<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/enterprise-security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Enterprise-security ]]></title>
                <link>https://www.itpro.com/tag/enterprise-security</link>
        <description><![CDATA[ All the latest enterprise-security content from the ITPro team ]]></description>
                                    <lastBuildDate>Wed, 09 Jul 2025 11:25:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ ‘The worst thing an employee could do’: Workers are covering up cyber attacks for fear of reprisal – here’s why that’s a huge problem ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-worst-thing-an-employee-could-do-workers-are-covering-up-cyber-attacks-for-fear-of-reprisal-heres-why-thats-a-huge-problem</link>
                                                                            <description>
                            <![CDATA[ More than one-third of office workers say they wouldn’t tell their cybersecurity team if they thought they had been the victim of a cyber attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XfWBssdeBNQVQm6ujgeevG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8eHSiVD9ymBMhfQqJ3VxPg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Jul 2025 11:25:00 +0000</pubDate>                                                                                                                                <updated>Wed, 09 Jul 2025 11:28:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8eHSiVD9ymBMhfQqJ3VxPg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female office worker in an open plan workspace looking concerned while working on laptop.]]></media:description>                                                            <media:text><![CDATA[Female office worker in an open plan workspace looking concerned while working on laptop.]]></media:text>
                                <media:title type="plain"><![CDATA[Female office worker in an open plan workspace looking concerned while working on laptop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8eHSiVD9ymBMhfQqJ3VxPg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK businesses face a huge hidden cyber risk that’s driving security practitioners mad: employees keeping quiet about cyber attacks.</p><p>More than one-third of office workers (39%) said they wouldn’t tell their cybersecurity team if they thought they had been the victim of a <a href="https://www.itpro.com/security/cyber-attacks">cyber attack</a> – and it's not for a lack of <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training">security awareness</a>. </p><p>A survey of 4,500 workers across EMEA by data security and management firm <a href="https://www.itpro.com/cloud/cloud-security/cohesity-expands-partnership-with-google-cloud-to-drive-generative-ai-data-insights">Cohesity </a>found that British employees are more aware of cyber threats, such as <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>, than their counterparts in France and Germany. </p><div class="product"><a data-dimension112="1d052117-97f3-4499-a977-60e003f73a17" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="1d052117-97f3-4499-a977-60e003f73a17" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="1d052117-97f3-4499-a977-60e003f73a17" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Almost half (43%) of UK employees know exactly what ransomware is, compared with just 28% of workers in France and 30% in Germany. Four-in-five (79%) said they were confident that they could identify a malicious cyber attack.</p><p>“Staying silent if they suspect a malicious cyber attack is quite possibly the worst thing an employee could do, particularly when they claim to know the dangers,” said Olivier Savornin GVP Europe at Cohesity. </p><p>"This reluctance to speak up leaves organizations in the dark and vulnerable to serious damage to the business."</p><p>So why are employees keeping quiet? According to the survey, 17% wouldn’t want people to think it was their fault, with the same number worried they'd get into trouble. One-in-eight said they were afraid of causing an unnecessary fuss.</p><p>This desire to hush things up is so serious that 11% said they would even try to fix the problem themselves, rather than seek official help from the company experts. </p><h2 id="drop-the-blame-game-improve-culture">Drop the blame game, improve culture</h2><p>Savornin noted that the research shows a big cultural change is needed to support workers and ultimately improve broader transparency in business. </p><p>“We need to create a workplace culture where people feel comfortable raising the alarm and are properly trained on how to recognize a cyber threat and the correct action to take - no matter how small the issue might seem," said Savornin. </p><p>Earlier this year, a <a href="https://www.sonicwall.com/threat-report"><u>survey</u></a> from managed services company IT.ie found that 43% of office workers believed that they were at risk of causing a cybersecurity incident in the next 12 months.</p><p>Six-in-ten of these people blamed incomplete or non-existent cybersecurity training, with 31% blaming poor communication from management regarding cyber risks. </p><p>This isn't the first time that a reluctance to report incidents has been reported. In October last year, for example, Arctic Wolf's <a href="https://www.globenewswire.com/Tracker?data=pnK0m3slEQaclML1diRyjuWtSLcymUrAqHLZHShi52rS82xRxepaHG1Rh6wLupO99agms7Gx1Qwp2VbnE8Rd4xBHNc7iN3oMEjcoATeC8eUGxcDECGxa_GZE73A1b8bs73kI0KmNEz2mCBlGGJSOEz4sAVnRzcAQWk2-uQMf9po="><u>2024 Human Risk Behavior</u></a> Snapshot report found that a quarter of workers were too scared to report security problems.</p><p>They may have good reason for this fear, however, with a report from security firm Egress last year <a href="https://www.itpro.com/security/four-in-ten-employees-sacked-over-email-security-breaches-as-firms-tackle-truly-staggering-increase-in-attacks"><u>finding</u></a> that just over half of employees caught out by phishing attacks were disciplined as a result. </p><p>Notably, four-in-ten were fired following an incident, and this only exacerbates long-term issues with reporting. </p><p>In some cases, staff have even been told not to disclose a breach. A 2023 survey from Bitdefender showed a cover-up culture had emerged at many enterprises. </p><p>The poll of 400 IT and security professionals found that nearly half of cybersecurity practitioners were <a href="https://www.itpro.com/security/370411/nearly-half-of-security-practitioners-told-to-keep-data-breaches-under-wraps">told to keep data breaches under wraps</a> by senior management figures. </p><p>Meanwhile, three-in-ten said they actively avoided disclosing a breach themselves despite specific processes being in place.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-protection/almost-a-third-of-workers-are-covertly-using-ai-at-work-heres-what-thats-a-terrible-idea">Almost a third of workers are covertly using AI at work</a></li><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/why-remote-work-is-still-giving-cisos-security-headaches">Remote work is still causing security headaches for CISOs</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shifting left might improve software security, but developers are becoming overwhelmed – communication barriers, tool sprawl, and ‘vulnerability overload’ are causing serious headaches for development teams ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/software-security-shift-left-developer-overload</link>
                                                                            <description>
                            <![CDATA[ Developers are becoming overwhelmed amid the 'shift left' in development practices, new research shows. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EUT7wUMzfHPvc2bN2ePQqR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7YH4hNrEoL7oEoygVyJuZi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 29 May 2025 11:50:45 +0000</pubDate>                                                                                                                                <updated>Thu, 29 May 2025 14:38:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7YH4hNrEoL7oEoygVyJuZi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software security concept image showing female developer working on a desktop computer with screen reflected in glasses.]]></media:description>                                                            <media:text><![CDATA[Software security concept image showing female developer working on a desktop computer with screen reflected in glasses.]]></media:text>
                                <media:title type="plain"><![CDATA[Software security concept image showing female developer working on a desktop computer with screen reflected in glasses.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7YH4hNrEoL7oEoygVyJuZi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nearly half of enterprises are trying to "shift left" in a bid to shore up software security, but developers are reporting significant issues with the strategy. </p><p>False positives, the faster pace of development thanks to AI, and challenges integrating tools are hampering progress.</p><p>That's according to<a href="https://www.pynt.io/resources-hub/guides-and-reports/shift-left-adoption-benchmark-report-2025"><u> research by AI security firm Pynt</u></a> that focused on the adoption of shift left  practices — referring to a strategy of spotting flaws and security issues earlier in the software development cycle when they're easier to fix.</p><p>The survey of 250 security professionals found 47% of organizations had implemented a shift left approach to software development, with a further 27% working to do so. </p><p>But a quarter of developers felt overwhelmed by the volume of vulnerabilities, and more than a third saw false positives as the main challenge to implementing a successful shift-left strategy, followed by integration issues and vulnerability overload. </p><p>The study raises serious questions over whether this approach to software development is actually reducing overall risks, or merely increasing complexity, according to Pynt chief executive Tzvika Shneider.</p><p>"Everyone talks about shifting left, but few are seeing the security gains they expected," said Shneider. "Most organizations have tools in place, but they still struggle with noise, process friction, and developer resistance."</p><p>"<a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>accelerates how software is developed and shipped, forcing security to keep pace, Shneider added.</p><p>The research also found that the vast majority of companies that had shifted left had turned to <a href="https://www.itpro.com/software/amazons-codewhisperer-updates-could-be-a-game-changer-for-shifting-left"><u>software tools to help the process</u></a>, but 31% said that integrating those tools within development workflows continued to be a major barrier. </p><p>The most popular tools are Static Application Security Testing (SAST), Software Composition Analysis (SCA) and Dynamic Application Security Testing (DAST), with each used by about a third of respondents. </p><h2 id="software-security-priorities-are-causing-friction">Software security priorities are causing friction</h2><p>Two-thirds of respondents said they prefer to fix bugs in app code rather than with rules in post-production, highlighting friction between developers and security teams. The former prioritize feature development and see security as a burden, while the latter wants to see flaws fixed rapidly.</p><p>"Shift right is easier since it doesn’t require extensive coordination between multiple teams, whereas Shift Left demands a collaborative effort across development, security, and testing teams,” the report noted.</p><p>"Shift Left was meant to improve security, but many organizations are finding that execution challenges are holding them back," added Shneider. "Security leaders must rethink their approach to reduce friction between security and development teams while maintaining effective risk management."</p><p>Pynt said that automation in security testing could help, and called for improved collaboration between security and development teams, including integrating security into testing phases. </p><p>Europeans are ahead adopting shift left practices, the survey found, with Germany and the UK both at 52%. Developer teams in the US, however, aren't quite up to scratch in this regard, researchers found, with just 42% of enterprises having adopted the approach.</p><p>The report follows earlier research that <a href="https://www.itpro.com/cloud/cloud-security/enterprise-ai-is-surging-but-is-security-keeping-up"><u>suggests enterprise security teams</u></a> are struggling to keep up with the adoption of AI tools. Similar research found showing the rise in AI coding tools may actually be slowing down development thanks to the <a href="https://www.itpro.com/software/development/devsecops-teams-are-ramping-up-the-use-of-ai-coding-tools-but-theyve-got-serious-concerns-ai-generated-code-is-causing-major-security-headaches-and-slowing-down-development-processes"><u>security headaches it causes</u></a>.  </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/anthropic-claude-opus-4-software-development">Anthropic’s new AI model could be a game changer for developers</a></li><li><a href="https://www.itpro.com/software/development/developers-will-need-to-adapt-microsoft-ceo-satya-nadella-joins-googles-sundar-pichai-in-revealing-the-scale-of-ai-generated-code-at-the-tech-giants-and-its-a-stark-warning-for-software-developers">30% of Microsoft's code is now AI-generated, and that's bad news for devs</a></li><li><a href="https://www.itpro.com/software/development/its-far-from-showing-its-age-java-mightve-just-turned-30-but-its-still-going-strong-and-here-to-stay">Java might’ve just turned 30, but it’s still going strong and here to stay</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "Thinly spread": Questions raised over UK government’s latest cyber funding scheme ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/thinly-spread-questions-raised-over-uk-governments-latest-cyber-funding-scheme</link>
                                                                            <description>
                            <![CDATA[ The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sFJaLxh7kPdjUAGtcGH4HB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jan 2025 11:50:28 +0000</pubDate>                                                                                                                                <updated>Fri, 10 Jan 2025 13:53:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of the Houses of Parliament, London, UK.]]></media:description>                                                            <media:text><![CDATA[View of the Houses of Parliament, London, UK.]]></media:text>
                                <media:title type="plain"><![CDATA[View of the Houses of Parliament, London, UK.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government plans to spend £1.9 million on cyber resilience projects across the country, the <a href="https://www.gov.uk/government/news/new-regional-skills-projects-to-bolster-uk-cyber-defences-and-deliver-on-plan-for-change"><u>Department for Science, Innovation and Technology (DSIT) has revealed</u></a>. </p><p>With planned investment in more than 30 projects, the money will help improve the UK’s cyber resilience for both businesses and consumers, and boost national <a href="https://www.itpro.com/security/strain-of-cyber-skills-deficit-still-impacting-firms-despite-global-workforce-surge">cyber skills</a>. </p><p>Some projects set to receive funding include ‘CyberSecurityAId: Empowering Small Businesses with Cyber Security Skills,’ ‘Cybersecurity Angel Investor Network,’ and ‘First Steps to a Cyber Security Career - North West.’</p><p>The funding boost comes amid growing concerns over <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">cybersecurity skills shortages</a> across the country. Almost half of UK firms report a deficit in this regard, according to the DSIT, and these projects will help fill current gaps and meet growing demand. </p><p>Under the scheme, people across the country will be able to pursue new, high-level career opportunities as a result, DSIT added. </p><p>“By <a href="https://www.itpro.com/business-strategy/training/358122/upskilling-a-remote-workforce">upskilling</a> small businesses and individuals, investing in workforce development, and encouraging neurodiverse talent, government and industry partners are fostering robust and diverse cyber communities for the future,” said Jonathan Ellison, director for national resilience and future technology at the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>. </p><p>“This is vital for protecting our digital economy, creating new opportunities for secure innovation, and helping make the UK the safest place to live and work online,” Ellison added. </p><p>The UK’s minister for cybersecurity, Feryal Clark, also commented, saying strong defenses are needed for the country’s growing digital economy, which is worth billions of pounds. </p><p>“Attempts to disrupt the technologies and services we rely on daily continue to grow, so we’re leaving no stone un-turned to make sure our communities have the skills to rise to the challenge,” Feryal said. </p><h2 id="cyber-investment-is-a-good-start-but-does-it-go-far-enough">Cyber investment is a good start, but does it go far enough?</h2><p>While the move has been welcomed by industry stakeholders, some experts have questioned the scope of the initiative. </p><p><a href="https://www.itpro.com/security/uks-first-national-security-center-to-open-in-wales">Socura</a> CEO Andy Kays said a key concern is the “size of investment relative to the scale of its ambition”, suggesting that the volume of projects set to be awarded funding could dilute the overall investment. </p><p>“30 new projects slated for 2025 and beyond across multiple regions means that this money will be thinly spread across the UK,” Kays said. </p><p>“The concern is that this money won’t go far enough to have the level of impact needed. It is, however, a good start,” he added. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QG6vhN3APSsV7GwFnj5f3o" name="Discover the six superpowers of Dell PowerEdge servers.jpg" caption="" alt="Discover the six superpowers of Dell PowerEdge servers" src="https://cdn.mos.cms.futurecdn.net/QG6vhN3APSsV7GwFnj5f3o.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell & AMD)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/discover-the-six-superpowers-of-dell-poweredge-servers"><em>Transform your data center</em></a></p></div></div><p>Kays said it was “only right” that the UK invest more money to develop its regional <a href="https://www.itpro.com/business/370195/welsh-startups-isolated-over-lack-of-diverse-funding-routes">cyber skills in places like Wales</a>, the North East of England, and Northern Ireland. </p><p>Jake Moore, global <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> advisor at ESET, welcomed the investment scheme, adding that the initiative will help strengthen the country’s overall cyber resilience and futureproof communities.  </p><p>“Upskilling workforces is crucial for safeguarding our digital economy, unlocking opportunities to secure innovation, and ensuring the UK remains protected from constant attacks,” Moore said.</p><p>“However, this isn’t the first time we have seen a shake-up in the UK’s skills shortage so it is vital that the initiative will continue to be funded and pushed to the next level where more roles are filled,” he added. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Acronis Cyber Protect Cloud review: Slick automated threat remediation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/acronis-cyber-protect-cloud-review-slick-automated-threat-remediation</link>
                                                                            <description>
                            <![CDATA[ A single cloud service that neatly combines malware protection with backup and recovery features ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">29G93GZ2JExyDaV2SCKcob</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EFdGmUBvkrVStGbbSB5xUX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Dec 2023 08:35:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EFdGmUBvkrVStGbbSB5xUX-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Acronis Cyber Protect Cloud user interface]]></media:description>                                                            <media:text><![CDATA[The Acronis Cyber Protect Cloud user interface]]></media:text>
                                <media:title type="plain"><![CDATA[The Acronis Cyber Protect Cloud user interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EFdGmUBvkrVStGbbSB5xUX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Acronis&apos; Cyber Protect Cloud (CPC) amalgamates cybersecurity, data backup, and disaster recovery into one easily managed product. Available from a choice of Acronis MSPs, it delivers a raft of protection measures, and the entire suite requires only a single host agent installed on each endpoint.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="m3oV8ZhyVSLVyjF7UJrPA9" name="m3oV8ZhyVSLVyjF7UJrPA9.jpg" caption="" alt="A close up shot of someone pressing a keyboard key on a laptop covered in blue and red lighting" src="https://cdn.mos.cms.futurecdn.net/m3oV8ZhyVSLVyjF7UJrPA9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">Best online cyber security courses for 2023</a></p></div></div><p>On the security side, you get advanced <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> protection using Acronis&apos; AI-based behavioral detection engine, web content filtering, patch management, vulnerability assessments, and device controls. We&apos;ve reviewed the Cyber Protect cloud backup service previously and have been impressed with its excellent data protection and recovery tools.</p><p>Acronis offers a range of optional packs for CPC so you can keep costs under control by adding only those you need. The advanced security pack with endpoint detection and remediation (EDR) provides event correlation, threat containment, incident investigation, kill chain analysis, and endpoint rollback recovery.</p><p>Pricing is based on workloads or the amount of cloud storage required, with the latter offering the best value. Protection for one workstation with 100GB of cloud backup storage, patch management, and the EDR pack included costs £16 per month.</p><h2 id="acronis-cyber-protect-cloud-review-deployment">Acronis Cyber Protect Cloud review: Deployment</h2><p>CPC offers an extensive range of agent deployment options, and you can do it yourself or let your MSP do it for you. Platform support includes Windows, macOS, and Linux systems, while the backup component also looks after iOS and Android mobiles, the most popular business apps including MS365 and <a href="https://www.itpro.com/software/workspace/google-workspace-review-a-simple-aesthetic-with-productivity-in-mind">Google Workspace</a>, and all the main <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">virtualization hosts</a>. </p><p>Not only does CPC use a single client agent, but all security and backup settings can be managed within the same protection profile. These are assigned to agent groups and include all backup requirements, enabling EDR, real-time malware scanning and agent self-protection, scheduling vulnerability assessments and patch management tasks, applying web filtering using up to 44 URL categories, and enforcing removable device controls.</p><p>Monitoring plans are a new feature and let you keep a close eye on key endpoint hardware metrics including <a href="https://www.itpro.com/hardware/components/cpu-architectures-whats-the-difference-between-arm-and-x86-and-why-does-it-matter">CPU</a> and memory usage, <a href="https://www.itpro.com/hardware/367907/how-to-check-if-your-cpu-is-running-cool-enough">CPU/GPU temperatures</a>, network activity, disk space and transfer rates, and warnings if the client&apos;s anti-malware services are disabled. Remote support services can be controlled with management plans that enable NEAR and RDP technician connections to selected client groups, allow file transfer, and use H.264 hardware encoding.</p><p>There&apos;s a lot going on inside CPC and the web portal dashboard presents a clear overview of your security posture and protection status. It uses a multitude of table, graph, and chart widgets that can be personalized by deleting some, adding others, and dragging them around the console.</p><p>Incoming alerts are viewed from the portal&apos;s monitoring page or the Protection section, which provides more detail with lists of all incidents filtered by severity and mitigation status. Selecting an incident takes you to an investigation page, which provides a kill chain diagram, details of how the attack developed, and what processes it interacted with.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2039px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LzB2SuoSfgx8AqBL46EtaE" name="Acronis_Cyber_Protect_Cloud_copy.jpg" alt="The Acronis Cyber Protect Cloud dashboard" src="https://cdn.mos.cms.futurecdn.net/LzB2SuoSfgx8AqBL46EtaE.jpg" mos="" align="middle" fullscreen="" width="2039" height="1147" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>For unmitigated incidents, you can open an investigation, apply response actions such as adding a malicious URL to a block list, and provide notes on support activities. Entire incidents comprising multiple threats can be remediated by CPC using quarantine actions and rollback of Registry and file changes using the client&apos;s local agent cache or backup image.</p><p>Businesses concerned about the cost and complexity of separate cybersecurity and data backup solutions will love Acronis Cyber Protect Cloud. It&apos;s only available from <a href="https://www.itpro.com/business-operations/managed-service-provider-msp/359139/bcdr-buyers-guide-for-msps">MSPs</a>, but deployment is simple, everything is accessible from one cloud portal and the EDR pack provides slick automated threat remediation and recovery services.</p><p><em>This content originally appeared on ITPro&apos;s sibling magazine PC Pro. For more information and to subscribe, please visit PC Pro&apos;s </em><a href="https://subscribe.pcpro.co.uk/"><em>subscription site</em></a><em>. </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GDPR fines just 6% of the total cost of data breaches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/gdpr-fines-just-6-of-the-total-cost-of-data-breaches</link>
                                                                            <description>
                            <![CDATA[ Costs are surging as tickbox compliance distracts organizations from proper security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TtC5ZycGxPejJUswNyKpb9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Aug 2023 11:44:36 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Aug 2023 11:06:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A red warning sign on a backgroud of code, denoting malware and cyber attacks]]></media:description>                                                            <media:text><![CDATA[A red warning sign on a backgroud of code, denoting malware and cyber attacks]]></media:text>
