the public at risk. It’s a wake-up call for law enforcement and policymakers to urgently patch systems and rethink how we secure critical communications.

Analyst 207
AI in Cybersecurity: Stunning Must-Have Defense

AI in Cybersecurity: Stunning Must-Have Defense

In a rapidly evolving digital landscape, the battle between AI-driven attacks and defenses is more intense than ever. Join us as we unpack the insights from the recent Black Hat conference, where experts discussed how AI can transform from a weapon for cybercriminals to a vital shield for defenders—reminding us that in cybersecurity, staying one step ahead is crucial!

Analyst 207
Connex Credit Union breach: Shocking Risky Wake-Up

Connex Credit Union breach: Shocking Risky Wake-Up

A recent cyber-attack at Connex Credit Union exposed the personal data of 172,000 members, leaving many understandably worried about identity theft and financial safety. While Connex notifies affected members and steps up security, now’s a good time to review your accounts and enable extra protections like monitoring and multi-factor authentication.

Analyst 207
WinRAR vulnerability: Stunning RomCom Risk Exposed

WinRAR vulnerability: Stunning RomCom Risk Exposed

A newly discovered zero-day in WinRAR (CVE-2025-8088) is being weaponized by the RomCom hacking crew, turning a tool used by millions into a malware delivery system. If you use WinRAR, update and patch now—this is a wake-up call about how convenience can become a major security risk.

Analyst 207
deepfake detectors: Must-Have Best Defense Against Fakes

deepfake detectors: Must-Have Best Defense Against Fakes

Deepfakes are evolving fast—threatening trust, fraud, and reputations—but new detection tools are racing to expose these digital impostors. Learn how experts at DEF CON and beyond are arming everyday users with the tools and know-how to spot and stop dangerous fakes.

Analyst 207
Cybersecurity threats: Critical Stunning Wake-Up Call

Cybersecurity threats: Critical Stunning Wake-Up Call

This week’s cybersecurity roundup spotlights three urgent threats—BadCam camera exploits, a critical WinRAR vulnerability, and attackers targeting EDR systems—reminding businesses and users to patch, reassess defenses, and stay vigilant.

Analyst 207
Cybersecurity vulnerabilities: Critical Stunning Threats

Cybersecurity vulnerabilities: Critical Stunning Threats

This week’s cybersecurity roundup spotlights BadCam’s webcam surveillance, critical WinRAR bugs, and a rising wave of ransomware — a clear reminder that no system is safe until it’s patched. Stay ahead by updating software, tightening defenses, and treating vigilance as your best protection.

Analyst 207
Romance fraud scheme: Stunning $100M Risky Scam

Romance fraud scheme: Stunning $100M Risky Scam

When online romance turns into a $100 million criminal scheme, four Ghana-based suspects have been extradited to the U.S., spotlighting how emotional manipulation fuels sprawling scams and why stronger international cooperation is urgently needed.

Analyst 207
Ghanaian romance fraud: Shocking Devastating $100M Scam

Ghanaian romance fraud: Shocking Devastating $100M Scam

Imagine thinking you’ve found love—only to learn it’s a $100M scam; the indictment of four Ghanaian nationals exposes how online romance can be weaponized, devastating lives and forcing urgent action on cross‑border fraud and digital trust.

Analyst 207
Business-Critical Assets: Must-Have Best Protection

Business-Critical Assets: Must-Have Best Protection

Protecting the assets that keep your business running isn’t just an IT task—it’s a strategic must; learn six practical, proven lessons to spot, prioritize, and defend the systems and data that power your revenue and operations. From risk-based prioritization and continuous monitoring to building a security-aware culture and testing response plans, these steps help you stay resilient as threats evolve.

Analyst 207
Click & Collect Must-Have Comeback Brings Relief

Click & Collect Must-Have Comeback Brings Relief

Good news — M&S has restored Click & Collect so shoppers can get back to the quick, convenient pickups they rely on; some online services remain down, but the retailer is working on fixes and stronger security.

Analyst 207
Click & Collect Service: Must-Have, Restored but Risky

Click & Collect Service: Must-Have, Restored but Risky

M&S has reopened Click & Collect, so customers can get back to the convenient, cost-savvy shopping they love. But with some services still lagging after the cyber attack, rebuilding trust and boosting security is now essential.

Analyst 207
Embargo ransomware Shocking $34.2M Haul Exposed

Embargo ransomware Shocking $34.2M Haul Exposed

TRM Labs revealed the Embargo ransomware gang has siphoned $34.2 million from victims—a stark reminder that our connected world can be exploited for huge profit. It’s time businesses, regulators, and users to boost defenses and work together to stop these crypto-enabled crimes.

Analyst 207
NIS2 Directive compliance: Stunning Risky Failures

NIS2 Directive compliance: Stunning Risky Failures

Eight EU countries risk penalties and increased vulnerability after missing the NIS2 transposition deadline—it’s a wake-up call to shore up cyber defenses before trust in essential services is eroded.

Analyst 207
AI in Cybersecurity: Risky Hype or Must-Have Tool?

AI in Cybersecurity: Risky Hype or Must-Have Tool?

UK red teamers warn that AI isn’t a magic bullet for cybersecurity — it’s a powerful tool that still needs human insight, training and oversight to stop real-world threats.

Analyst 207
WinRAR zero-day exploit: Must-Have Critical Fix

WinRAR zero-day exploit: Must-Have Critical Fix

A critical WinRAR zero-day (CVE-2025-8088, CVSS 8.8) is being actively exploited to run code via crafted archives—update your Windows WinRAR now to protect your files and avoid a costly breach.

Analyst 207
Trend Micro vulnerability: Risky, Stunning Security Failure

Trend Micro vulnerability: Risky, Stunning Security Failure

Trend Micro’s Apex One management console has a critical, actively exploited vulnerability with no patch available, leaving organizations exposed and customer trust at risk. It’s a wake-up call for greater transparency, faster fixes, and heightened vigilance from both vendors and users.

Analyst 207
Win-DDoS vulnerabilities: Stunning Critical Threat

Win-DDoS vulnerabilities: Stunning Critical Threat

Researchers at DEF CON 33 revealed Win-DDoS, a worrying new technique that could turn thousands of public domain controllers into a massive DDoS botnet—putting everything from online banking to emergency services at risk. Stay vigilant: patch systems, monitor networks, and train staff now to prevent trusted infrastructure from being weaponized.

Analyst 207
Windows EPM Poisoning: Stunning Risky Exploit Alert

Windows EPM Poisoning: Stunning Risky Exploit Alert

A newly patched Windows RPC flaw (CVE-2025-49760) exposes a storage-spoofing vector that could let attackers escalate privileges across a domain—so applying Microsoft’s update and reviewing your defenses should be top of the to-do list. Stay proactive: patch promptly, educate your teams, and verify your security controls to keep impersonation attacks at bay.

Analyst 207
Water security hackers: Must-Have Best Defense

Water security hackers: Must-Have Best Defense

As cyberattacks on water systems rise, ethical hackers are stepping in with successful pilot programs across four states to help utilities find and fix vulnerabilities—offering a hopeful, if carefully overseen, path to safer community water supplies.

Analyst 207