                                <media:title type="plain"><![CDATA[A red warning sign on a backgroud of code, denoting malware and cyber attacks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over a third (37%) of breaches were caused by human error, and 40% of breaches took more than 72 hours to report, research has found.</p><p>An analysis of nearly 100,000 data breaches (99,460) reported to the UK <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico"><u>Information Commissioner’s Office (ICO)</u></a> from April 2019 to December 2022 has found a lengthy gap between the breach and the report, despite the ICO taking a more robust line.</p><p>The length of the gap demonstrates the challenges faced in identifying a threat. For 18% of breaches, more than a week passed until the ICO was notified. </p><p>The costs of <a href="https://www.itpro.com/security/data-breaches/data-breach-costs-businesses-lose-73-of-their-income-in-the-year-following-an-incident"><u>breaches</u></a> can be high, dwarfing fines, with research finding the 33 most notable breaches cost organizations more than £13.5 billion, of which only 6% were made up by global regulatory fines.</p><p>In this instance, ‘notable’ refers to actual data breaches rather than organizations maliciously abusing data themselves or were reported by <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained"><u>white-hat hackers</u></a> with no damage occurring.</p><p>The most common causes of the breaches in the research weren’t cyber attacks. Only a third (33%) of breaches reported were due to malware or phishing, with all breaches caused by threats from outside an organization accounting for 35% of reports. Insider threats, however, came to 40%. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="s4zyVqVoidbXQRwdhFsaEM" name="ITIC 2022 Global Server Hardware, Server OS Security Report Image.jpg" caption="" alt="ITIC 2022 Global Server Hardware, Server OS Security Report" src="https://cdn.mos.cms.futurecdn.net/s4zyVqVoidbXQRwdhFsaEM.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><strong>ITIC 2022 Global Server Hardware, Server OS Security Report</strong></p><p class="fancy-box__body-text"><em>Learn more about how you can combat ever-growing security threats.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/servers-and-storage/itic-2022-global-server-hardware-server-os-security-report"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Human error accounted for more – 23% were caused by data being shared with the wrong person, while 11% was due to lost or stolen data. This includes, for example, stolen devices or paperwork being left in an unsecured location.</p><p>Terry Ray, SVP, data security GTM and field CTO of Imperva, noted the ICO’s tougher stance but worries organizations are prioritizing measures that demonstrated compliance on paper, over genuine data security. </p><p>“In many cases, initiatives that meet the letter of compliance will not in fact prevent organizations from suffering the financial impact of a data breach, such as from customer churn and reputational damage, which can dwarf any potential fines,” he said.</p><p>Data breaches are rising by more than a third (34%) annually, according to Ray, and he expressed concern that – due to a lack of clear metrics – businesses were unsure their data security investments are paying off.</p><p>The ICO has averaged £14.7 million per year in fines issued since it began issuing fines under GDPR rules, compared to £1.5 million levied in the 12 months before <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a> rules came into effect. This increase doesn’t compare favorably with the average cost of the 33 most notable breaches, which was approximately £410 million. “At present,” said Ray, “it would take the ICO 28 years to fine organizations the equivalent of just one of the ‘most notable’ data breaches.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Software security ‘overhauled for the better’ thanks to US legislation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/software-security-overhauled-for-the-better-thanks-to-us-legislation</link>
                                                                            <description>
                            <![CDATA[ The requirements around necessitating a software bill of materials have driven positive changes in both the US and UK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v8ednnfaoG44NPGBKrrLSn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VUDZptndWJDCBjYxYfV9u6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Aug 2023 13:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Aug 2023 10:34:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VUDZptndWJDCBjYxYfV9u6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software security depicted by an image of sprawling Python code displayed on a screen]]></media:description>                                                            <media:text><![CDATA[Software security depicted by an image of sprawling Python code displayed on a screen]]></media:text>
                                <media:title type="plain"><![CDATA[Software security depicted by an image of sprawling Python code displayed on a screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VUDZptndWJDCBjYxYfV9u6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Software development has been transformed since the introduction of the Biden administration’s executive order (EO) to improve cyber security across the US.</p><p>The <a href="https://www.itpro.com/security/cyber-security/359527/pres-biden-bolsters-of-nations-cyber-security-defenses-by-executive"><u>EO</u></a> was designed to bolster defenses against cyber attacks and was primarily focused on federal agencies and contractors. However, research has shown that it has impacted organizations in both the US and UK.</p><p>A key tenet of the order was a requirement for companies to implement a <a href="https://www.itpro.com/security/cyber-attacks/borderline-irresponsible-attitude-to-third-party-risks-must-change-says-expert"><u>software bill of materials (SBOM)</u></a> to ensure robust <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> hygiene.</p><p>More than three-quarters (76%) of enterprises surveyed in the UK and US have since adopted an SBOM, and 16% plan to in the future, Sonatype revealed in its latest research. </p><p>Only 4% reported that an SBOM had been adopted more than three years ago, indicating how rapidly things have changed.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pyFsy4LXwQC5LHt9D4U95N" name="The board's evolving perceptions of cyber risk_thumbnail.jpg" caption="" alt="Whitepaper cover with black and white image of man's face wearing glasses and with beard on the right side" src="https://cdn.mos.cms.futurecdn.net/pyFsy4LXwQC5LHt9D4U95N.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The board&apos;s evolving perceptions of cyber risk</strong></p><p class="fancy-box__body-text"><em>78 global CISOs share their recommendations on how to communicate cyber risk as business risk to their C-suite peers and the board. </em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-boards-evolving-perceptions-of-cyber-risk">DOWNLOAD FOR FREE</a></p></div></div><p>SBOMs are also becoming an essential procurement requirement, underlined by 60% of respondents reporting that they were required to complete business deals. Just over a third (37%) said they plan to add the requirement in the future.</p><p>The survey results, from 217 cyber security directors in companies with revenues of more than £50 million or $50 million in the UK and the US respectively, showed that proper <a href="https://www.itpro.com/security/370309/surge-in-compromised-credentials-highlights-rampant-cyber-hygeine-failings"><u>security hygiene</u></a> is increasingly tied to commercial opportunities as well as government work.</p><p>However, the figures also indicated nearly a quarter of respondents are yet to adopt SBOMs.</p><p>The reasons for this were varied; almost half said they needed to gain a better understanding of how to implement them or their benefits, while others noted concerns around cost, and nearly a third (32%) reported that they simply needed more staff.</p><p>Brian Fox, CTO and co-founder at Sonatype, described SBOMs as just the first step to cyber resilience and noted that more work would be needed, including investment in software composition analysis tools. </p><h2 id="what-is-a-software-bill-of-materials">What is a software bill of materials?</h2><p>An SBOM lists everything that goes into a particular application. As well as the components themselves, it also includes information such as the license version and type, such as open-source or commercial, for example.</p><p>Spreadsheets and manual files have also been used but are prone to human error and are unsuitable for larger projects that would benefit more greatly from an automated approach - potentially as part of the <a href="https://www.itpro.com/development/32887/what-is-continuous-integration"><u>CI/CD</u></a> pipeline.</p><p>While SBOMs are not a new concept, the high-profile vulnerability in the popular Java logger <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability"><u>Log4j</u></a> highlighted the importance of knowing what is in one’s software supply chain and being prepared to deal with or mitigate the potential impact of breaches.</p><p>Despite the signing of the executive order and the implementation of SBOMs by some enterprises, the Log4j vulnerability demonstrated that there remains work to do in order to ensure software supply chain security. </p><p>The US has continued to work to bolster security and published the <a href="https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf" target="_blank"><u>National Cybersecurity Strategy</u></a> in March 2023. The EU proposed its own <a href="https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act" target="_blank"><u>Cyber Resilience Act </u></a>in 2022, highlighting the importance placed on security in both regions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ubuntu shifts to four-week update cycle ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/linux/ubuntu-shifts-to-four-week-update-cycle</link>
                                                                            <description>
                            <![CDATA[ Critical fixes will also come every two weeks, mitigating the issues involved with releasing prompt patches on the old three-week cadence ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c4YQiYGN3vKZbvNdthoKtL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MerZpQ6vR99uzygjyKfjK8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Aug 2023 14:58:46 +0000</pubDate>                                                                                                                                <updated>Thu, 03 Aug 2023 12:46:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Linux]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MerZpQ6vR99uzygjyKfjK8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Red Ubuntu logo appearing on a web browser with a microscope over the logo, placing emphasis on it]]></media:description>                                                            <media:text><![CDATA[Red Ubuntu logo appearing on a web browser with a microscope over the logo, placing emphasis on it]]></media:text>
                                <media:title type="plain"><![CDATA[Red Ubuntu logo appearing on a web browser with a microscope over the logo, placing emphasis on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MerZpQ6vR99uzygjyKfjK8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Canonical Kernel Team is abandoning its update cadence in favor of a four-week cycle, and will add an additional update every two weeks for the most urgent fixes.</p><p>A move to a four-week cycle with a midpoint update will result in regular upstream stable updates, including security patches, bug fixes, and feature requests coming every four weeks. Critical fixes that can’t wait will arrive on a two-week cadence.</p><p>In the past, the <a href="https://www.itpro.com/software/open-source/ubuntu-publisher-canonical-to-assume-control-of-lxd"><u>Canonical</u></a> team worked to a three-week kernel update cycle. This, according to Kleber Souza, Linux kernel engineering manager at Canonical, made for reasonable responsiveness but was “prone to interruptions from urgent <a href="https://www.itpro.com/security/exploits/360411/top-30-most-exploited-vulnerabilities"><u>CVEs</u></a>, urgent customer requests and regressions found in -updates or during testing.”</p><p>The result was that the cycle tended to be extended, and delivering CVE fixes promptly was challenging.</p><p>Souza noted that OEM kernels would follow a more flexible schedule in terms of their deadlines for the acceptance of new patches.</p><p><a href="https://www.itpro.com/network-internet/internet-of-things-iot/368307/ubuntu-core-22-is-now-generally-available-for-iot"><u>Ubuntu</u></a> is one of the most popular <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system"><u>Linux</u></a> distributions, and the changes will interest engineers charged with maintaining fleets of hardware running the operating system - on-premises or in the cloud - in light of the pace of vulnerability discovery and patching.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="k8ftzpSTX7UAHzb6bhxVzh" name="Quantifying the public vulnerability market_listing.jpg" caption="" alt="Whitepaper cover with title over solid purple circle graphics" src="https://cdn.mos.cms.futurecdn.net/k8ftzpSTX7UAHzb6bhxVzh.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Quantifying the public vulnerability market</strong></p><p class="fancy-box__body-text"><em>Read how the reporting of vulnerabilities is contributing to greater, comprehensive security for all.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/quantifying-the-public-vulnerability-market-2022-edition"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The move was <a href="https://discourse.ubuntu.com/t/ubuntu-kernel-4-2-sru-cycle-announcement/37478/2" target="_blank"><u>described</u></a> by one user on the company’s forums as “ambitious” and comes in the wake of a relatively easy-to-exploit privilege escalation <a href="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now"><u>vulnerability</u></a> disclosed recently.</p><p>The vulnerability in the OverlayFS module used in Ubuntu was documented in <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2640" target="_blank"><u>CVE-2023-2640</u></a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32629" target="_blank"><u>CVE-2023-32629</u></a> and was exclusive to the operating system following changes made by the Canonical team in 2018.</p><p>CVE-2023-2640 permits an unprivileged user to set privileged extended attributes on mounted files. CVE-2023-32629 is a local privilege escalation vulnerability where permission checks are skipped.</p><p>Those changes only became an issue in 2020 when a security vulnerability patched in the Linux kernel did not make it into Ubuntu due to the earlier changes.</p><p>One report <a href="https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability" target="_blank"><u>stated</u></a> that the vulnerability could affect 40% of Ubuntu cloud workloads. Ubuntu fixed the vulnerabilities on 24 July 2023, and users were instructed to update their kernels.</p><p>With the revised cycle schedule, Souza said: “The Canonical Kernel Team is expecting to deliver more predictable updates with quicker turnaround for time-sensitive fixes”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber attacks in the cloud take less than ten minutes to launch ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cyber-attacks-in-the-cloud-take-less-than-ten-minutes-to-launch</link>
                                                                            <description>
                            <![CDATA[ Researchers said the time it takes to attack the cloud is “light years” quicker than traditional scenarios ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gycx5pTAutXWgMkeGxpzBN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Sb34qzHnFamveDnex64kMY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Aug 2023 14:41:26 +0000</pubDate>                                                                                                                                <updated>Thu, 03 Aug 2023 12:42:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Sb34qzHnFamveDnex64kMY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber attack: Cloud made of little cubes]]></media:description>                                                            <media:text><![CDATA[Cyber attack: Cloud made of little cubes]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber attack: Cloud made of little cubes]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Sb34qzHnFamveDnex64kMY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New research into cyber attacks in the cloud has shown that on average it takes less than ten minutes to launch an attack after first discovering credentials.</p><p>The finding concerned targeted attacks, where cyber criminals chose their targets for a specific reason, such as having a misconfiguration in their cloud environment that could be exploited.</p><p>Of the ten minutes it took from finding a working credential to launching the attack, five of them were dwell time.</p><p>When cyber criminals can enter a cloud environment and launch an attack at such pace, it becomes extremely difficult for defenders to detect the intrusion and prevent the attack from taking place.</p><p>During opportunistic attacks - those without a specific target - it took cyber criminals on average less than two minutes to find a publicly exposed credential after scanning for a <a href="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now">vulnerability</a>, like a <a href="https://www.itpro.com/cloud/cloud-security/report-google-cloud-platform-is-the-most-commonly-misconfigured-big-three-cloud-platform"><u>misconfiguration</u></a>. It then took an average of 21 minutes for them to initiate an attack.</p><p>Researchers at Sysdig attributed the speed of attacks to the weaponization of automation, warning that attackers are focusing on <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity and access management (IAM) </a>with evolving techniques for credential access, privilege escalation, and lateral movement.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TUHb3DrtXpm3KwkkJUCCS6" name="Choosing_right_technology to strengthen cloud security_listing.jpg" caption="" alt="A whitepaper from ServiceNow covering how to lay a strategic foundation for cloud security that protects what matters to your business" src="https://cdn.mos.cms.futurecdn.net/TUHb3DrtXpm3KwkkJUCCS6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Choosing the right technology to strengthen cloud security and risk management</strong></p><p class="fancy-box__body-text"><em>Learn how to lay the strategic foundation for cloud security.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/choosing-the-right-technology-to-strengthen-cloud-security-and-risk-management"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>While the time from credential discovery to starting an attack was measured in minutes, the team noted that attackers could need hours to identify a suitable target - depending on motive and visibility.</p><p>Getting hold of a secret was highly dependent on the storage location. For example, with <a href="https://www.itpro.com/cloud/amazon-s3/367664/what-is-amazon-s3">AWS S3</a> buckets, an attacker might have to spend several days searching for a specific public name.</p><p>The increasing emphasis on ‘everything as code’ in the cloud environment has contributed to the difficulties defenders face. The report noted: “A syntax error while writing code for appropriate access and privileges could be the only thing standing between you and front‑page news”.</p><p><a href="https://www.itpro.com/server-storage/31782/what-is-serverless-architecture">Serverless</a> function code and infrastructure-as-code (IaC) software such as CloudFormation and Terraform were said to be of particular interest to attackers since the files can contain credentials or secrets but might be overlooked by security scans.</p><h2 id="what-is-in-your-supply-chain">What is in your supply chain?</h2><p>Researchers also considered the state of containers. The nature of the technology - essentially a package to deliver an application with everything required built-in - can make them an ideal delivery mechanism for malicious code. </p><p>After analyzing 13,000 <a href="https://www.itpro.com/development/containers/354652/getting-started-with-docker">Docker</a> hub images, researchers found 819 were malicious. However, 10% of those were undetectable, thanks to advanced techniques to hide malicious code. Only at runtime could the threat be detected.</p><p>Performing a static scan of the contents of a container will only go so far and is not enough to assure safety.</p><p>Researchers cited an example of a threat actor that created 11 accounts, all hosting 30 of the same container images. The image itself looked benign but launched a disguised cryptominer when it was run.</p><p>A runtime threat detection tool is therefore required, as well as static image analysis and vulnerability scanning. </p><h2 id="what-are-the-targets-and-what-are-the-goals">What are the targets and what are the goals?</h2><p>Nearly two-thirds (65%) of cloud attacks target the telecommunications and finance sectors specifically. </p><p>The researchers didn’t comment on why these sectors were targeted so often, but they are among the most valuable in the world, both holding highly sensitive information.</p><p>For the telecommunication sector, as well as harvesting personal information, data collected can potentially be used for <a href="https://www.itpro.com/security/hacking/358575/eight-brits-arrested-over-hacking-celeb-mobile-phones">SIM swapping</a> - effectively taking over a victim’s mobile device and permitting authentication through <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a> into other important accounts. </p><p>After the telecommunications and finance sectors, healthcare and defense trailed at 5% and 1%, respectively. The finding surprised researchers, considering the type of data that could be stolen.</p><p>Other goals include resource hijacking, where an attacker will seek to quickly monetize an asset by spinning up <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptomining</a> instances and leveraging existing instances to launch new attacks.</p><h2 id="mitigation-and-trends">Mitigation and trends</h2><p>Defending against and mitigating attacks requires a multi-pronged approach, researchers said. </p><p>For example, vendors such as AWS will scan <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> for any AWS credentials and attach a quarantine policy to limit potential damage. According to the report, GitHub is also examing commits for several secret formats and can reject them automatically.</p><p>However, it is essential to recognize the determination of a user to bypass protections put in for their safety.</p><p>As the cloud continues to move toward everything-as-code and container technologies, complexity will continue to increase, and attackers will take advantage of any mistakes made. </p><p>The report cited the rapid development of new cloud services giving new opportunities to attackers despite continual improvements in security by vendors. Although attack timelines are unlikely to reduce from the pace observed, the attacks themselves will continue to evolve with automation becoming more prevalent.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Report: Google Cloud Platform is the most commonly misconfigured big-three cloud platform ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/report-google-cloud-platform-is-the-most-commonly-misconfigured-big-three-cloud-platform</link>
                                                                            <description>
                            <![CDATA[ Little separated GCP and Azure, but AWS fared markedly better according to the latest figures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K7nfUKoA59FteJfxbi5tCX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eGBuw7HPn9vDjv5Gf2jZwg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Aug 2023 13:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Aug 2023 13:15:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eGBuw7HPn9vDjv5Gf2jZwg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Google Cloud Platform logo displayed on their stand during the Mobile World Congress 2023]]></media:description>                                                            <media:text><![CDATA[The Google Cloud Platform logo displayed on their stand during the Mobile World Congress 2023]]></media:text>
                                <media:title type="plain"><![CDATA[The Google Cloud Platform logo displayed on their stand during the Mobile World Congress 2023]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eGBuw7HPn9vDjv5Gf2jZwg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Research has shown that controls within Google Cloud Platform (GCP) are the most commonly misconfigured of the big three cloud service provider (CSP) environments, making them more vulnerable to cyber attackers.</p><p>Researchers at Qualys looked at cloud misconfiguration issues and found <a href="https://www.itpro.com/cloud/cloud-storage/368014/what-is-google-cloud-storage"><u>GCP</u></a> leading the way with an average failure rate of 60% when run against the Center for Internet Security’s (CIS) benchmarks. <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws"><u>Azure</u></a> was close behind, with an average failure rate of 57%, and <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362608/what-is-aws"><u>AWS</u></a> stood at 34%.</p><p>GCP services of particular concern, according to the CIS benchmarks, were BigQuery, DataProc, and Logging.</p><p>The CIS Benchmarks comprise more than 100 secure configuration guidelines for more than 25 product families. The intent is to provide recommendations for hardening technology against cyber attacks.</p><p>While the platforms themselves are not inherently insecure, the figures highlight the issue of misconfiguration, which amplifies the risk of breaches and unauthorized access. </p><p>Misconfigurations can be caused by anything from a simple lack of expertise and human error to rapid deployment, where security considerations drop down the list of priorities compared to a business need.</p><p><a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>Encryption</u></a>, identity management, and external-facing assets were noted as some of the most impactful misconfigurations that are commonly made, potentially leading to exploits and cyber attack.</p><p>Encryption is hugely important for protecting an organization’s data. However, despite most Cloud Service Providers (CSP) making its implementation as simple as selecting a configuration option, the report found that it was not universally deployed.</p><p>Nearly all (99%) of the Azure disks scanned lacked encryption or a customer managed key (CMK). On GCP, researchers found 97.5% of virtual machine disks for critical VMs lacked encryption using customer-supplied encryption keys (CSEKs).</p><p>As with encryption, <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>identity and access management (IAM)</u></a> was poorly implemented by customers of all three CSPs. </p><p>Among the most significant IAM misconfigurations were console passwords not having <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue"><u>multi-factor authentication (MFA)</u></a> enabled. Nearly half (44%) of IAM cases on AWS had the industry-standard security control deployed.</p><p>Additionally, scans for Enabling Authentication and configuring Client Certificates within Azure App Service failed 97% of the time.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="d3rcKqaKkpbkDwSqX8yXGY" name="GettyImages-1229047327-IBM-logo-Seoul.jpg" caption="" alt="The IBM logo (stylised letters that read "IBM") on a board against a concrete wall, with two businessmen entering from the right of the frame wearing business suits and medical masks" src="https://cdn.mos.cms.futurecdn.net/d3rcKqaKkpbkDwSqX8yXGY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Observability in pre-production testing</strong></p><p class="fancy-box__body-text"><em>Application monitoring is in place to prevent software issues affecting users and customers. Discover the benefits of applying Enterprise Observability in pre-production testing.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/enterprise-applications/369844/observability-in-pre-production-testing">DOWNLOAD FOR FREE</a></p></div></div><p>Finally, external-facing assets can present attackers with multiple opportunities. The report noted that 31% of S3 buckets are publicly accessible, exposing them to an array of possible vulnerabilities.</p><p>The report noted: “A common misconfiguration by users of all major cloud providers is inadvertently leaving data publicly accessible”. Doing so can impact the effectiveness of other cloud services. Public S3 buckets, for example, can hold more than just sensitive data; access keys, credentials, or backup files can also be found in them, meaning the potential compromise of other services, such as EC2 instances.</p><p>“The convenience of - say, working on cloud assets from anywhere without having to use a VPN - suddenly transforms into a potential breach just waiting to happen.”</p><h2 id="log4shell-lingers">Log4Shell lingers</h2><p>The report noted the risk of weaponized vulnerabilities, particularly the ongoing danger of <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability"><u>Log4Shell</u></a>.</p><p>Log4Shell was first detected in December 2021 and exploits functionality in Log4j, an open-source logging framework used in many Java applications, to execute arbitrary code.</p><p>Despite being a well-known vulnerability, figures have shown that the Log4j flaw is proving difficult to mitigate. In this instance, the challenge is partly due to the scale and complexity of cloud environments. Many make extensive use of open-source software, such as Log4j, and are publicly exposed.</p><p>The Qualys team noted that it had detected 1 million Log4Shell vulnerabilities. Only 30% had been successfully fixed, leaving 70% unpatched. The average remediation time stood at 136 days, which researchers attributed to the complexity involved.</p><h2 id="lambda-another-exploitation-threat">Lambda: another exploitation threat</h2><p>While the CIS hardening benchmark lacks controls specifically for AWS Lambda, researchers found issues when looking at permissions provided to <a href="https://www.itpro.com/infrastructure/server-storage/369605/aws-speeds-up-cold-starts-with-lambda-snapstart"><u>Lambda</u></a> functions. </p><p>In terms of hardening, some checks on Lambda functions - including for monitoring and execution limits - recorded a more than 90% fail rate. Others, such as a check that Lambda environment variables at rest were encrypted with CMK, had a fail rate of 58%. </p><p>A failure around the hardening stance has the potential to give access to attackers.</p><p>Lambda has been specifically targeted by the <a href="https://www.itpro.com/security/cyber-security/367396/denonia-named-as-first-malware-to-target-aws-lambda-platform"><u>Denonia malware strain</u></a>, a crypto-miner that will burn through expensive compute cycles once it has achieved a foothold. Since Lambda - and other <a href="https://www.itpro.com/cloud/362623/what-is-serverless-computing"><u>serverless</u></a> technologies - are relatively new, security measures have tended to be overlooked.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thoma Bravo adds $1.5bn in value to Imperva before selling to Thales ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/thoma-bravo-adds-dollar15bn-in-value-to-imperva-as-thales-acquisition-agreed</link>
                                                                            <description>
                            <![CDATA[ Software investment giant to sell off the US-based data and application security provider for $3.6 billion ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YtMvrHjnys6FYmmqABYrga</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sX8yaf5ehG9kLmi8VbSu6V-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Jul 2023 10:32:27 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Jul 2023 15:28:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sX8yaf5ehG9kLmi8VbSu6V-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Thoma Bravo sells Imperva to Thales: Imperva&#039;s logo on a smartphone]]></media:description>                                                            <media:text><![CDATA[Thoma Bravo sells Imperva to Thales: Imperva&#039;s logo on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[Thoma Bravo sells Imperva to Thales: Imperva&#039;s logo on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sX8yaf5ehG9kLmi8VbSu6V-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Thales has reached an agreement with software investment firm Thoma Bravo to acquire application security provider Imperva for $3.6 billion.</p><p>One of the largest software investors in the world, Thoma Bravo bought Imperva for $2.1 billion in 2019, saying at the time its aim was to build a “market-leading data and application security company”. Imperva’s sale to Thales marks an addition of $1.5 billion in value to Imperva in the last four years. </p><p>With more than $127 billion in assets under management, Thoma Bravo invests in growth-oriented, innovative companies in the software and technology sectors. </p><p>Over the last couple of years, the company has been on an acquisition spree, snapping up a host of businesses – including Coupa Software, UserTesting, <a href="https://www.itpro.com/business-strategy/acquisition/369297/thoma-bravo-snaps-up-forgerock-for-23-billion"><u>ForgeRock</u></a>, <a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/367383/thoma-bravo-acquires-sailpoint-for-69-billion"><u>SailPoint</u></a>, <a href="https://www.itpro.com/business-strategy/acquisition/368735/thoma-bravo-adds-ping-identity-to-growing-cyber-security"><u>Ping Identity</u></a>, and more. Imperva is one of just a small number of businesses to be sold by Thoma Bravo in the past three years.</p><p>Seth Boro, managing partner at Thoma Bravo, said Imperva differentiated itself under its ownership through “accelerated growth and innovation” and its “unique approach” to end-to-end application and data security.</p><p>“During this time, the company successfully executed three acquisitions which strengthened its product offerings and capabilities to better protect clients’ critical data and applications,” he said.</p><h2 id="thales-x2019-plans-for-imperva">Thales’ plans for Imperva</h2><p>Upon completion of its acquisition, Thales said Imperva will enable growth in data security, as well as its entry into the application security market. </p><p>The firm expects Imperva’s integration to add around $500 million of revenue, as well as “significantly expand” its data and application security offering. Overall, Thales said its cyber security business will generate more than €2.4 billion ($2.65 billion) in revenue.</p><p>“The acquisition of Imperva marks a major milestone in Thales’ cyber security strategy,” said Patrice Caine, chairman and CEO at Thales. “With this acquisition, we are seizing a unique opportunity to accelerate our cyber security capabilities and are taking an important step towards our ambition to build a world-class global cyber security integrated player, providing a comprehensive portfolio of products and services.”</p><p>The freshly combined operations of the two businesses will create a cyber security portfolio structured around three areas: identity, data security, and application security. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zqJ5igWTeX9R9eFaNKdzme" name="Sustainability at scale, accelerated by data_listing.jpg" caption="" alt="Whitepaper cover with cityscape at sunset image in background" src="https://cdn.mos.cms.futurecdn.net/zqJ5igWTeX9R9eFaNKdzme.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Sustainability at scale, accelerated by data</strong></p><p class="fancy-box__body-text"><em>Learn how GPT delivered winning sustainability outcomes and better business resiliency.</em></p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-operations/370384/sustainability-at-scale-accelerated-by-data">DOWNLOAD FREE TODAY</a></p></div></div><p>Thales said increased capabilities are expected in the fields of protecting data at rest and data in use, while the pair’s “strong complementarity and cultural fit” is expected to yield “significant commercial opportunities”. </p><p>Imperva will sit within the global security products section of Thales’ offering, which focuses on the CipherTrust Data Security Platform, the SafeNet Trusted Access <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>Identity & Access Management</u></a> as a service solution, as well as the broader cloud protection & licensing offerings.</p><p>“Imperva and Thales share the same vision and the same DNA,” Caine added. “We look forward to welcoming Imperva to Thales to further enhance our cyber security solutions, and help customers address their most important digital security challenges.”</p><p>Thales has placed a significant focus on cyber security in recent times. Last month, the company announced an agreement to acquire Tesserent in a move designed to bolster its cyber security services family of products and services, as well as extend its presence in Australia and New Zealand.</p><p>From January 2024, Thales said it plans to regroup all its civil cyber activities within its digital identity and security (DIS) segment to strengthen its position as a provider of civil cyber security products.</p><p>Following the acquisitions of Imperva and Tesserent, Thales added that global <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> products and services will represent 44% of its DIS segment sales in 2024 –a 60% increase. </p><h2 id="what-is-imperva">What is Imperva?</h2><p>Headquartered in San Mateo, California, Imperva’s aim is to protect critical applications, APIs, and data at scale, with an approach that combines edge, application security, and data security. </p><p>The company has a global footprint in the Americas, Asia Pacific, as well as EMEA, and monitors threats across 180 countries.</p><p>Imperva’s portfolio includes its web application firewall (WAF), as well as its Data Security platform that helps to enhance the visibility of a company’s data to prevent breaches and avoid compliance issues. </p><p>The platform provides data discovery and classification, data security governance, data access monitoring, AI-powered risk analysis, intrusion detection, and more.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cryptojacking attacks surge 399% globally as threat actors diversify tactics ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cryptojacking-attacks-surge-399-globally-as-threat-actors-diversify-tactics</link>
                                                                            <description>
                            <![CDATA[ Attackers are switching tactics to wreak havoc and maximize financial gains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2f4fweCgsNPfXAzhvPXx5o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MZTBPVYpCXchNj6t4aFJ4T-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Jul 2023 10:01:39 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 12:02:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MZTBPVYpCXchNj6t4aFJ4T-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cryptojacking: A neon purple, fragmenting cryptocurrency token is hovering above the ground in a futuristic looking room]]></media:description>                                                            <media:text><![CDATA[Cryptojacking: A neon purple, fragmenting cryptocurrency token is hovering above the ground in a futuristic looking room]]></media:text>
                                <media:title type="plain"><![CDATA[Cryptojacking: A neon purple, fragmenting cryptocurrency token is hovering above the ground in a futuristic looking room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MZTBPVYpCXchNj6t4aFJ4T-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have issued a warning over a significant increase in cryptojacking attacks as threat actors seek to ‘diversify’ their tactics. </p><p>The volume of cryptojacking attacks surged by 788% in Europe during the first half of the year, with attacks in North America also rising by 345%. </p><p>Globally, the volume of cryptojacking attacks has increased by around 399%, according to research from SonicWall. </p><p>This increase marks the highest year-on-year record for global cryptojacking attacks, the firm said, and highlights a shift away from traditional <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> attacks in favor of “stealthier means of malicious activities”. </p><p>“Cyber criminals are diversifying and expanding their skill sets to attack critical infrastructure, making the threat landscape even more complex and forcing organizations to reconsider their security needs,” the company said in a statement. </p><p>This rise comes amid a decline in global ransomware attempts, which have dropped by 41% since the beginning of the year. However, the research indicated an upward trend in other attack methods, such as IoT <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> (+37%) and encrypted threats (+22%).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="y4BBTiSvSodzDxwU38wqXR" name="Six steps to a stronger security posture through automation_listing.jpg" caption="" alt="Whitepaper cover with business man wearing glasses looking to his right holding a smartphone" src="https://cdn.mos.cms.futurecdn.net/y4BBTiSvSodzDxwU38wqXR.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Six steps to a stronger security posture through automation</strong></p><p class="fancy-box__body-text"><em>Discover the tools to boost your cyber resilience.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/six-steps-to-a-stronger-security-posture-through-automation"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Bobby Cornwell,  vice president of product security at SonicWall, said the evolving tactics witnessed in recent months show a desire among threat actors to harness techniques that are low-cost, but often deliver high returns. </p><p>“SonicWall intelligence suggests that bad actors are pivoting to lower-cost, less risky attack methods with potentially high returns, like <a href="https://www.itpro.com/technology/cryptocurrencies/360485/what-is-cryptojacking-and-how-does-it-work"><u>cryptojacking</u></a>,” he said. </p><p>“It also explains the reason we’re seeing higher levels of cyber crime in regions like Latin America and Asia. Hackers search for the weakest points of entry, with the lightest possible repercussions, limiting their risk and maximizing their potential profits.”</p><h2 id="high-priority-targets">High-priority targets</h2><p>Globally, SonicWall found that ransomware attacks on a host of industries saw a decline during the first half of the year, reflecting a broader dip in ransomware activity. </p><p>However, popular target sectors such as healthcare, government, and education all faced an increase in cryptojacking attacks. </p><p>Cryptojacking attempts against educational institutions surged by 320% while government-related attacks also increased by 89%. </p><p>“The seemingly endless digital assault on enterprises, governments, and global citizens is intensifying, and the threat landscape continues to expand,” said SonicWall president and CEO Bob VanKirk. </p><p>“Threat actors are relentless, and our data indicates they are more opportunistic than ever, targeting schools, state and local governments, and retail organizations at unprecedented rates.</p><h2 id="what-is-cryptojacking">What is cryptojacking?</h2><p>Cryptojacking is a type of attack that harnesses a victim’s desktop or laptop device to mine cryptocurrency. </p><p>This form of attack has grown in popularity among threat actors alongside the rise of cryptocurrencies in recent years, and is typically initiated when a victim unwittingly installs malware on their device. </p><p><a href="https://www.itpro.com/security/29093/what-is-phishing"><u>Phishing attacks</u></a> are frequently leveraged to initiate this type of attack, prompting users to click on a malicious link in email correspondence, or even on a webpage. </p><p>Victims of cryptojacking often might not be aware they’ve even fallen prey to cyber criminals, enabling the attacker to fly under the radar and mine cryptocurrency for extended periods. </p><p>There are telltale signs, however. One of the main signs of cryptojacking is decreased device performance due to the increased use of processing power. </p><p>Similarly, for laptop devices, a rapidly decreasing battery capacity can also be a telltale sign that a user has been compromised and their device is being used to mine currencies. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NTT Data begins rolling out new MDR service  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ntt-data-begins-rolling-out-new-mdr-service</link>
                                                                            <description>
                            <![CDATA[ The new security management outsourcing offering is being launched in Japan before a wider global release before March 2024 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Q4cmzYXn936u94SdJoPfBH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JfDCLjBNLnmpCQrY5MT2U4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jul 2023 10:09:21 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 11:29:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JfDCLjBNLnmpCQrY5MT2U4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NTT Data logo displayed on a glass door in an office]]></media:description>                                                            <media:text><![CDATA[NTT Data logo displayed on a glass door in an office]]></media:text>
                                <media:title type="plain"><![CDATA[NTT Data logo displayed on a glass door in an office]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JfDCLjBNLnmpCQrY5MT2U4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT services provider NTT Data has announced the launch of its new managed detection and response (MDR) service for security management.</p><p>The offering will be rolled out in Japan this month, while a broader global release is expected before the end of March 2024, the company said.</p><p>With the new service, advanced security engineers will provide support to clients that either don’t have the in-house talent to manage a security function or simply find it easier or more cost-efficient to pay for a managed service.</p><p>NTT Data said these engineers will act on behalf of clients by executing a “comprehensive set of measures” to identify the cause of an incident, implement emergency response measures, maximize recovery efforts, and work to prevent a recurrence.</p><p>“To support client companies that find it difficult to manage security on their own, NTT DATA will start providing MDR services utilizing the design, construction, and operational know-how cultivated through its Global Zero Trust Security Service, along with the experience for more than 20 years and expertise of NTTDATA-CERT, its advanced security specialist organization,” the company said in an announcement.</p><p>The service will provide businesses with fully integrated, cross-sectional, and multilingual support. It will start with the introduction of an incident response framework, through to detection, response, and recovery in an incident – as well as continual elevation and improvement of the introduced framework, the firm said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4qgTo2YTCSpjo3wUy2D6VU" name="Business_value_FP_listing.jpg" caption="" alt="Whitepaper cover with title in green: Business value of security operations" src="https://cdn.mos.cms.futurecdn.net/4qgTo2YTCSpjo3wUy2D6VU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Business value of ServiceNow security operations</strong></p><p class="fancy-box__body-text"><em>See what happens when your security, risk and IT teams can gain unprecedented visibility of threats.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/business-value-of-servicenow-security-operations"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>To help develop talent that can drive its MDR services, NTT Data will also launch a new talent development program for advanced security engineers. </p><p>The firm said it aims to expand the structure from the current level of 100 engineers to 500 globally by the end of March 2026.</p><p>The program is based on the expertise of NTT Data’s incident response organization and has been built to incorporate knowledge from NTT locations around the world, while its curriculum has been developed in collaboration with NTT Data Intellilink Corporation. Upon completion of the online program, engineers will be certified as MDR Services Specialists.</p><h2 id="mdr-market">MDR market</h2><p>MDR services provide customers with modern security operations center (SOC) functionality to help detect and disrupt security threats. The security as a service model allows organizations to outsource their security operations to overcome hurdles such as staff shortages and skills gaps.</p><p>According to a <a href="https://www.reportlinker.com/p05222513/Managed-Detection-and-Response-Market-by-Security-Type-Deployment-Organization-Size-Industry-Vertical-And-Region-Global-Forecast-to.html?utm_source=GNW"><u>recent report</u></a> from market data provider <em>ReportLinker</em>, the global MDR market is currently valued at approximately $3.3 billion in 2023 – and is projected to grow to around $9.5 billion by 2028, at a compound annual growth rate of 23.3%.</p><p>Factors helping to drive the market’s expansion are said to include an uptick in business email compromise, <a href="https://www.itpro.com/security/ransomware/ibm-law-enforcement-helped-save-ransomware-victims-dollar470k-in-2023"><u>ransomware</u></a>, as well as <a href="https://www.itpro.com/technology/cryptocurrencies/360485/what-is-cryptojacking-and-how-does-it-work"><u>cryptojacking</u></a> threats. Adoption of MDR services has also been fueled by the industry’s cyber security skills gap.</p><p>With the positive forecast for the market over the coming years, NTT said it’s aiming to take its annual global sales from security management to over 200 billion Japanese Yen (approximately USD 1.4 billion) by March 2026, mainly in <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a> services.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM: Law enforcement helped save ransomware victims $470k in 2023 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/ibm-law-enforcement-helped-save-ransomware-victims-dollar470k-in-2023</link>
                                                                            <description>
                            <![CDATA[ New report reveals that organizations that reached out to law enforcement saw shorter recovery times and lower financial impact ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tTpdHALpsQtA3bFdDTaGgU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3mUMFwCvQx59DXbzPVdfRK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Jul 2023 04:01:00 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 11:26:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3mUMFwCvQx59DXbzPVdfRK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IBM: Mockup image of ransomware - a red background with binary code and a padlock in the middle with &#039;ransomware&#039; written on top of it]]></media:description>                                                            <media:text><![CDATA[IBM: Mockup image of ransomware - a red background with binary code and a padlock in the middle with &#039;ransomware&#039; written on top of it]]></media:text>
                                <media:title type="plain"><![CDATA[IBM: Mockup image of ransomware - a red background with binary code and a padlock in the middle with &#039;ransomware&#039; written on top of it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3mUMFwCvQx59DXbzPVdfRK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Victims of ransomware that did not involve law enforcement paid an average of $470,000 more in breach costs in 2023 than those that did, according to a new report released by IBM.</p><p>Conducted in partnership with Ponemon Institute, the firm’s annual <em>Cost of a Data Breach Report</em> analyzed data breaches experienced by 553 organizations around the world between March 2022 and March 2023.</p><p>The study found that participating organizations that did not involve law enforcement experienced breach life cycles that were 33 days longer on average than those that did reach out – at an average cost of $470,000.</p><p>Despite ongoing efforts by law enforcement to collaborate with ransomware victims, 37% of surveyed organizations still chose not to engage them, while 47% reportedly paid the ransom.</p><p>For those that did, the total time to identify and contain a ransomware breach stood at 273 days, compared with 306 days for those who didn’t – an 11.4% reduction. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8Hych4XJRfHkUY47d64Qg8" name="State of ransomware readiness 2022_listing.jpg" caption="" alt="Whitepaper cover with red and white title over a black and white image of a businessman stood looking out of an office window" src="https://cdn.mos.cms.futurecdn.net/8Hych4XJRfHkUY47d64Qg8.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>State of ransomware readiness 2022</strong></p><p class="fancy-box__body-text"><em>Dig deeper into ransomware threats and assess their impact on cyber security teams.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/state-of-ransomware-readiness-2022"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The mean time to contain a breach was 63 days - 23.8% shorter with law enforcement involvement compared to 80 days without.</p><p>Overall, the global average cost of a data breach saw a 15% increase over the last three years, rising to $4.45 million in 2023 – an all-time high for the report, which has been conducted annually for the previous 18 years.</p><p>Detection and escalation costs also jumped 42% over the same period, representing the highest portion of breach costs, which IBM says signifies a shift towards more complex breach investigations.</p><h2 id="ibm-cost-of-data-breach-report-paying-the-ransom">IBM Cost of Data Breach Report: Paying the ransom</h2><p>Organizations that decided to <a href="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up"><u>pay the ransom</u></a> during an attack were found to achieve just a 2.2% difference in total cost, coming in at $5.06 million compared to the $5.17 million total for those that did not. </p><p>However, IBM said that calculation does not take into consideration the ransom fee itself and, due to their hefty totals, those that did pay were likely to have spent more overall. </p><p>Additionally, the data revealed that paying a ransom has also become less beneficial, with an 82.5% decline in savings since last year’s report.</p><h2 id="ibm-cost-of-data-breach-report-detection-and-escalation">IBM Cost of Data Breach Report: Detection and escalation</h2><p>Overall costs have risen and so too have the costs associated with detection and escalation. </p><p>IBM said these costs include activities that enable an organization to “reasonably detect a breach” and can include forensic and investigative activities, assessment and audit services, crisis management, as well as communications to executives and boards.</p><p>In 2022, the category became the costliest of the data breach expenses, suggesting that investigations had become more complex and time-consuming. This year, it remained on top of the pile, rising 9.7% from $1.44 million to $1.58 million.</p><h2 id="ibm-cost-of-data-breach-report-data-breach-lifecycle">IBM Cost of Data Breach Report: Data breach lifecycle</h2><p>As for the data breach lifecycle, the report found that the time taken to identify and contain a data breach “held steady” at 277 days – or approximately nine months – in 2023. </p><p>That’s consistent with the average over the last seven years of reported data, which ranges from a low of 257 days in 2017 to a high of 287 in 2021.</p><p>Shorter data breach lifecycles also continue to be linked to lower <a href="https://www.itpro.com/security/data-breaches/368649/price-hike-for-consumers-as-data-breach-costs-rocket-to-all-time-high"><u>data breach costs</u></a>, with lifecycles under a 200-day threshold clocking an average cost of $3.93 million. By comparison, longer lifecycles of more than 200 days cost an average of $4.95 million – a 23% difference.</p><h2 id="ibm-cost-of-data-breach-report-cost-mitigation">IBM Cost of Data Breach Report: Cost mitigation</h2><p>From a pool of 27 key cost factors, the adoption of a DevSecOps approach was the most effective at mitigating overall costs. According to the data, breaches at organizations that had implemented a <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important"><u>DevSecOps</u></a> approach had an average cost that was $249,278 less than the average of $4.45 million.</p><p>Employee training and <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach"><u>incident response</u></a> planning and testing rounded out the top three, with average cost reductions of $232,867 and $232,008 respectively.</p><p>As for cost amplifiers, the top three culprits were found to be security system complexity (+$240,889), security skills shortage (+$238,637), and noncompliance with regulators (+$218,915). The average cost of a breach for organizations with high levels of security <a href="https://www.itpro.com/business-strategy/careers-training/369682/hiring-from-overseas-tech-skills-gap"><u>skills shortage</u></a> was $5.36 million.</p><p>Commenting on the findings, Chris McCurdy, general manager at Worldwide IBM Security Services, said that time is the “new currency” in cyber security for both defenders and attackers.</p><p>“As the report shows, early detection and fast response can significantly reduce the impact of a breach,” he said. “Security teams must focus on where adversaries are the most successful and concentrate their efforts on stopping them before they achieve their goals. </p><p>“Investments in threat detection and response approaches that accelerate defenders speed and efficiency – such as <a href="https://www.itpro.com/business-strategy/automation/368115/ai-is-now-powerful-enough-to-automate-the-back-office"><u>AI and automation</u></a> – are crucial to shifting this balance.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenSSH vulnerability uncovered by researchers, RCE exploit developed  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/openssh-vulnerability-uncovered-by-researchers-rce-exploit-developed</link>
                                                                            <description>
                            <![CDATA[ Attackers can remotely manipulate common libraries to execute arbitrary code ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BcSSgyBb3FeqZGPC5zxgBH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jul 2023 09:32:45 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Jul 2023 10:57:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenSSH vulnerability: A red warning sign on a background of code, denoting malware and cyber attacks]]></media:description>                                                            <media:text><![CDATA[OpenSSH vulnerability: A red warning sign on a background of code, denoting malware and cyber attacks]]></media:text>
                                <media:title type="plain"><![CDATA[OpenSSH vulnerability: A red warning sign on a background of code, denoting malware and cyber attacks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have uncovered a vulnerability, tracked as CVE-2023-38408, in the secure networking suite OpenSSH which would allow hackers to remotely execute code using simple commands.</p><p>Exploitation of the vulnerability makes use of a commonly-used helper program in OpenSSH called ssh-agent, which holds a user’s private keys for use in frequent, often automated, SSH public key authentication.</p><p>Administrators managing remote servers often enable ‘ssh-agent forwarding’, which enables the ssh-agent to be accessed from a chosen server so that local SSH keys to be used without storing keys on the server itself.</p><p>Qualys researchers <a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent" target="_blank"><u>discovered</u></a> that when a forwarded agent is set up using default settings, with PKCS11 enabled, it’s possible for a threat actor with a connection to the same remote server to load and unload shared libraries on a victim’s machine with malicious side effects.</p><p>Security researchers used this technique to achieve one-shot, remote code execution (RCE) by combining just four side effects of loading and unloading common shared libraries.</p><p>Once an attacker has achieved RCE, a host of malicious actions can be undertaken including the installation of <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, carrying out a <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach"><u>data breach</u></a>, or total system takeover.</p><p>“This newly uncovered ssh-agent vulnerability underlines the continuous need for rigorous security measures and immediate response,” wrote Saeed Abbasi, manager, Vulnerability Signatures at Qualys.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fJNPj3JADSPXRojuC6w3p8" name="State of ransomware readiness 2022_thumbnail.jpg" caption="" alt="Whitepaper cover with red and white title over a black and white image of a businessman stood looking out of an office window" src="https://cdn.mos.cms.futurecdn.net/fJNPj3JADSPXRojuC6w3p8.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>State of ransomware readiness 2022</strong></p><p class="fancy-box__body-text"><em>Find out how organizations are defending against ransomware attacks today</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/state-of-ransomware-readiness-2022"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Even robust systems can harbor hidden vulnerabilities, as demonstrated by the shortcomings of the ssh-agent. Proactively rectifying such vulnerabilities through actions such as implementing patches is critical to maintaining the integrity of digital assets.”</p><p>OpenSSH is a widely-used solution for encrypted data transfer and remote logins, particularly by administrators seeking to easily manage <a href="https://www.itpro.com/security/cyber-security/359457/what-are-ssh-keys"><u>SSH keys</u></a>. It is used worldwide for secure connections.</p><p>Researchers found the default installations of Ubuntu Desktop 22.04 and 21.10 to be vulnerable and warned that other <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros"><u>Linux distributions</u></a> or <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system"><u>operating systems</u></a> could also be exploited if left unpatched.</p><p>Vulnerable OpenSSH releases include:</p><ul><li>1:7.9p1-10+deb10u2</li><li>1:7.9p1-10+deb10u1</li><li>1:8.4p1-5+deb11u1</li><li>1:9.2p1-2</li><li>1:9.3p1-1</li></ul><p>The issue has been fixed as of version 1:9.3p2-1.</p><p>OpenSSH noted that the flaw can only be exploited if specific libraries are present in the victim’s system, and that if agents are not forwarded to a hacker-compromised network, attacks cannot be achieved remotely.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rubrik appoints Zscaler’s Sean Sullivan as director of alliances for EMEA ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/rubrik-appoints-zscalers-sean-sullivan-as-director-of-alliances-for-emea</link>
                                                                            <description>
                            <![CDATA[ The cyber sales veteran will lead the development of Rubrik’s partnership capabilities and sales strategy across the region ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j9Da9esGhLHBQuF9qHHcGY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PLTssNANQ2exnSHMYEeyBR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Jul 2023 11:10:08 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Jul 2023 09:05:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PLTssNANQ2exnSHMYEeyBR-1280-80.jpg">
                                                            <media:credit><![CDATA[Rubrik]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Rubrik&#039;s Sean Sullivan headshot with grey background]]></media:description>                                                            <media:text><![CDATA[Rubrik&#039;s Sean Sullivan headshot with grey background]]></media:text>
                                <media:title type="plain"><![CDATA[Rubrik&#039;s Sean Sullivan headshot with grey background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PLTssNANQ2exnSHMYEeyBR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zero trust data security specialist Rubrik has announced the appointment of former Zscaler channel director Sean Sullivan as its new director of alliances for EMEA. </p><p>The specially created role will see the seasoned channel veteran take charge of developing Rubrik’s partnership capabilities, with a focus on supporting major telecoms and internet service providers with the necessary security services.</p><p>Sullivan joins the business having accumulated more than 25 years’ experience within technology and cyber security sales, including senior positions at Microsoft, Netscape, Dell EMC, and BlackBerry-owned Good Technology. </p><p>In his most recent role at Zscaler, he led the development of the firm’s relationships with telecom clients.</p><p>Commenting on his appointment, Sullivan said that he has witnessed the service provider industry transform over his career.</p><p>“Most businesses have changed their solutions approach: They now look for one provider to deliver internet connectivity, storage, and security, rather than pick and mix different solutions from different vendors,” he said. </p><p>“For Rubrik, this presents a real opportunity to offer service providers new and better services that will attract more customers. </p><p>“Whether it’s reselling Rubrik licenses as optional extras or including Rubrik security as a managed service to customers, I’m excited to see how we can support our customers and partners more than ever.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dtzryvF42B8M2aazM4PbyS" name="The top zero trust use cases_listing.jfif.jpg" caption="" alt="Whitepaper cover with title over an image of male colleague at a workstation in a warehouse, with dotted blue patter overlayed" src="https://cdn.mos.cms.futurecdn.net/dtzryvF42B8M2aazM4PbyS.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The top zero trust use cases</strong></p><p class="fancy-box__body-text"><em>Leverage the Zero Trust Exchange to stop threats from infiltrating the enterprise</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-top-zero-trust-use-cases"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>With 72% of organizations paying out when confronted by ransomware, according to the latest data from Rubrik Zero Labs, Rubrik said Sullivan’s appointment as EMEA alliances chief will help service providers find new ways of defending themselves against increasingly sophisticated cyber threats.</p><p>“Security is a constantly evolving industry, which is why it’s so important to have a depth of knowledge, talent, and experience within a business,” said Ghazal Asif, vice president of global partners and alliances at Rubrik. “That’s why I’m very happy to welcome Sean to our team. </p><p>“His background working with some of the tech world’s major players, coupled with his attitude and approach makes him an ideal person to lead our efforts with service providers.”</p><p>The move is the latest in a string of leadership hires for Rubrik and the second in as many months that have arrived from Zscaler, following the appointment of <a href="https://www.itpro.com/business/leadership/rubrik-appoints-former-zscaler-executive-as-vice-president-for-ukandi"><u>Tony Keech as vice president of its UK&I business</u></a>.</p><p>Rubrik has also recently announced <a href="https://www.itpro.com/business/leadership/rubrik-appoints-richard-cassidy-as-new-field-ciso-for-emea"><u>Richard Cassidy as its new field CISO for EMEA</u></a>, as well as <a href="https://www.itpro.com/business/leadership/rubrik-appoints-andres-botero-as-chief-marketing-officer"><u>Andres Botero as chief marketing officer</u></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Telefónica Tech and F5 unveil new service to protect enterprise applications ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/telefonica-tech-and-f5-unveil-new-service-to-protect-enterprise-applications</link>
                                                                            <description>
                            <![CDATA[ The new Web Application Defense (WAD) managed service will help enterprise customers detect threats and vulnerabilities in real time ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8eYWADmuP6EdVrGJg7Fo6j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NEjje87dAuG8WVNiQvoKSF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jul 2023 10:43:10 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Jul 2023 13:31:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NEjje87dAuG8WVNiQvoKSF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Telefónica Tech: A series of blue blocks with binary code displayed alongside yellow padlocks]]></media:description>                                                            <media:text><![CDATA[Telefónica Tech: A series of blue blocks with binary code displayed alongside yellow padlocks]]></media:text>
                                <media:title type="plain"><![CDATA[Telefónica Tech: A series of blue blocks with binary code displayed alongside yellow padlocks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NEjje87dAuG8WVNiQvoKSF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Telefónica and F5 have expanded their partnership to launch a new SaaS-based service designed to improve the security and speed of app deployment in multi-cloud environments. </p><p>Deployed on F5’s Distributed Cloud platform, the new Web Application Defense (WAD) managed service enables Telefónica Tech’s enterprise customers to detect threats and vulnerabilities in real time by combining telemetry collection with programmable rules, advanced AI, and machine learning.</p><p>Managed from a single dashboard, the offering has been designed to protect enterprise applications whether they are deployed on-premises, across multiple clouds, or at the edge.</p><p>Juan Campillo, Telefónica Tech’s director of cyber security product marketing, said the company’s partnership with F5 enables the company to launch a “state-of-the-art managed services solution” that can detect and block the attempted exploitation of application vulnerabilities.</p><p>“In particular, the deployment of WAD on F5&apos;s Distributed Cloud Platform will add speed to a critical security layer, while providing flexibility for our enterprise customers to deploy, secure and operate applications in a multi-cloud environment wherever needed: In the data center, across hybrid deployments, or across multiple clouds,” he said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NxDbqv8WKS7eZFSALxtrDN" name="Six Reasons IT Pros are Ditching Legacy Monitoring Tools_listing.jpg" caption="" alt="Newspaper style whitepaper cover with image of laptop on a users lap" src="https://cdn.mos.cms.futurecdn.net/NxDbqv8WKS7eZFSALxtrDN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: LogicMonitor)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Six reasons IT Pros are ditching legacy monitoring tools</strong></p><p class="fancy-box__body-text"><em>How to drive operational efficiency, become less reactive, and be more proactive</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/six-reasons-it-pros-are-ditching-legacy-monitoring-tools"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“In addition, the managed services approach is a significant boost for organizations that lack the resources and expertise to address today&apos;s cyber security challenges."</p><p>Specializing in digital transformation, Telefónica Tech provides a host of services and integrated solutions across cyber security, cloud, IoT, big data, and blockchain. </p><p>The company claims it has the capacity to reach 5.5 million customers across 175 countries through its presence in Spain, the UK, northern Europe, USA, Brazil, Peru, Colombia, Chile, and Mexico.</p><p>The firm’s new WAD managed service is supported by its security operations center (SOC) team, which will provide round-the-clock support and cloud environment monitoring for enterprise customers.</p><p>Available for organizations in Spain for a monthly fee, the offering currently includes F5’s Web Application Firewall (WAF), bot defense, <a href="https://www.itpro.com/development/application-programming-interface-api/369956/the-it-pro-podcast-the-problem-with-apis"><u>API security</u></a>, and <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>distributed denial of service (DDoS)</u></a> mitigation capabilities.</p><p>“We are delighted to announce the launch of the WAD <a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service"><u>managed service</u></a> with Telefónica Tech,” commented Mariana Agache, VP for SP Managed Services at F5. “Our partnership goes far beyond just providing a technology platform, and we will continue to support Telefónica with enablement and <a href="https://www.itpro.com/business-strategy/31699/what-is-a-gtm-strategy"><u>go-to-market</u></a> efforts both in EMEA and beyond. </p><p>“As ever, our mutual goal is to ensure continual innovation and safe, world-class services for customers.”  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC neutralizes fewer cyber crime campaigns for first time in six years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/ncsc-neutralizes-fewer-cyber-crime-campaigns-for-first-time-in-six-years</link>
                                                                            <description>
                            <![CDATA[ Drop in takedowns may be due to short lifetimes of extortion email servers and crypto scams ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eHaqoHsan8Q7QD5ZR3UFka</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jul 2023 10:37:40 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Jul 2023 13:23:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:description>                                                            <media:text><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:text>
                                <media:title type="plain"><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s National Cyber Security Centre (NCSC) announced today that the total number of cyber crime takedowns has fallen for the first time in six years.</p><p>According to its annual Active Cyber Defence (ACD) report, it shut down 1.8 million malicious campaigns and 2.4 million malicious URLs throughout 2022, representing a 33% and 22.5% fall on 2021’s figures respectively.</p><p>The NCSC started publishing its ACD reports in 2017 and until 2023, every year had led to an increasing number of takedowns.</p><p>Much of the reduction came from a drop in takedowns of extortion mail servers. Its figures for 2022 stood at 528,000, down from 2021’s 1,867,439,  and cryptocurrency investment scams which dropped to 459,278 from 610,621 the previous year.</p><p>The cyber security arm of GCHQ didn’t offer a concrete explanation regarding why the number of takedowns had fallen, and the campaign-by-campaign breakdown of the takedown data showed mixed conclusions. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CZGRPmo3S5zynJBv3QLkjb" name="ThreatLabz State of Phishing Report_thumb.jfif.jpg" caption="" alt="Whitepaper cover with title over image of colleagues chatting in an office with red circular digital icons around them" src="https://cdn.mos.cms.futurecdn.net/CZGRPmo3S5zynJBv3QLkjb.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>ThreatLabz 2023 Phishing Report</strong></p><p class="fancy-box__body-text"><em>Helping you realize the tactics used in phishing attacks, in order to prevent costly data breaches</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-2023-phishing-report"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Some attacks dropped in frequency, like extortion mail servers, but others soared, like the takedowns of <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>-associated URLs.</p><p>Both malware infrastructure <a href="https://www.itpro.com/security/cyber-attacks/is-the-new-zip-top-level-domain-a-cyber-security-risk"><u>URLs</u></a> and web-inject malware URLs were in the top ten list of  campaign types that were taken down this year.</p><p>The former rose to 18,337 takedowns in 2022, up from 5,270 in 2021, and the latter rose to 6,287 from 1,466 the previous year.</p><p>One of the possible explanations for the drop in takedowns could be due to apparent low uptimes of the campaigns.</p><p>Mail servers have a median availability of 25.5 hours, according to the report, and <a href="https://www.itpro.com/technology/cryptocurrencies/354811/how-safe-are-cryptocurrencies"><u>cryptocurrency</u></a> investment scams stand at one hour. In comparison, the next top five attack types have a combined median of 56.29 hours. </p><p>The figures suggest that the longer an attack is available, the more time there is for a takedown to occur.</p><p>The report also noted a drop in attacks hosted from the UK to the tune of 25%.</p><p>While phishing attacks remained at the top of the list, the number of attacks fell markedly, from 113,457 in 2021 to 77,471 in 2022 and a reduction from ten to seven hours of median availability.</p><p>Brute force attacks also formed part of the <a href="https://www.ncsc.gov.uk/report/acd-the-sixth-year" target="_blank"><u>report</u></a> and, despite the ACD only starting the use of honeypots in August 2022, 40,890 takedowns were recorded. </p><p>SSH was the protocol that led to most takedowns - more than 32,000 were reported from August 2022 to December 2022 - followed by RDP, <a href="https://www.itpro.com/development/web-development/368222/wordpress-vs-wix-vs-squarespace"><u>WordPress</u></a>, and Exchange some way behind.</p><p>Other services covered in the <a href="https://www.itpro.com/security/370303/ncsc-launches-free-browser-security-threat-checks-smbs"><u>NCSC</u></a> report include the suspicious email reporting service, which permits members of the public to report suspicious emails and web sites. According to the report, malicious URLs were removed from the internet in an average of six hours. </p><h2 id="what-is-the-ncsc-x2019-s-takedown-service">What is the NCSC’s Takedown service?</h2><p>The ACD’s Takedown service finds malicious sites and removes them before significant harm can be done. </p><p>It is focussed on what it deems would cause the most harm to UK interests and also targets all malicious activity hosted in the UK.</p><p>It was initially developed with just UK government organizations in mind, but has broadened to cover a wider range of users over the years.</p><p>In 2020 it commenced takedowns against cryptocurrency investment scams, takedowns of which peaked in January 2021 before following a consistent downward trend into December 2022.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is platform engineering and will it see the end of DevSecOps? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/what-is-platform-engineering-and-will-it-see-the-end-of-devsecops</link>
                                                                            <description>
                            <![CDATA[ Platform engineering is not just the latest industry buzzword but could represent a profound change in how software is developed and governed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a5bHuKxHMhmY8rGfTvbebP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/psr4hnun2R4R2jEq9AeSU4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jul 2023 08:32:19 +0000</pubDate>                                                                                                                                <updated>Tue, 11 Jul 2023 14:03:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/psr4hnun2R4R2jEq9AeSU4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital circuit board]]></media:description>                                                            <media:text><![CDATA[A digital circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[A digital circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/psr4hnun2R4R2jEq9AeSU4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Platform engineering has become somewhat of an industry buzzword in recent years as organizations look to rapidly accelerate the delivery of applications and unlock greater business value at scale. </p><p>This emerging discipline, as Gartner describes it, helps markedly improve developer experience and productivity by “providing self-service capabilities with automated infrastructure operations”. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important">What is DevSecOps and why is it important?</a></p></div></div><p>Simply put, platform engineering centers around enabling <a href="https://www.itpro.com/software/development/356827/how-to-become-a-developer-a-beginners-guide"><u>developer</u></a> teams to focus on building and fine tuning products while rapidly accelerating product teams’ delivery pipeline. </p><p>Similarly, it helps solve the age-old issue of fostering closer cooperation between software developers and operators. </p><p>By 2026, 80% of <a href="https://www.itpro.com/business-strategy/careers-training/358051/software-developers-versus-software-engineers"><u>software engineering</u></a> organizations will will establish platform teams, according to Gartner research. This prompts some to question whether platform engineering will render <a href="https://www.itpro.com/devops/28097/what-is-devops"><u>DevOps</u></a> or <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important"><u>DevSecOps</u></a> obsolete. </p><h2 id="does-platform-engineering-spell-the-end-of-devops">Does platform engineering spell the end of DevOps?</h2><p>This was a question posed to a trio of participants during a roundtable discussion at KubeCon 2023 in April. </p><p>The panel, which included GitLab CPO David DeSanto, Sarah Polan, Field CTO EMEA at HashiCorp, and Stu Miniman, director of market insights at Red Hat, explored at length the rise of platform engineering and whether it spells the end of DevOps as we know it.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yJT8tAEv5WVR26o854DXBC" name="Trend Micro security predictions for 2023_listing.jpg" caption="" alt="Whitepaper cover with title over a shattered glass style image of a female wearing a VR headset" src="https://cdn.mos.cms.futurecdn.net/yJT8tAEv5WVR26o854DXBC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Trend Micro security predictions for 2023</strong></p><p class="fancy-box__body-text"><em>Learn more about securing environments and systems with a Zero Trust strategy</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370157/trend-micro-security-predictions-for-2023"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>While all three agreed this emerging trend has gathered, and continues to gather, pace in recent years, it’s more complex than simply heralding a new era in product engineering and development. It’s dependent wholly on the individual needs of the business, and their ability to navigate change. </p><p>Platform engineering isn’t for everyone, but it could unlock significant improvements to productivity and application delivery if done currently, according to Stu Miniman. </p><p>“When we talk to our developer communities, some of the biggest problems we hear is that there’s cognitive overload and dealing with context switching,” he said. </p><p>“It’s a challenge that all of us have, but especially with developers. Platforms are not new, but platform engineering is a thing that’s been growing for about three years now.”</p><p>Miniman noted that, fundamentally, platform engineering is about enabling developers to focus on their primary role and delegate certain aspects of platform management and governance to teams specifically catered around that task. </p><p>In doing this, platform engineering makes things “a little bit simpler” for developers and removes – to an extent – the cognitive overload that many experience when building and managing platforms. </p><h2 id="what-problem-does-platform-engineering-solve">What problem does platform engineering solve?</h2><p>For many years, businesses globally have focused significant resources in bringing together the developer, operator, and <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> elements that all play a key role in delivering software applications rapidly to keep pace with insatiable customer demand.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">Does risk management actually work?</a></p></div></div><p>But asking developers to build then subsequently maintain platforms has placed significant strain on teams, Polan noted. This strain has reared its ugly head frequently, especially with regard to security and <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference"><u>risk management</u></a>. </p><p>“The past couple of years, the previous trend was very much DevOps. So we wanted to encourage developers and engineers to build and run their own infrastructure and then we quickly became cognizant, both from a business standpoint but also the technical and developer standpoint, that the developers didn’t actually want to own and run their own infrastructure because there’s a lot that goes into that,” she said. </p><p>“Whether it’s risk based, velocity based, or not being able to focus on the business problem.”</p><p>Miniman echoed Polan’s comments, noting that this increased strain has frequently been referenced as one of the key hindrances to developer teams in addition to the increased security considerations required when developing at pace. </p><p>“DevSecOps is great, but we know one of the impediments to rolling things out faster often are security issues that you need to worry about or getting everyone involved,” he said. </p><p>“You’re talking about golden paths and about giving people the guardrails, governance, and control. In certain pieces, we want to take that off the plates of the developers so they can focus on writing code, modernizing things and taking advantage of technologies. </p><p>“So, if we can make things a little bit simpler and allow developers to focus on their primary role and the stuff they want to be doing, that makes things easier.”</p><h2 id="platform-engineering-in-an-era-of-heightened-risk">Platform engineering in an era of heightened risk</h2><p>Surging security threats in recent years have, in part, led to the growing popularity of platform engineering as a discipline, Polan insisted. By charging responsibility of governance, control, and risk management to developer teams, this can lead to overload and causes vital issues to be missed or overlooked. </p><p>Platform engineering helps mitigate this problem by delegating an aspect of this responsibility. </p><p>“I think that it [platform engineering] is becoming increasingly important, especially as we start looking toward the <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot"><u>Internet of Things (IoT)</u></a> starting to explode and edge computing, and having to have this modularity but also looking from the security and risk standpoint,” she said. “We need to be able to follow these different patterns.”</p><p>Polan cited the SolarWinds and <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability"><u>Log4j</u></a> incidents as a prime example of this lack of clarity about platform risks and transparency of oversight for individual platforms within an organization’s estate. </p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=46862322&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>“I think if we look at SolarWinds, for example, not being able to follow exactly where all of this infrastructure and deployments went affected where the potential threat breach was after the initial supply chain attack. </p><p>“So just making sure that we as organizations are in control, but also garnering business value from this by setting guardrails in place and say <em>‘</em>we want you to be able to do what you want, follow industry standards, use <a href="https://www.itpro.com/software/28109/what-is-open-source"><u>open source’</u></a>, but also make sure we have adequate control over these things.”</p><h2 id="why-devsecops-is-here-to-stay">Why DevSecOps is here to stay</h2><p>All three roundtable participants agreed that platform engineering doesn’t necessarily spell the end for DevSecOps as a discipline. Instead, this forms another part of how organizations build, modernize and manage their platform environments. </p><p>Miniman suggested that platform engineering represents an “outgrowth” of DevSecOps, adding that it’s “an extension of what we’re doing - it’s evolutionary, not necessarily revolutionary.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/chief-information-officer-cio/368452/cio-business-leaders-not-technologists">Why business leaders – not technologists – make the best CIOs</a></p></div></div><p>DeSanto echoed his thoughts, noting that there is room for beneficial coexistence that will ultimately deliver benefits for developer teams and the broader organization. </p><p>“I sometimes struggle with why something has to die for something else to exist,” he said. “And so, I don’t know what nerd references are right for the audiences, but maybe it’s the Jedi versus the Sith? That’s what it feels like to me.</p><p>“I think there’s a lot more overlap and value to that. In essence, platform engineering is making sure your DevOps or DevSecOps teams are more effective - and they’re more effective because they’re working with the platform team and vice versa. </p><p>“One of the things I’ve seen is that the more you go toward infrastructure as code, that could be in the DevOps system, but it’s for the platform team. You end up in this situation where they’re actually related and one is not necessarily killing the other.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud attacks rise but majority of sensitive data remains unencrypted ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cloud-attacks-rise-but-majority-of-sensitive-data-remains-unencrypted</link>
                                                                            <description>
                            <![CDATA[ Thales’ latest Cloud Security Report shows how managing and protecting data in the cloud is becoming an increasingly complex task for organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">px2xDLFgbnPStPMHtv4MJH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mBwh4N9qw7ibycfqL7Adw7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jul 2023 11:01:45 +0000</pubDate>                                                                                                                                <updated>Wed, 05 Jul 2023 14:38:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mBwh4N9qw7ibycfqL7Adw7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud attacks depicted by a digital mockup of a cloud floating above a circuitboard, all in a futuristic-looking colour scheme of neon blue, purple and yellow]]></media:description>                                                            <media:text><![CDATA[Cloud attacks depicted by a digital mockup of a cloud floating above a circuitboard, all in a futuristic-looking colour scheme of neon blue, purple and yellow]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud attacks depicted by a digital mockup of a cloud floating above a circuitboard, all in a futuristic-looking colour scheme of neon blue, purple and yellow]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mBwh4N9qw7ibycfqL7Adw7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Less than half of the sensitive data in organizations’ cloud environments is encrypted despite a continuous rise in attacks.</p><p>According to Thales’ latest report,  just 45% of sensitive data stored in the cloud is currently encrypted, despite 39% of respondents having experienced a breach in their cloud environment in the last 12 months, up 9% from the previous year. </p><p>Despite the increase in sensitive data being stored in the cloud, only a fifth (22%) of respondents reported that more than 60% of their sensitive data is protected with encryption.</p><p>The issues also extend to the control businesses have over their encryption keys, with only 14% stating they controlled all the keys to their data in their cloud environments. Additionally, nearly two thirds (62%) said they have five or more key management systems, which increases the overall complexity of securing their data.</p><p>The annual <a href="https://www.thalesgroup.com/en/worldwide/security/press_release/cloud-assets-biggest-targets-cyberattacks-data-breaches-increase" target="_blank"><u>report</u></a> surveyed nearly 3,000 IT and security professionals across 18 countries, examining the latest cloud security threats, trends, and emerging risks. </p><p>Concern for the security of sensitive data is elevated due to a considerable increase in the level of such data being stored in the cloud. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VAYyZGUoQS5jxhNwKer8sG" name="Prioritize zero trust_thumb.png" caption="" alt="Blue whitepaper cover with title" src="https://cdn.mos.cms.futurecdn.net/VAYyZGUoQS5jxhNwKer8sG.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Prioritize zero trust for better cloud security</strong></p><p class="fancy-box__body-text"><em>Working together to enable a zero trust approach</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/prioritize-zero-trust-for-better-cloud-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Three-quarters (75%) of businesses reported more than 40% of their stored data is classified as sensitive, compared to 49% of businesses just a year ago.</p><p>In terms of targets, more than a third (38%) ranked <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">software as a service (SaaS)</a> applications as the top target for attackers, followed by cloud-based storage (36%). Human error was reported as the leading cause of cloud data breaches by 55% of respondents.</p><p>The findings come at a time when the adoption of <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a> continues to snowball, with 79% of organizations now having multiple cloud providers.</p><p>“The study shows that organizations are operating in a dynamic multi-cloud landscape, demanding seamless and efficient access to on-demand IT infrastructure and services,” said Sebastien Cano, SVP for cloud protection and licensing activities at Thales.</p><p>In addition to infrastructure growth, the report also found that the use of SaaS apps is also seeing a significant uptick, with 22% of businesses now utilizing between 51 and 100 different SaaS applications – compared with 16% back in 2021.</p><p>It all adds up to increasingly complex challenges for businesses, with 55% stating that managing their data in the cloud is more complex than tackling on-premises environments. </p><p>A large proportion (83%) also expressed concerns over digital sovereignty, while 55% said data privacy and compliance in the cloud has become more difficult. </p><h2 id="improving-cloud-security">Improving cloud security</h2><p>Recommending next steps for vulnerable organizations, Thales highlighted <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>identity and access management (IAM)</u></a> as a “crucial measure” in mitigating breaches. </p><p>The firm’s report found that the adoption of robust <a href="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution"><u>multi-factor authentication (MFA)</u></a> is continuing to progress, with 65% of respondents now utilizing the technology. </p><p>Zero trust controls, however, are lagging somewhat, with just 41% of organizations having implemented them in their cloud infrastructure, and 38% using them within their cloud networks. </p><p>Thales said these factors shine a light on the need to adopt “comprehensive security measures” to effectively safeguard sensitive data and bolster overall resilience. </p><p>Consolidation of key management environments can provide increased operational control to scale up the use of encryption in a manner that security teams can tackle. </p><p>Businesses are also advised to take advantage of the “force-multiplying power of automation” to help reduce the risk of human error and bolster digital sovereignty compliance efforts. </p><p>“Treating cloud environments as an extension of existing infrastructure while maintaining exclusive control and security of data, especially sensitive data, is key to cloud security,” Cano said.</p><p>“Customer control of encryption keys is essential as it allows organizations to leverage the scalability, cost efficiency, and accessibility benefits of the cloud while ensuring the utmost integrity and confidentiality of their valuable information.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rubrik partners with Microsoft to drive generative AI-powered cyber recovery ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/rubrik-partners-with-microsoft-to-drive-generative-ai-powered-cyber-recovery</link>
                                                                            <description>
                            <![CDATA[ Rubrik Security Cloud will integrate with Microsoft Sentinel and Azure OpenAI to accelerate recovery from cyber attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LpcTqqaFxf82HwDjGAnVS8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jYWhBayTGsrCrUWDnNjSSi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jun 2023 11:06:19 +0000</pubDate>                                                                                                                                <updated>Mon, 03 Jul 2023 13:42:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jYWhBayTGsrCrUWDnNjSSi-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Rubrik logo appearing on a background of dark blue]]></media:description>                                                            <media:text><![CDATA[Rubrik logo appearing on a background of dark blue]]></media:text>
                                <media:title type="plain"><![CDATA[Rubrik logo appearing on a background of dark blue]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jYWhBayTGsrCrUWDnNjSSi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data security provider Rubrik has announced a new collaboration with Microsoft which aims to accelerate cyber recovery through generative AI and natural language processing (NLP). </p><p>Building upon Rubrik’s existing channel offering, the move will see Rubrik Security Cloud integrated with Microsoft Sentinel and Azure OpenAI Service to reduce the time required to investigate and determine responses to cyber incidents. </p><p>According to Rubrik Zero Labs’ <em>State of Data Security</em> <a href="https://www.rubrik.com/zero-labs" target="_blank"><u>report</u></a>, just 56% of IT and security leaders reported developing or reviewing an incident response plan in 2022, while security operations center (SOC) and incident response teams have become inundated with alerts each day, making prioritization time-consuming.</p><p>Rubrik and Microsoft say the new integrations will help SOC teams investigate the most pressing cyber events, as well as offer up remediation guidance.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bvmLpWwnDGsuH7nN6zDy2n" name="The right workload in the right cloud_listing.jpg" caption="" alt="Whitepaper cover with title over an image of a city with a lightning bolt shaped cloud above in the blue sky" src="https://cdn.mos.cms.futurecdn.net/bvmLpWwnDGsuH7nN6zDy2n.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The right workload in the right cloud</strong></p><p class="fancy-box__body-text">Understanding the challenges and the security considerations</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/the-right-workload-in-the-right-cloud"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“In a time when bad actors are becoming increasingly inventive, organizations must lean on AI to turn the tables on attackers,” said Charlie Bell, executive vice president of security, compliance, identity, and management at Microsoft. </p><p>“Working with Rubrik establishes a counterpoint to the modern threats that our customers are facing and allows organizations to react to incidents more quickly. </p><p>“Through the speed of AI, we believe security defenders will be able to identify and stop attacks faster than ever before.”</p><p>The development expands Rubrik’s existing integration with Microsoft Sentinel, which was announced back in October 2022. </p><p>Now, Rubrik says its platform’s ability to provide time series data insights directly into Microsoft Sentinel will enable organizations to tackle evolving <a href="https://www.itpro.com/security/malware/the-top-malware-and-ransomware-threats-for-june-2023"><u>cyber threats</u></a> and safeguard sensitive data.</p><p>Thanks to the new integration, Rubrik can now leverage large language models and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> through OpenAI to automatically create recommended task workstreams in Microsoft Sentinel. Security and IT teams will be able to streamline incident creation, <a href="https://www.itpro.com/business-strategy/automation/367382/hyperautomation-in-action-most-exciting-examples"><u>automate recommended task workstreams</u></a>, as well as accelerate overall cyber recovery.</p><p>Bipul Sinha, CEO and co-founder at Rubrik, said the explosion of generative AI will kick start a <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them"><u>new age of cyber attacks</u></a> that “go far beyond human comprehension”.</p><p>“We must fight fire with fire and use generative AI to not only understand future cyber events but to also prevent and defend against them,” he said. “We’re thrilled to collaborate with Microsoft and continue to build upon our progressive and long-standing partnership. </p><p>“This is an important step forward as we continue our mission of securing the world’s data and helping businesses achieve <a href="https://www.itpro.com/security/369055/gartner-most-businesses-are-dropping-security-vendors-to-improve-cyber-resiliency"><u>cyber resilience</u></a>.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malwarebytes bolsters reseller partner program with fresh incentives ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/malwarebytes-bolsters-reseller-partner-program-with-fresh-incentives</link>
                                                                            <description>
                            <![CDATA[ The revamped initiative aims to help partners generate profitable, consistent business growth and target specific vertical markets ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v9N78PTpUQGAwgtomEwbui</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pqgNcUerzdpWFUYNVYW9cd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Jun 2023 11:36:43 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:07:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pqgNcUerzdpWFUYNVYW9cd-1280-80.jpg">
                                                            <media:credit><![CDATA[Malwarebytes]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malwarebytes logo on blue background]]></media:description>                                                            <media:text><![CDATA[Malwarebytes logo on blue background]]></media:text>
                                <media:title type="plain"><![CDATA[Malwarebytes logo on blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pqgNcUerzdpWFUYNVYW9cd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security vendor Malwarebytes has announced a refresh of its reseller partner program, which combines its endpoint security technology with channel incentives such as base and multi-year discounts.</p><p>Designed to help partners create profitable and consistent business growth, the new program features three tiers: gold, silver, and bronze – with specific benefits for each level. </p><p>Those include margin discounts, protected margins on deal registration, lead sharing, NFR licenses, as well as access to market development funds (MDF). </p><p>The initiative also supports targeting specific verticals with specialized bundle solutions that Malwarebytes said will fulfill vertical needs and drive targeted engagement with a partner’s customer base.</p><p>“Today’s evolving <a href="https://www.itpro.com/security/369743/the-it-pro-podcast-surveying-todays-threat-landscape"><u>threat landscape</u></a> means that organizations are leaning on their partners to be their trusted IT advisors and <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> experts more than ever before,” said Jason Coville, chief sales officer at Malwarebytes. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MtPjjHSEfTqgo7yGoRaypN" name="Accessing the XDR realm_listing.jpg" caption="" alt="Whitepaper cover with title over an image of  XDR in a circle positioned in front of a dark cityscape" src="https://cdn.mos.cms.futurecdn.net/MtPjjHSEfTqgo7yGoRaypN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: WatchGuard)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Accessing the XDR realm</strong></p><p class="fancy-box__body-text"><em>A guide for MSPs to unleash modern security</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/accessing-the-xdr-realm"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“We believe it is critical to invest in and support our partners as they guide their customers to a more secure future. We are committed to providing our partners with cutting-edge security solutions that are easy to use, create growth, and provide fast time-to-value.”</p><p>Malwarebytes says its revamped reseller program offers competitive pricing and margins to help increase overall earnings potential with deal registrations, as well as additional margin and deal exclusivity on all new opportunities.</p><p>There’s also sales and technical training for Malwarebytes solutions, as well as a host of marketing resources such as co-branded collateral, a global campaign repository, and partner communications. </p><p>Partners can access these sales and marketing resources through the Malwarebytes Partner Experience Center (PXC) portal, where they can also register deals and provide customers with free trials.</p><p>The firm said the initiative will also benefit from mutual engagement, with partners able to provide input to help drive technology development, as well as future marketing and sales activities.</p><p>“At Malwarebytes, if it doesn’t work for our <a href="https://www.itpro.com/business-strategy/sustainability/369351/sustainability-now-number-one-focus-channel-partners"><u>channel partners</u></a>, it doesn’t work for us,” said Philip Walsh, Malwarebytes’ channel account sales leader for EMEA. </p><p>“Our new reseller program has many elements truly valuable for partners looking to create profitable and predictable businesses. We are focused on making Malwarebytes easy to buy, sell, deploy, and manage.”</p><p>Matthew Whitton, chief operating officer of Climb Global Solutions EMEA, a Malwarebytes partner, praised the security vendor’s channel revamp.</p><p>“The new reseller program is a testament to Malwarebytes’ ongoing prioritization of the channel,” he said. </p><p>“It offers many opportunities to grow our business, offer additional solutions to upsell and cross sell and gives my team the training and support they need to fully understand and advise customers.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Researchers uncover novel RDStealer malware targeting remote desktop protocol ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/researchers-uncover-novel-rdstealer-malware-targeting-remote-desktop-protocol</link>
                                                                            <description>
                            <![CDATA[ Bitdefender's experts said the level of disguise observed in this campaign “surpasses anything witnessed thus far” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K53G9Kqz62qKYdpDzyhBYB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o7aE2bbqGF7TeVESbqgZfb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Jun 2023 10:50:01 +0000</pubDate>                                                                                                                                <updated>Tue, 20 Jun 2023 15:34:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o7aE2bbqGF7TeVESbqgZfb-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[RDStealer: Mockup of brigtly coloured alert with code and a warning sign, reading &#039;malware&#039;]]></media:description>                                                            <media:text><![CDATA[RDStealer: Mockup of brigtly coloured alert with code and a warning sign, reading &#039;malware&#039;]]></media:text>
                                <media:title type="plain"><![CDATA[RDStealer: Mockup of brigtly coloured alert with code and a warning sign, reading &#039;malware&#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o7aE2bbqGF7TeVESbqgZfb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have uncovered a brand-new malware strain targeting Windows’ remote desktop protocol (RDP).</p><p>Experts at Bitdefender Labs revealed the newly discovered <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a><u> </u>today, dubbed RDStealer. </p><p>RDStealer takes the form of a server-side implant that monitors incoming connections with client drive mapping enabled.</p><p>Once connected, an <a href="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp"><u>RDP</u></a> client is infected with the Logutil malware, allowing data (including credentials and private keys) to be extracted.</p><p>The attack chain associated with RDStealer involves a typical DLL sideloading technique, but researchers observed that the level of disguise observed in this campaign “surpasses anything witnessed thus far”.</p><p>DLL sideloading takes advantage of how Windows locates libraries. An attacker might give a malicious binary the same name as a trusted DLL and drop it into the same folder, or high in the search order, as a trusted application. </p><p>When that application launches, the malicious binary is also launched.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nkJY2faZ4P9fjuCkSx3EiA" name="nkJY2faZ4P9fjuCkSx3EiA.jpg" caption="" alt="Whitepaper cover with image of female working remotely at a laptop on her sofa" src="https://cdn.mos.cms.futurecdn.net/nkJY2faZ4P9fjuCkSx3EiA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Unified Endpoint Management and Security in a work-from-anywhere world</strong></p><p class="fancy-box__body-text"><em>New ways to mitigate vulnerabilities and support threat detection</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369803/unified-endpoint-management-and-security-in-a-work-from-anywhere"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The attack features multiple DLL libraries chained together and the process is initiated through the utilization of the Windows Management Instrumentation (WMI).</p><p>The cross-platform nature of RDStealer represents an even more significant threat since both the RDStealer and Logutil malware samples have been written in the <a href="https://www.itpro.com/security/ransomware/361965/ransomware-rewritten-golang-to-target-windows-linux-users"><u>Go programming language</u></a>. </p><p>During an analysis of domains connected to the attack, researchers noted references to Linux and <a href="https://www.itpro.com/security/ransomware/vmwares-esxi-security-issues-spur-new-ransomware-gang-into-action"><u>ESXi</u></a> - the VMware hypervisor - indicating the multiplatform potential of the Logutil backdoor.</p><p>The attack itself appears more concerned with the theft of data and credentials, and used folders that were likely to be excluded by scanners such as %WinDir%\System32\. </p><p>Researchers also found malware in %WinDir%\security\database directory, where Microsoft has advised administrators to exclude specific files from scanning. </p><p>The findings suggest the attackers have anticipated administrators simply excluding the entire folder.</p><h2 id="rdstealer-how-does-the-attack-work">RDStealer: How does the attack work?</h2><p>RDStealer specializes in <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>data gathering, clipboard capturing, and keylogging</u></a>. </p><p>It also monitors incoming RDP connections and can compromise a remote machine if Client Drive Mapping (CDM) is enabled. </p><p>CDM is a commonly used feature and must be enabled at both the client and server ends. It permits users to access and transfer files between their local machine and the remote server via RDP and allows administrators to move files between a remote server and their admin workstation.</p><p>On a compromised machine, RDStealer collects clipboard data and keystrokes before checking the availability of tsclient connection and one of the C, D, E, F, G or H drives (automatically created when CDM is enabled and representing disks on the connected RDP client.)</p><p>Data is exfiltrated and the Logutil backdoor is deployed to both maintain a foothold in the victim’s network and provide capabilities such as file download/upload and command execution.</p><p>The abuse of WMI by this malware to establish persistence on the system is particularly unique. </p><p>The malware can be triggered by either the WMI service or host process and makes use of a library (ncobjapi.dll) that has previously been weaponized by other groups. </p><p>However, in this instance, the library is simply used to launch the Logutil payload as part of the sideloading chain.</p><h2 id="how-to-prevent-infection">How to prevent infection</h2><p>The research is a reminder that attacks will continue to get ever more sophisticated as tactics evolve, particularly with the move to remote work. </p><p>All virtual channels are capable of transferring data and can be weaponized, so administrators must consider exposed entry points and deploy automated protection controls.</p><p>And, as researchers note, “the best protection against modern attacks remains the defense-in-depth architecture”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Report: UK lags behind US in auditing code for security flaws ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/report-uk-lags-behind-us-in-auditing-code-for-security-flaws</link>
                                                                            <description>
                            <![CDATA[ The CTO of open source software firm SUSE suggested the US’ DevOps maturity can be attributed to the difference in aptitude ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iFfCvHH7eJQ7g8dsFJnfzQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5gPaRMAUcbUoDU6UJ54oTE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Jun 2023 10:10:04 +0000</pubDate>                                                                                                                                <updated>Tue, 20 Jun 2023 15:11:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5gPaRMAUcbUoDU6UJ54oTE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Programmer writing code on a laptop and second larger display]]></media:description>                                                            <media:text><![CDATA[Programmer writing code on a laptop and second larger display]]></media:text>
                                <media:title type="plain"><![CDATA[Programmer writing code on a laptop and second larger display]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5gPaRMAUcbUoDU6UJ54oTE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US is leading the tech industry in auditing codebases for security issues, with the UK reportedly lagging well behind.</p><p>Germany was also identified as one of the nations that was underperforming when it comes to code auditing, despite significant cyber security challenges across the industry.</p><p>The findings came from open source software firm SUSE’s latest report, showing a disparity in the way in which the nations see code auditing as an operational priority.</p><p>According to the report, nearly half (45%) of respondents in the US regard code audits as a priority, and invest accordingly, while only 23% and 26% of respondents in Germany and the UK respectively adopt the same attitude.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="j9SfGKiJe4VP7Gb4Ycon6D" name="Top data security trends_listing.jpg" caption="" alt="Whitepaper cover with cartoon character wearing digital armour stood in front of a bar/line graph with mobile phone featuring image of female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/j9SfGKiJe4VP7Gb4Ycon6D.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Salesforce)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Top data security trends</strong></p><p class="fancy-box__body-text"><em>Must-have tools for your data security toolkit</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/top-data-security-trends"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>SUSE’s global CTO Brent Schroeder said he believes that the US’ potentially more mature <a href="https://www.itpro.com/devops/28097/what-is-devops"><u>DevOps</u></a> environments could be an influential factor.</p><p>“The US being ahead is probably more about the maturity of the US with DevOps and <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important"><u>DevSecOps</u></a>,” Schroeder told <em>ITPro</em>.</p><p>Citing his experience with meeting customers, Schroeder said the importance of bringing the integration of security and security practices into the developer pipeline and notes that “companies, at least in the US, are really starting to embrace and recognize that”.</p><p>“If they don’t bring security into the process, they encounter one of two things: One is the speed and agility with which code is delivered is significantly diminished because near the end of the process they have to do checks for security.</p><p>“They do everything they can to do the integration as quickly as possible but then releasing new applications, major new features into a production environment, they’ve got to pause to check with the security team: does this pass all the audits and the requirements?</p><p>“Or else you deliver vulnerabilities at scale.”</p><h2 id="who-cares-about-source-code-audits">Who cares about source code audits?</h2><p>Being aware of what is in one’s software supply chain is critical. <a href="https://www.itpro.com/security/cyber-attacks/log4j-exploits-may-rise-further-as-microsoft-continues-war-on-phishing"><u>Recent security incidents </u></a>have demonstrated the importance of detecting, remediating, and monitoring <a href="https://www.itpro.com/security/28520/most-open-source-software-has-security-vulnerabilities"><u>vulnerabilities</u></a> in applications.</p><p>Across the US, Germany, and the UK, an average of 33% of respondents to the survey believed that goals on source code audits would be revised upwards, rising to 46% if one only considers software and network engineers, technical architects, and <a href="https://www.itpro.com/software/development/356827/how-to-become-a-developer-a-beginners-guide"><u>developers</u></a>.</p><p>95% also intended to review their software supply chain to increase security. This included 51% that had already done so, increasing to 68% of US-based respondents but going down to only 40% of those that are Europe-based.</p><h2 id="why-are-the-uk-and-germany-lagging">Why are the UK and Germany lagging?</h2><p>The difference in approach could potentially be attributed to governmental and regulatory approaches. </p><p>In the US, the M-22-18 memorandum set a deadline for compliance with the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF), SP 800-218, and the NIST Software Supply Chain Guidance.</p><p>The M-22-18 memorandum, dated 14 September 2022, set clear dates for US government agencies to adopt the requirements. </p><p>Ninety days were given for a software inventory, 120 days for a vendor communication process, and 270 days for attestation letters not posted publicly by software providers for “critical software”.</p><p>US companies keen to do business with government agencies must therefore ensure they comply with the NIST requirements, aimed at addressing software security and secure development practices.</p><p>The EU’s Network and Information Security (NIS) directive was the first piece of EU-wide legislation on cyber security but, as a briefing on <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive"><u>NIS2</u></a> in February 2023 noted, implementation proved difficult and resulted in fragmentation across member states.</p><p>NIS2 entered into force on 16 January 2023 and is set to be implemented in each member states’ national law by 17 October 2024.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Six generative AI cyber security threats and how to mitigate them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them</link>
                                                                            <description>
                            <![CDATA[ What are the risks posed by generative AI and how can businesses protect themselves? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UyaoyhhdDMPVDuWxHKUctT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U4MhnPA9zTWxjpZqWccBeS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Jun 2023 07:00:39 +0000</pubDate>                                                                                                                                <updated>Fri, 17 May 2024 15:28:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U4MhnPA9zTWxjpZqWccBeS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital brain coloured in red]]></media:description>                                                            <media:text><![CDATA[A digital brain coloured in red]]></media:text>
                                <media:title type="plain"><![CDATA[A digital brain coloured in red]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U4MhnPA9zTWxjpZqWccBeS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ChatGPT and competitors such as the recently-launched Google Bard have shot generative <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>artificial intelligence (AI)</u></a> into the mainstream. Allowing users to create, combine and remix content, <a href="https://www.itpro.co.uk/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> is hailed as a transformative technology for businesses. </p><p>As the use of generative AI grows, though, so do concerns about <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a>, because the technology has the ability to drive more targeted cyber attacks. Hackers can use generative AI to compose impactful <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing emails</u></a>, and the technology is making <a href="https://www.itpro.com/security/369243/real-time-deepfakes-are-becoming-a-serious-threat"><u>deepfakes</u></a> even more convincing.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">What is generative artificial intelligence (AI)?</a></p></div></div><p>Creating <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> is also easier with generative AI. In 2020, for example, researchers discovered a new type of malware called <a href="https://github.com/CyberWarefare/DeepLocker"><u>DeepLocker</u></a> that used generative AI to create unique obfuscation techniques, making it difficult for security tools to detect and block. </p><p>Attackers use off-the-shelf <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning"><u>machine learning</u></a> libraries and frameworks such as TensorFlow or PyTorch to create generative models, says Adam Blake, CEO and founder ThreatSpike Labs. “These tools are widely available and easy to use, which has lowered the barrier to entry for adversaries looking to use AI in their attacks.”</p><p>There are several types of generative AI, each with potential uses in cyber attacks. So what are the new risks posed by the different types of generative AI and how can businesses protect themselves as the technology develops?</p><h2 class="article-body__section" id="section-text-based-generative-ai-security-threats"><span>Text-based generative AI security threats </span></h2><p>Text-based generative AI such as ChatGPT helps make phishing attacks far more sophisticated and <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack"><u>difficult to spot</u></a>. “AI-enhanced campaigns could create highly personalized emails to enable <a href="https://www.ncsc.gov.uk/guidance/phishing"><u>spear phishing</u></a> at scale,” says Dane Sherrets, senior solutions architect at HackerOne.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRrgzsXGoa6Lpzkz6LcgbX" name="AI and cyber security_listing.jpg" caption="" alt="Purple whitepaper cover with white text over background image of suited female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/LRrgzsXGoa6Lpzkz6LcgbX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI and cyber security</strong></p><p class="fancy-box__body-text"><em>The promise and truth of the AI security revolution</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/ai-and-cyber-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Because text-based generative AI models are currently the most mature, experts say this type of attack will have the most impact in the near future. “They can be used to generate personalized phishing emails, or disinformation campaigns about an organization or individual,” adds Josh Zaretsky, partner at consulting firm Altman Solon.</p><p>Using text-based generative AI, interactive chat capabilities could be honed in the future to automatically target companies via their web chat services, says Matt Aldridge, principal solutions consultant at OpenText. </p><h2 class="article-body__section" id="section-video-based-generative-ai-security-threats"><span>Video-based generative AI security threats </span></h2><p>Further down the line, video-based <a href="https://www.bloomberg.com/news/articles/2023-03-20/generative-ai-s-next-frontier-is-video"><u>generative AI</u></a> such as Runway’s <a href="https://www.technologyreview.com/2023/02/06/1067897/runway-stable-diffusion-gen-1-generative-ai-for-video/"><u>Gen-1</u></a> could super-charge deep fake attacks to trick employees into transferring large amounts of cash to criminals. For example, an adversary could use video generation to create a deepfake of a company executive for social engineering attacks or to spread disinformation, says Blake. </p><p>Alternatively, he says, an attacker could use a video-generating model to create fake footage of a CEO instructing employees to transfer money or disclose sensitive information. Video models can be used to bypass facial recognition security measures in an identity-based attack, or impersonate company employees in spoofing attacks, according to Zaretsky. </p><h2 class="article-body__section" id="section-audio-based-generative-ai-security-threats"><span>Audio-based generative AI security threats</span></h2><p>Voice cloning is just one use for audio-based generative AI, and it’s easy to see how it could be used for nefarious means. An attacker could use audio-based systems to create a convincing voice phishing call that appears to be from a trusted source, such as a bank or credit card company, says Blake. “Alternatively, an attacker could use an audio-generating model to create a fake audio clip of a CEO instructing employees to take a specific action.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369004/art-is-on-its-knees-and-ai-will-deliver-the-killer">Art is on its knees – and AI will deliver the killer blow</a></p></div></div><p>Text-to-speech generative AI such as Microsoft’s new neural codec language model <a href="https://www.itpro.co.uk/technology/artificial-intelligence-ai/369857/microsofts-valle-cyber-crime-deepfakes">VALL-E</a> is able to accurately replicate a person’s voice using a combination of a text prompt and a short clip of a real speaker. Because VALL-E can replicate tone and intonation and convey emotion, voice clips produced using the model are very convincing.</p><p>The speed at which audio-based generative AI is developing is a major threat, according to Aldridge. “Audio fakes are a reality and the technology that makes them possible is improving at speed – we’ve seen huge developments in recent years, with computers creating conversations on their own.”</p><h2 class="article-body__section" id="section-image-based-generative-ai-security-threats"><span>Image-based generative AI security threats</span></h2><p>AI-generated images created by the likes of DALL·E 2 could also pose a major risk as the technology develops. </p><p>An attacker could use generative AI to create a convincing fake image or video that appears to show a company executive engaging in inappropriate or illegal behavior, for example. “The image or video could be used to blackmail or to spread disinformation,” says Blake.</p><h2 class="article-body__section" id="section-code-based-generative-ai-security-threats"><span>Code-based generative AI security threats</span></h2><p>As well as enabling less experienced attackers to create advanced malware, automated code generation by generative AI models can facilitate the bypass of traditional security tools, says Aldridge. Code-based generative AI tools include <a href="https://www.tabnine.com/"><u>Tabnine</u></a> and <a href="https://docs.github.com/en/copilot/overview-of-github-copilot/about-github-copilot-for-individuals"><u>GitHub Copilot</u></a>.</p><p>“It will do so by hiding malicious intent deeply within an otherwise benign application in an advanced trojan attack for example – in a similar way to how information can be hidden within an image using steganography.”</p><h2 class="article-body__section" id="section-combined-generative-ai-security-threats"><span>Combined generative AI security threats</span></h2><p>Adversaries can also combine different types of generative AI models to carry out more complex attacks. </p><p>For example, an attacker wishing their victim to perform a specific action could use a text-generating model to compose a convincing email; a video-generating model to create a fake video; and an audio-generating model to create a phony audio clip, Blake explains. </p><p>“This combined attack could be particularly effective because it leverages multiple forms of media to create a more transparent and compelling message.”</p><h2 class="article-body__section" id="section-how-to-mitigate-generative-ai-security-threats"><span>How to mitigate generative AI security threats</span></h2><p>Like any type of security threat, the risk posed by generative AI-based attacks is likely to evolve, making it integral that businesses are prepared. For now, it’s worth noting that security technology is not always able to spot and halt these attacks. </p><p>There are no known tools at this moment that can identify generative AI-derived attacks as “the modus operandi is to appear human-like”, says Kevin Curran, senior IEEE member, and professor of cyber security at Ulster University. He says the generation of realistic fake videos is particularly worrying.</p><p>With this in mind, businesses need to stay vigilant and adapt to new threats as they emerge, working closely with cyber security experts and technology providers, says Maher Yamout, senior security researcher at Kaspersky. He advises stringent authentication measures such as <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication (MFA)</u></a> to prevent unauthorized access.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53320039&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/370416/generative-ai-mark-zuckerberg-metaverse-in-the-dust">Generative AI has left the metaverse in the dust</a></p></div></div><p>Overarching this should be a strong strategy, taking into account the use of AI within the business. Introducing AI technology into the fabric of a business could be counterproductive if organizations fail to consider safety and security, says Sherrets. </p><p>As the threat posed by generative AI becomes more sophisticated, experts agree <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training"><u>training and education</u></a> are key. Sherrets advises businesses to bolster staff training around the latest methods of attack. “Humans will always be one of the easiest vectors for an adversary to exploit – organizations will do well to make sure their staff are educated about the new tools used by attackers.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyware cuts ribbon on new global partner program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/cyware-cuts-ribbon-on-new-global-partner-program</link>
                                                                            <description>
                            <![CDATA[ The CywareOne initiative aims to equip partners with “the tools they need to differentiate themselves in the market” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">owyny3Uz9GEKuGbUyoCkhN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u4dqPobeLPG8tKHTgEAPBC-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Jun 2023 09:59:15 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:07:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u4dqPobeLPG8tKHTgEAPBC-1280-80.jpeg">
                                                            <media:credit><![CDATA[Cyware]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyware logo on white background]]></media:description>                                                            <media:text><![CDATA[Cyware logo on white background]]></media:text>
                                <media:title type="plain"><![CDATA[Cyware logo on white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u4dqPobeLPG8tKHTgEAPBC-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security solutions provider Cyware is looking to grow its partnership with its channel and managed security (MSSP/MDR) partners through its new global partner program, CywareOne.</p><p>The fresh initiative will enable partners to provide customers with Cyware’s advanced threat intelligence automation, security advisory sharing, <a href="https://www.itpro.com/software/development/367576/low-code-vs-no-code"><u>low-code</u></a> vendor-agnostic SOAR, as well as cyber fusion technologies.</p><p>In an announcement, the firm revealed it has already partnered with several globally renowned cyber security providers to deliver security solutions, including GuidePoint Security, Ernst & Young, Optiv, Morado, and SHI.</p><p>"CywareOne represents a significant step forward in our commitment to developing strong partnerships with businesses that share our vision for a safer digital world," said Matt Courchesne, Cyware’s head of channel for North America. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MtPjjHSEfTqgo7yGoRaypN" name="Accessing the XDR realm_listing.jpg" caption="" alt="Whitepaper cover with title over an image of  XDR in a circle positioned in front of a dark cityscape" src="https://cdn.mos.cms.futurecdn.net/MtPjjHSEfTqgo7yGoRaypN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: WatchGuard)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Accessing the XDR realm</strong></p><p class="fancy-box__body-text"><em>A guide for MSPs to unleash modern security</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/accessing-the-xdr-realm"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>"Our new program will deliver the resources and support our partners need to succeed in the rapidly evolving cyber security landscape."</p><p>Cyware specializes in unifying threat intelligence, <a href="https://www.itpro.com/automation/33000/how-automation-can-help-digital-transformation"><u>automation</u></a>, threat response, and <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>vulnerability management</u></a> with a range of data insights. The company’s Cyber Fusion solution integrates SOAR and TIP technology to enable collaboration across siloed security teams. </p><p>The platform is deployed by enterprises, government agencies, and <a href="https://www.itpro.com/security/28879/what-is-an-mssp"><u>MSSPs</u></a> while providing threat intelligence-sharing platforms for the majority of information-sharing and analysis centers (ISACs) around the world.</p><p>With its new partner program, Cyware is now also offering various benefits to its partners, including comprehensive training programs, dedicated support, co-marketing opportunities, and competitive discounts.</p><p>CywareOne has been designed to streamline engagement and opportunity management while facilitating a high level of trust and transparency. </p><p>Ultimately, the aim is to equip partners with the skills and resources to effectively tackle clients’ cyber security issues.</p><p>The company said the program will create a thriving community of partners that are “united by their commitment to excellence”.</p><p>"We designed CywareOne with a clear goal in mind: to facilitate our partners&apos; success," said Amit Patel, SVP of sales at Cyware. </p><p>"We are committed to working collaboratively with our partners to deliver unrivaled cyber security solutions, providing them with the tools they need to excel and differentiate themselves in the market."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything you need to know about the latest Windows 11 updates - from bug fixes to brand-new features ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/windows/everything-you-need-to-know-about-the-latest-windows-11-updates-from-bug-fixes-to-brand-new-features</link>
                                                                            <description>
                            <![CDATA[ Two new cumulative updates are on the way and will be installed automatically on Windows 10 and Windows 11 machines ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Tc8Gakjv3ybjUkgZvac7m8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Jun 2023 11:11:01 +0000</pubDate>                                                                                                                                <updated>Thu, 15 Jun 2023 13:53:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:description>                                                            <media:text><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:text>
                                <media:title type="plain"><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has been busy in the past few days with a series of announcements and patches, including new features for the Windows Subsystem for Android and critical security updates.</p><p>We’ve listed some of the top features included in the new Windows 11 updates, including details of the latest vulnerabilities affecting devices that haven’t yet been updated.</p><h2 id="file-sharing-with-android">File sharing with Android</h2><p>Windows Insiders can now share files directly from their user folder to the Windows Subsystem for Android.</p><p>Windows Subsystem for Android allows users to run Android apps directly on their device, provided they are downloaded directly through the Amazon Appstore.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Y8zp3VtzSfMaNA32DY582d" name="Beat cyber criminals at their own game_thumb.jpg" caption="" alt="Red whitepaper cover with title and logo above circular images of colleagues using laptops, and servers" src="https://cdn.mos.cms.futurecdn.net/Y8zp3VtzSfMaNA32DY582d.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Beat cyber criminals at their own game</strong></p><p class="fancy-box__body-text"><em>A guide to winning the vulnerability race and protection your organization</em></p><p class="fancy-box__body-text"><strong>DOWNLOAD FOR FREE</strong></p></div></div><p>Much like <a href="https://www.itpro.com/operating-systems/microsoft-windows/369594/windows-users-can-now-run-linux-apps-and-distros-natively"><u>Windows Subsystem for Linux</u></a>, it negates the need for manual <a href="https://www.itpro.com/612016/what-is-virtualisation"><u>virtualization</u></a> and allows developers to debug Android APK files directly on their PC.</p><p>Apps must request file viewing and editing permission through a system dialog each time they are connected to a compatible device, and this can be revoked at any point. System folders and hidden folders are excluded from file sharing.</p><p>Microsoft also stated that potential threats from an app will be scanned and blocked via the user’s antivirus software, regardless of whether the app was installed through the Amazon Appstore or </p><p>A full release date for the feature has yet to be announced, but is expected in the near future.</p><p>Microsoft also stated that potential threats from an app will be scanned and blocked via the user’s <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">antivirus software</a>, regardless of whether the app was installed through the Amazon Appstore or another platform.</p><p>A full release date for the feature has yet to be announced, but is expected in the near future.</p><h2 id="june-2023-patch-tuesday-fixes">June 2023 Patch Tuesday fixes</h2><p>This month, Microsoft’s Patch Tuesday security release included a total of 94 patches, inclusive of 14 <a href="https://www.itpro.com/chromium/32681/what-is-chromium"><u>Chromium</u></a> flaws and five GitHub vulnerabilities.</p><p>Six critical vulnerabilities were included in this list, including three Windows Pragmatic General Multicast (PGM) vulnerabilities carrying near-maximum severity scores of 9.8 on the CVSS v3.1 scale. </p><p>The high severity scores were assigned because exploiting them could have led to remote code execution (RCE) via the Windows messaging queue.</p><p>The PGM vulnerabilities were tracked as CVE-2023-29363, CVE-2023-32014, and CVE-2023-32015 respectively.</p><p>Microsoft also patched a SharePoint vulnerability that could have allowed a threat actor to obtain administrator powers through privilege execution, tracked as CVE-2023-29357.</p><p>Unlike every Patch Tuesday for the past year, this month’s contained no zero-day vulnerabilities.</p><p>“This is the third month in a row where Patch Tuesday features at least one critical RCE in Windows PGM, and June adds three to the pile,” said Adam Barnett, lead software engineer at Rapid7.</p><p>“Microsoft hasn’t detected exploitation or disclosure for any of these, and considers exploitation less likely, but a trio of critical RCEs with CVSS 3.1 base score of 9.8 will deservedly attract a degree of attention.”</p><p>While Microsoft has not identified any of the vulnerabilities as having been exploited in the wild, there are some that have been highlighted as “exploitation more likely”, underlining the need to patch them as soon as possible.</p><h2 id="moment-3">Moment 3</h2><p>Windows has also dropped a fresh cumulative update for Windows 11 22H2 (KB5027231), which had been known under the codename ‘Moment 3’ prior to release.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TFnUJrhRdXSyWQooRpLFKn" name="Worldwide unified endpoint management services_listing.jpg" caption="" alt="Whitepaper cover with title and logo on blue header banner and analysis chart" src="https://cdn.mos.cms.futurecdn.net/TFnUJrhRdXSyWQooRpLFKn.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>IDC MarketScape: Worldwide unified endpoint management services</strong></p><p class="fancy-box__body-text"><em>2022 vendor assessment</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369801/idc-marketscape-worldwide-unified-endpoint-management-services"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>A significant feature of the update is a fix for 32-bit apps that use the CopyFile <a href="https://www.itpro.com/development/application-programming-interface-api/369956/the-it-pro-podcast-the-problem-with-apis"><u>API</u></a> and support the large address aware memory usage option. The error affected file copying and attachment in commercial and enterprise environments.</p><p>The update also comes with a number of quality-of-life improvements, including support for Bluetooth low energy (LE) audio and a new section in the settings menu for <a href="https://www.itpro.com/storage/22740/usb-vs-thunderbolt-which-is-better"><u>USB-4 and Thunderbolt</u></a> devices connected to a device.</p><p>Microsoft rolled out accessibility improvements within the release, including a fix that allows the narrator tool to correctly describe file attributes.</p><h2 id="even-more-features-in-a-cumulative-update">Even more features in a cumulative update</h2><p>In addition to KB5027231, Microsoft also rolled out another update named KB5027223 for Windows 10 21H2.</p><p>In addition to all of the patches from Moment 3, KB5027223 includes a number of other improvements such as general improvements for the taskbar search box.</p><p>The update fixes an error that prevented users from accessing the Server Message Block (SMB) shared folder, one that prevented the Local Security Authority Subsystem Service (LSASS) from working, and an audio issue affecting certain CPUs.</p><p>It also addresses a Windows kernel vulnerability that could have allowed attackers to view heaped memory from secure processes.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Log4J exploits may rise further as Microsoft continues war on phishing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/log4j-exploits-may-rise-further-as-microsoft-continues-war-on-phishing</link>
                                                                            <description>
                            <![CDATA[ Despite Log4J patches being made almost immediately in 2021, exploit attempts are still in the tens of millions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hxrXBRVjzFQXCEuyB4XCUG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y8abhoQWdvEHQQfbBgpqEn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 12 Jun 2023 10:45:58 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 11:32:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y8abhoQWdvEHQQfbBgpqEn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Log4J: Hacker&#039;s hand hovering over an illuminated MacBook keyboard - an image denoting hacking]]></media:description>                                                            <media:text><![CDATA[Log4J: Hacker&#039;s hand hovering over an illuminated MacBook keyboard - an image denoting hacking]]></media:text>
                                <media:title type="plain"><![CDATA[Log4J: Hacker&#039;s hand hovering over an illuminated MacBook keyboard - an image denoting hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y8abhoQWdvEHQQfbBgpqEn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have theorized that rising exploits of the critical vulnerability in Log4J could soon worsen as cyber criminals continue to find new ways around the ongoing implementation of Microsoft’s anti-phishing measures.</p><p>Introduced in 2022 after the IT community demanded it for years, Microsoft blocked the enablement of VBA macros in Office documents by default.</p><p>It meant that one of the leading methods of distributing malware via Office documents and phishing emails was effectively nullified - a major boon to defenders.</p><p>Since then, researchers at ESET have noticed a rise in exploits targeting the Log4J vulnerability across the world. </p><p>While the reason for the increase in attempts isn’t currently clear to researchers, the possibility that cyber criminals are looking for new ways to carry out attacks now phishing with malicious documents has become more difficult.</p><p>ESET’s researchers said that, while it’s just a theory, this rise may continue as cyber criminals look for effective ways to achieve their goals now one of their most favored tactics has been thwarted. </p><p>“If you look at the numbers globally, we have seen 166 million attacks [in 2022]... and in 2023, the numbers were going up by 13%,” said Ondrej Kubovič, security awareness specialist at ESET, about the latest data on Log4J exploit attempts.</p><p>“So, knowing that there are new systems being introduced with Log4J, and our statistics are showing this, then we can say that Log4J is still interesting for the attackers, and with VBA [macros] being closed down and OneNote being closed down, this might get worse.”</p><h2 id="the-latest-log4j-numbers">The latest Log4J numbers</h2><p>Despite <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability"><u>Log4Shell</u></a> not being as devastating as the community initially thought it would be, it remains highly exploited - the second-most used exploit method, according to ESET’s telemetry, behind password guessing.</p><p>The popularity of exploiting the vulnerability is also expected to increase not just because of Microsoft’s anti-phishing measures, but also because of the number of vulnerable downloads that are still made.</p><p>ESET said in its <a href="https://www.welivesecurity.com/wp-content/uploads/2023/02/eset_threat_report_t32022.pdf" target="_blank"><u>T3 2022 Threat Report</u></a> that as many as a quarter of all new Log4J library downloads are of the vulnerable version, even though patched and secure versions have been available since December 2021.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8Hych4XJRfHkUY47d64Qg8" name="State of ransomware readiness 2022_listing.jpg" caption="" alt="Whitepaper cover with red and white title over a black and white image of a businessman stood looking out of an office window" src="https://cdn.mos.cms.futurecdn.net/8Hych4XJRfHkUY47d64Qg8.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>State of ransomware readiness 2022</strong></p><p class="fancy-box__body-text"><em>Reducing the personal and business cost</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/state-of-ransomware-readiness-2022"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>IBM’s <a href="https://securityintelligence.com/articles/log4j-downloads-vulnerable/" target="_blank"><u>figures</u></a> paint an even darker picture, suggesting that nearly half (40%) are still vulnerable to the flaw that received a maximum 10/10 rating on the CVSSv3 severity scale.</p><p>In just the last seven days, 32% of Log4J downloads were of the vulnerable version, <a href="https://www.sonatype.com/resources/log4j-vulnerability-resource-center" target="_blank"><u>Sonatype’s data</u></a> showed.</p><p>As of September 2022, the number of blocked Log4J exploit attempts in the UK sat at 13.4 million, ESET said, roughly 12% of the global 166 million attempts. </p><p>This represented a 15% year-on-year increase, one that was generally in line with the figures for countries across the world.</p><p>Poland’s figures were amongst the highest out of any country in the world with a 30% increase in attacks. </p><p>ESET could not offer a definitive explanation for these markedly high attack attempts and neither could the Polish national computer emergency response team (CERT) after consulting with the security researchers.</p><p>Ukraine’s CERT issued <a href="https://cert.gov.ua/article/1751036" target="_blank"><u>an alert</u></a> at around this time warning of Russia’s changing tactics, favoring vulnerability exploits as opposed to attack techniques used earlier in the conflict, though a strong link between the nation’s activity and Log4J exploits in Poland has not been established.</p><h2 id="blocking-vba-macros-how-effective-has-it-been">Blocking VBA macros: How effective has it been?</h2><p>In the year since Microsoft rolled out the changes to Office documents, blocking VBA macros by default, data has shown a dramatic reduction in attacks.</p><p>Proofpoint’s <a href="https://www.proofpoint.com/sites/default/files/misc/pfpt-us-threat-research-2023-05-12-cybercrime-experimentation.pdf" target="_blank"><u>figures</u></a> from the back end of 2022 showed a 66% drop in macro-enabled attack attempts, a trend that continued through the first half of 2023 with macros “barely” making an appearance in campaign data.</p><p>“The cyber criminal ecosystem has experienced a monumental shift in activity and threat behavior over the last year in a way not previously observed by threat researchers, the security company said. </p><p>“Financially motivated threat actors that gain initial access via email are no longer using static, predictable attack chains, but rather dynamic, rapidly changing techniques.”</p><p>The findings in Proofpoint’s data were also corroborated by researchers at ESET in private media briefings.</p><h2 id="attackers-pivoting-to-onenote">Attackers pivoting to OneNote</h2><p>After Microsoft put an end to macro-enabled Office documents, attackers soon realized that the company’s note-taking app OneNote could be exploited in a similar way to how Word and Excel were before 2022.</p><p>An increase in attacks was reported by various security firms earlier this year involving OneNote files, which still allowed the embedding of various files in documents, including executables.</p><p>A typical scenario would see an email sent to a victim and attached to it was a mostly empty OneNote document. </p><p>Attackers would create a large text box reading ‘Click to open document’, or a similar message, but behind that text box would be a number of links to batch files that would be clicked and executed if the victim clicked on the text box, which only served to conceal the malicious buttons.</p><p>In some examples, a series of batch files would run, downloading other similar files and executing <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell"><u>PowerShell</u></a> code, ultimately leading to the installation of malware and essentially bypassing the <a href="https://www.itpro.com/security/cyber-security/368513/microsoft-confirms-vba-macro-backtrack-is-only-temporary"><u>blocking of VBA macros</u></a>. </p><p><br></p><p>An example <a href="https://www.fortinet.com/blog/threat-research/microsoft-onenote-file-being-leveraged-by-phishing-campaigns-to-spread-malware"><u>highlighted by Fortinet in March 2023</u></a> saw such an attack lead to the dropping of the AsyncRAT which was able to assume total control of a victim’s machine.</p><p>In the same month, Microsoft implemented enhanced security measures for OneNote, including more frequent and explicit warnings when opening potentially malicious files.</p><p>Weeks later, it also announced it would block 120 file extensions often used in malicious campaigns by default as an additional stand against <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> using its productivity software.</p><p>Now, fresh concerns have been raised around the introduction of the <a href="https://www.itpro.com/security/cyber-attacks/is-the-new-zip-top-level-domain-a-cyber-security-risk"><u>new top-level domains (TLDs)</u></a>.  </p><p>Cyber security experts have previously criticized the new additions, including the ones such as .zip, as these could be harnessed in campaigns, potentially making malicious links appear more legitimate than they really are.</p><p>ESET’s researchers told <em>ITPro</em> that while the current data doesn’t show a significant increase in attacks leveraging the new TLDs, they “understand the concern”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Arctic Wolf expands $1 million security operations warranty to Europe and ANZ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/arctic-wolf-expands-dollar1-million-security-operations-warranty-to-europe-and-anz</link>
                                                                            <description>
                            <![CDATA[ Qualifying customers now have access to fully underwritten financial assistance of up to $1 million in the event of a cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vqzBRxQvd5fwk8o5UTdvJd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HtMzNHSiMiAUAvku5ChTxa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jun 2023 10:02:42 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 10:47:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HtMzNHSiMiAUAvku5ChTxa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Arctic Wolf: Cyber security insurance and risk management mockup]]></media:description>                                                            <media:text><![CDATA[Arctic Wolf: Cyber security insurance and risk management mockup]]></media:text>
                                <media:title type="plain"><![CDATA[Arctic Wolf: Cyber security insurance and risk management mockup]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HtMzNHSiMiAUAvku5ChTxa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security operations provider Arctic Wolf has announced an expansion of its Security Operations Warranty to eligible customers in Europe, as well as Australia and New Zealand (ANZ). </p><p>The initiative aims to provide qualifying customers with fully underwritten financial assistance of up to $1 million, should they be on the receiving end of a major security incident. </p><p>It&apos;s available at no cost to both new and renewing customers that use the Arctic Wolf <a href="https://www.itpro.com/business-operations/managed-service-provider-msp/369416/msps-next-biggest-investment-will-be-in-mdr"><u>Managed Detection and Response</u></a> and other solutions to support incident response activities, legal and regulatory expenses, and other associated business costs that may arise from cyber attacks.</p><p>Dan Schiappa, chief product officer at Arctic Wolf, said the company is focused on delivering a “combination of effective security operations solutions and unique customer benefits” that will help organizations build business resilience.</p><p>"With the expansion of the Arctic Wolf Security Operations Warranty to Europe and ANZ, we continue to demonstrate our leadership in the security operations space and the confidence we have in the Arctic Wolf Security Operations Cloud, coupled with the third-party provider service benefits as part of the Security Operations Warranty, to detect and prevent successful cyber attacks across all threat surfaces," he said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uH2UFsZsWQr9xxCirTLXZP" name="More than a number_Your risk score explained_listing.jpg" caption="" alt="The back of two colleagues looking, and pointing at, a dual screen workstation in an office" src="https://cdn.mos.cms.futurecdn.net/uH2UFsZsWQr9xxCirTLXZP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>More than a number: Your risk score explained</strong></p><p class="fancy-box__body-text"><em>Understanding risk score calculations</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk/370277/more-than-a-number-your-risk-score-explained"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The move comes at a time when 40% of organizations currently lack comprehensive <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance"><u>cyber insurance</u></a>, the firm’s own research has found, while most businesses that do not have an active cyber policy believe it would not fully cover the <a href="https://www.itpro.com/security/data-breaches/368649/price-hike-for-consumers-as-data-breach-costs-rocket-to-all-time-high"><u>costs of a major cyber breach</u></a>.</p><p>In response, Arctic Wolf said it developed its Security Operations Warranty to help customers address their cyber risk gaps by automatically providing an additional layer of financial resilience.</p><p>The company revealed the warranty expansion as part of its Partner Jam event, which centers around its channel, alliance, and insurance partner community. </p><p>The Arctic Wolf Partner Program has grown to incorporate 1,300 partners around the world, with almost 200 of those located in EMEA and ANZ – including Arctic Wolf’s European Alpha Partner of the Year, medocino Hamburg GmbH. </p><p>“Many cyber security vendors claim to be able to be able to stop cyber attacks, but few are willing to stand behind their claims, which is what makes Arctic Wolf and their Security Operations Warranty such a disruptor for our industry,” said Stephan Beckmann, CEO at medocino.</p><p>“With their Security Operations Cloud, Arctic Wolf is addressing a real market need by making world-class security operations achievable for any business with the push of a button.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Deep Instinct appoints new channel chief for the Americas ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/deep-instinct-appoints-new-channel-chief-for-the-americas</link>
                                                                            <description>
                            <![CDATA[ Jim Ortbals will lead the firm’s channel operations in the region, Ryan Vaupel becomes vice president of operations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Zb8jMoWXcvSi9odyvBGir3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RmcjdmeyCgmizTWhhmJ5Fj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jun 2023 12:00:18 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 10:44:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RmcjdmeyCgmizTWhhmJ5Fj-1280-80.jpg">
                                                            <media:credit><![CDATA[Deep Instinct]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Deep Instinct company logo]]></media:description>                                                            <media:text><![CDATA[Deep Instinct company logo]]></media:text>
                                <media:title type="plain"><![CDATA[Deep Instinct company logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RmcjdmeyCgmizTWhhmJ5Fj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Prevention-first cyber security provider Deep Instinct has announced the appointment of Jim Ortbals as its new vice president of Americas channels, while Ryan Vaupel joins as vice president of operations.</p><p>As channel lead for the Americas, Ortbals will focus on driving adoption of the platform via the company’s Stratosphere Partner Program, supporting existing partners, and striking up new relationships. </p><p>He joins the company from Zscaler, where he led the firm’s global service provider, MSSP, and distribution routes to market, working with many of its top partners around the world. </p><p>Prior to that, he held various global channel and field sales leadership positions at industry multinationals such as VMware and Cisco, as well as late-stage startups such as Zerto.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7UJUnNNcf8UDfSzoPDK8Yc" name="The top five fists of perimeter firewalls_listing.jfif.jpg" caption="" alt="Whitepaper cover with title and logo on blue colour block next to man holding glasses and a smart tablet" src="https://cdn.mos.cms.futurecdn.net/7UJUnNNcf8UDfSzoPDK8Yc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The top five fists of perimeter firewalls</strong></p><p class="fancy-box__body-text"><em>...and the one way to overcome them all</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/the-top-five-fists-of-perimeter-firewalls"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>In an announcement, Ortbals said Deep Instinct’s channel partners and customers are “looking for innovation in cyber security” as opposed to more detection and response.</p><p>“The Deep Instinct Stratosphere Partner Program is bringing predictive prevention to our partners to lower risk for customers around the globe and the demand is growing,” he said. </p><p>“My focus is to develop our partner ecosystem and ensure they have the right tools and solutions to be successful.”</p><p>Ryan Vaupel also joins the business as vice president of operations, tasked with “laying the foundation for operation excellence,” Deep Instinct said.</p><p>With almost two decades of executive-level experience, Vaupel most recently served as senior vice president of global operations at ZIMPERIUM and held a similar leadership role at Zerto. </p><p>Deep Instinct said the appointment will add a combination of technology, enterprise sales, leadership, transformation, and operations expertise to the company.</p><p>“The status quo reactionary security model is failing to stop zero-day, <a href="https://www.itpro.com/security/malware/the-top-malware-and-ransomware-threats-for-june-2023"><u>ransomware</u></a>, and other unknown threats until after they are already inside an organization,” Vaupel said. </p><p>“Deep Instinct’s prevention platform provides organizations with a proactive security model that prevents threats before they can execute in an environment.</p><p>“I look forward to driving our organization at maximum operating efficiency to ensure we delight our customers, partners, and employees.”</p><p>Commenting on the appointments, Deep Instinct CEO Lane Bess said the industry is at a “tipping point” with the rise of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> promising to “broadly increase not only the velocity of attacks but also severity”.</p><p>“It is a wakeup call for organizations to focus their attention on prevention and the only way we get there is with the most sophisticated form of AI – <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370322/can-generative-ai-change-security"><u>deep learning</u></a>,” Bess added. “Jim and Ryan will both play an integral role for Deep Instinct during this time of immense growth.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security consolidation is about improving results, not just cost savings ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/security-consolidation-is-about-improving-results-not-just-cost-savings</link>
                                                                            <description>
                            <![CDATA[ Channel partners can play a key role in enabling businesses to consolidate security operations and bolster resilience ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HVExvNtPcxZxxpseyT3kBm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JiT3Ap3nyi8dqAUWbuxrF7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Jun 2023 11:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:45:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Matthew Middleton-Leal ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RA5TMT4SzkAwrdBagh9GAc.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JiT3Ap3nyi8dqAUWbuxrF7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock operating on the electronic circuit CPU]]></media:description>                                                            <media:text><![CDATA[Security padlock operating on the electronic circuit CPU]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock operating on the electronic circuit CPU]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JiT3Ap3nyi8dqAUWbuxrF7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The economy is in a difficult situation. ONS figures show that the UK economy grew by 0.1 percent in the first quarter of 2023 and the cost-of-living crisis continues to affect confidence. </p><p>While the technology sector has traditionally been able to weather tough conditions, that&apos;s not the case this time around. </p><p>Even areas like IT security are facing challenges. While Gartner predicted this market will <a href="https://www.gartner.com/en/documents/4019160" target="_blank"><u>continue to grow by 11.1% year-on-year</u></a> through to 2026, this increase in spending will have to be stretched further to keep pace with emerging threats. </p><p>CISOs are having to look at their strategies with fresh eyes in order to stretch budgets, including potentially consolidating the number of vendors they work with.</p><p>So what will these consolidation exercises look like, and how can channel partners capitalize?</p><h2 id="what-should-consolidation-mean-to-your-customers">What should consolidation mean to your customers?</h2><p>When we use the term consolidation, we typically mean cost-cutting. However, for security teams, the ability to reduce costs should not be conflated with decreasing budgets, which will ultimately leave teams without critical resources. </p><p>The challenge is how to make budgets go further and invest where companies need it, rather than this being an exercise in having money taken away.</p><p>Waiting until customers ask about this approach is too late. Instead, taking a proactive approach can put you - and your customer’s security team - in the driving seat when it comes to how projects are defined and what the success metrics are.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-the-channel-can-help-secure-the-future-of-work">How the channel can help secure the future of work</a></p></div></div><p>To get started, analyze how your customer manages their security processes and the products. It’s easy to build up shelfware that is either not being used, or only utilized for tasks that are not valuable enough to carry on spending on them. </p><p>These solutions can be removed and replaced with more cost-effective options, especially where other solutions can be used to cover the same tasks.</p><p>This may throw up some interesting findings. You may find yourself dealing with challenging scenarios and internal company politics. For example, you may find that processes are not as efficient as they could be, or that teams are relying heavily on manual work to get things done.</p><p>In a worst case scenario, you may uncover something that is not compliant with an industry standard or regulation. </p><p>It’s important to be tactful here, as security teams may have invested a lot of their time into building and evolving their processes. With anything that has been in place for a while, this can create a lot of attachment. While we all like to think of ourselves as rational beings, this is not always the case. </p><p>Taking a diplomatic approach can pay off as no-one likes to think of their deployment as wasteful.</p><h2 id="building-back-up-again">Building back up again</h2><p>Once you have established the tools, processes, and people involved in delivering security, you can assess the potential overlaps and where consolidation can occur. </p><p>Every vendor talks about the mythical single pane of glass for security, and you may find that customers have multiple ways of achieving this result. They may even be running multiple product suites for their security and risk management requirements, from identity management through to firewalls, <a href="https://www.itpro.com/security/369418/information-security-vs-cyber-security-vs-network-security"><u>network security</u></a>, and cloud.</p><p>From here, you can look at how to consolidate and improve security operations. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/building-channel-resilience-in-2023-and-beyond">Building channel resilience in 2023 and beyond</a></p></div></div><p>This may remove some tools, but the main goal should be to achieve better processes and faster delivery. Ideally, you can reduce the overall vendor count and make use of more integrated suites of services rather than multiple products. </p><p>This can make a big difference in cloud environments, where customers would otherwise have to run multiple agents to get the security services they need. Taking a ‘one agent’ approach reduces the overall amount of compute resources required to manage security services, which helps the customer save costs.</p><p>On top of this audit, you can move into recommending how best to consolidate and maintain security levels. For example, many companies will subscribe to a <a href="https://www.itpro.com/endpoint-security/30038/three-key-pillars-of-threat-visibility"><u>threat intelligence </u></a>feed, but do they make use of it? </p><p>Instead, can you supply a service that combines multiple feeds for better coverage while also offering recommendations on where to improve over time. This delivers an ongoing revenue opportunity while helping customers reduce their spending on specific security products.</p><p>Alongside this, explore ways  you can help the customer to automate their processes where possible. These efforts not only help the security team work faster and more efficiently, but it can show where there are ways to improve processes and working practices. </p><p>Security vendors are all deploying AI and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning]"><u>machine learning</u></a> to streamline processes, but this should also be used to free up focus time for security analysts.</p><h2 id="looking-for-more-opportunities-around-value">Looking for more opportunities around value</h2><p>While security consolidation projects may set out to cut costs, they might lead to other opportunities that you can build on. For instance, many companies now need more help in communicating their security position to their internal leadership teams or the board. </p><p>This calls for more risk management support, but it also requires nuanced communication support as well. It is not enough to <em>just </em>provide a dashboard – instead, you may need to help security teams <a href="https://www.itpro.com/security/information-security-infosec/370355/cyber-security-suffers-communication-problem"><u>work on how they communicate with leadership</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/how-the-channel-ecosystem-can-tackle-future-tech-shocks">How the channel ecosystem can tackle future tech shocks</a></p></div></div><p>Improving communication is a great secondary objective for consolidation projects. By cutting the number of tools involved, you can remove some of the headaches for security teams about getting the right data together. </p><p>On top of this, you can make it easier for them to demonstrate they are doing a good job.</p><p>Many companies need help on security consolidation projects. To maximize these opportunities, start by looking for overlaps and gaps. Once this audit is complete, you can make recommendations on how to reduce the number of vendors, integrate those that are in place, and make processes more efficient for everyone involved. </p><p>The result should save the company money, but it should also deliver better security posture for the future.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Change individual behavior to improve cyber security, says expert ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/change-individual-behavior-to-improve-cyber-security-says-expert</link>
                                                                            <description>
                            <![CDATA[ Organizations can deliver as much cyber security training as they want, but its value is limited unless it leads to actual behavior change ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vviBWPpsAb7wGvnQPWQXnS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6GmAUwkXyW5Jc2jmHzCqgM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 May 2023 15:19:15 +0000</pubDate>                                                                                                                                <updated>Tue, 30 May 2023 13:53:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6GmAUwkXyW5Jc2jmHzCqgM-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Oz Alashe speakign on stage at Dell Technologies World 2023]]></media:description>                                                            <media:text><![CDATA[Oz Alashe speakign on stage at Dell Technologies World 2023]]></media:text>
                                <media:title type="plain"><![CDATA[Oz Alashe speakign on stage at Dell Technologies World 2023]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6GmAUwkXyW5Jc2jmHzCqgM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations have been urged to place a greater focus on ensuring that the cyber security training they deliver is translated into actual behavior change among staff.</p><p>Leading cyber security experts and a career criminal addressed delegates at Dell Technologies World 2023, saying that raising cyber awareness across the business is not enough to enact useful change.</p><p>Oz Alashe MBE and CEO at risk management firm Cybsafe, veteran security journalist Kim Zetter, and famous former con artist Frank Abagnale all agreed that individual behavior can make or break an organization’s cyber posture.</p><p>Zetter used Mandiant’s Henna Parviz, a security analyst who spotted the first indicators of the Solarwinds attack.</p><p>It was Parviz who in November 2020 noticed a Samsung phone had been registered to an employee without a phone number, and that it had been used to log into the employee’s virtual private network (VPN) from a different state to where the employee was based.</p><p>What she had discovered was the first concrete clue of the <a href="https://www.itpro.com/security/cyber-attacks/361144/the-it-pro-podcast-behind-the-scenes-of-the-solarwinds-hack"><u>Solarwinds breach</u></a>, led by a standard security alert that Zetter stated a less-fresh, “more jaded” analyst may have disregarded entirely.</p><p>Alashe said that the main question that goes unasked in board rooms right now is: ‘Is what we’re doing working’ and noted that this also forces firms to consider what their goals are.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HuVkXKYxS9nVFkEwoBk7MR" name="HuVkXKYxS9nVFkEwoBk7MR.png" caption="" alt="Whitepaper cover with dark green corner graphic" src="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Don’t just educate: Create cyber-safe behaviour</strong></p><p class="fancy-box__body-text"><em>Designing effective security awareness and training programmes</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>He pointed to a need for small and medium businesses to feel motivated and empowered to take care of cyber security, and for large businesses to govern cyber security at a board level with the same clarity as other risks.</p><p>“It’s not knowledge vs behavior change, that’s not what I’m saying at all,” he told <em>ITPro</em>.</p><p>“What I’m saying is that knowledge doesn’t equal behavior change, and if we’re not changing behaviors we’re not reducing risk.”</p><p>“I know I shouldn’t eat as many packets of crisps as I do and I’m going to do it. If I’m going from A to B, I don’t want someone to teach me how to read a map, I want my phone to help me ‘go down the road and turn left’.</p><h2 id="ai-x2019-s-influence-on-cyber-security">AI’s influence on cyber security</h2><p>Alashe also pointed out areas of innovation that will demand a change in behavior from employees, such as the <a href="https://www.itpro.com/security/369243/real-time-deepfakes-are-becoming-a-serious-threat"><u>threat posed by real-time deepfakes</u></a> or <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a>.</p><p>Although <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370366/social-engineering-attacks-generative-ai-soar-135"><u>AI has driven a surge in social engineering attacks</u></a>, with text-generating chatbots such as ChatGPT or Bard allowing attackers to craft sophisticated emails, firms could also <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370337/organisations-soon-be-using-generative-ai-prevent-phishing"><u>use generative AI to protect against phishing</u></a>.</p><p>While <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning"><u>machine learning (ML)</u></a> algorithms can be used for positive processes such as identifying behavioral weaknesses, Alashe said this could also be turned on its head by attackers to better identify prime targets for social engineering.</p><p>It is in light of this that he has called for a focus on behavioral change over a purely educational approach to cyber security.</p><p>“It is a constant game of cat and mouse, this idea that we would get to a point of knowledge and education - or indeed behavior nirvana - is just not true,” said Alashe.</p><p>“Ultimately as technology evolves, and as criminals find new ways of using this technology to steal or gain access to things that they shouldn’t have access to, we will need to evolve the things that we do and the behaviors we exhibit to get around them.”</p><h2 id="perspectives-on-the-future-of-security">Perspectives on the future of security</h2><p>Abagnale stressed that criminals are the same as they have ever been, but are increasingly in possession of more sophisticated tools.</p><p>“What I did 50 years ago as a teenager is 4,000 times easier to do today, and with AI it will be 5,000 times easier in the next few years,” he said.</p><p>Despite the growing threat, Abagnale praised the growing trend of companies abandoning passwords for passkeys, as <a href="https://www.itpro.com/security/phishing/as-google-launches-passwordless-authentication-for-all-what-are-the-business-benefits-of-passkeys"><u>Google has done recently</u></a>.</p><p>All three speakers were also jointly optimistic about the potential for canny users and improved technology to bring down risk in the near future.</p><p>“There will come a time when virtually every single device considers the user, and the people using them, and therefore gives them the help and support they need,” Alashe said.</p><p>“We no longer have to rely just on training and education, we can actually give you the persistence and influence what they actually do. It’s a better and more scientific way to be, it’s a more data-driven way to be. And our people deserve it.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Building channel resilience in 2023 and beyond ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/building-channel-resilience-in-2023-and-beyond</link>
                                                                            <description>
                            <![CDATA[ Building a resilient, robust channel ecosystem could be key to weathering current economic trends ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aHxyj3CkYk6aR8u7h3V2PG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dFqDip9EuemFdcyNcg8By8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 May 2023 11:30:00 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:46:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ John Nolan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/JkBHKtWn4YhxiFZ8y6tpb8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dFqDip9EuemFdcyNcg8By8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Full length side view of young man climbing up on blue bar graphs against white background]]></media:description>                                                            <media:text><![CDATA[Full length side view of young man climbing up on blue bar graphs against white background]]></media:text>
                                <media:title type="plain"><![CDATA[Full length side view of young man climbing up on blue bar graphs against white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dFqDip9EuemFdcyNcg8By8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With a slew of tech giants announcing layoffs, the mood of the IT services market is cautious. Big investments and expansion plans are likely to be on hold, at least in the short term. </p><p>But while it’s easy to see all of the negative headlines and fear the worst, it’s also important to think long term. There are positive predictions for the year. <a href="https://www.gartner.com/en/newsroom/press-releases/2022-10-13-gartner-identifies-three-factors-influencing-growth-i"><u>Gartner</u></a> has predicted that the IT security market will grow over 11% in 2023, and it’s perhaps a mixed blessing that cyber criminals are keeping the security market buoyant. </p><p>Rather than panic, the channel should prepare, and focus on communicating the value of security to grow this part of their business.</p><h2 id="cultivating-a-resilient-ecosystem">Cultivating a resilient ecosystem</h2><p>Key to creating a compelling security offering is building an ecosystem - working with the right vendors with solutions that work together and can create sales opportunities. For example, email security and <a href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation"><u>endpoint security</u></a> are essentials that every customer needs, but these can be complemented with <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training"><u>security training</u></a> for users. </p><p>Email protection and user awareness together can protect a business far better than just email protection, but businesses will often only demand the first. It’s natural for them to assume that a technical solution will fix what they see as a technical problem. It may take time to educate users, but having the right solution will make this much easier.</p><p>Similarly, protection is vital, but there needs to be a backup plan - literally. <a href="https://www.itpro.com/data-loss-prevention/28864/data-recovery-why-is-it-so-important">Data loss prevention</a> is a critical addition to this suite of solutions that can be added later if the customer is not immediately convinced of its necessity.</p><p>The key is to create a jigsaw that can be slotted together all at once or completed over time, rather than a cacophony of overlapping products. Providers should be looking to create an integrated suite of vendors and solutions that will segue into complementary sales.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-the-channel-can-help-secure-the-future-of-work">How the channel can help secure the future of work</a></p></div></div><p>Channel partners should also embrace more of the solutions within existing vendor portfolios. Vendors have done a lot of the hard work in creating solutions where a need exists, and this should be taken advantage of. Just because a vendor is known for its <a href="https://www.itpro.com/private-cloud/29637/how-to-keep-applications-secure-in-a-private-cloud"><u>network firewalls</u></a>, that doesn’t mean it doesn’t offer worthwhile security solutions outside of this niche.</p><h2 id="build-a-foundation-and-find-areas-for-growth">Build a foundation and find areas for growth</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hcHuSq3S4kCsxdR2Stp96B" name="hcHuSq3S4kCsxdR2Stp96B.jpg" caption="" alt="Whitepaper cover with title and logo, and image of New York skyline" src="https://cdn.mos.cms.futurecdn.net/hcHuSq3S4kCsxdR2Stp96B.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>A guide to ESG reporting frameworks</strong></p><p class="fancy-box__body-text"><em>Guidelines to assist with your approach to ESG reporting</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/sustainability/370383/a-guide-to-esg-reporting-frameworks"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>It can be tempting to focus on the here and now, but building resilience means creating a foundation for future growth. It’s natural to say that you should repair the roof while the sun is shining, but that doesn’t mean the roof shouldn’t be repaired during inclement weather.</p><p>Even in straitened times it’s necessary to invest in the right training. This is true for sales people, it’s vital that they know exactly what they are selling, but also engineers. </p><p>Time needs to be allocated for learning and development, whether that’s gaining certification or learning through communities. </p><p>Staying resilient means customers have faith in the partner they work with. Firms will also be using this time to consider how they are spending their money and thinking about value.</p><p>But need will be a consideration, and so partners should be proactive in undertaking account reviews to accommodate businesses&apos; evolving needs.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bolstering-cyber-security-with-the-right-channel-partnerships">Bolstering cyber security with the right channel partnerships</a></p></div></div><p>Annual refresh cycles are a thing of the past with <a href="https://www.itpro.com/strategy/30003/is-it-worth-making-anything-in-the-service-as-a-service-world"><u>as-a-service products</u></a>, and there’s no need to wait a year to approach a customer and suggest a review if things have changed. By working with vendors that provide strong analytics and dashboard features, insights can not only preempt issues, but be used to upsell.</p><h2 id="partnerships-and-customer-success-xa0">Partnerships and customer success </h2><p>Not everything offered by a partner has to be delivered directly. By working with businesses offering complementary solutions then it’s possible to offer a more comprehensive service. This can be a stopgap until a service is brought in-house. </p><p>Either way, the point is to let the customer know we are a one-stop shop and can cover all their needs. </p><p>That’s important, as one of the key parts of resilience is understanding how important current customers are. We all know the old adage that winning a new customer costs ten times as much as retaining an existing one. Resilience means a sales team has to treat every customer as a potential lifetime partner and show that they are not forgotten once sold to. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/how-the-channel-ecosystem-can-tackle-future-tech-shocks">How the channel ecosystem can tackle future tech shocks</a></p></div></div><p>Ultimately, resilience means looking at where your business is healthiest and making sure that everything possible is done to make sure this aspect is supported, through sales, customer service, employee education and the right product suite.  </p><p>It may also be the right time to think about who your customers are - are you a generalist, or are you serving a niche market? </p><p>Targeting an audience, rather than limiting options for future sales, can increase resilience - there are benefits of more targeted sales material, a consolidated product suite, even better word of mouth as businesses talk to similar businesses.</p><p>Resilience is not a case of battening down the hatches and waiting the bad times out, it means being proactive. It means keeping up with changes that will keep a business going through the worst of times, and being prepared to take advantage of better times. </p><p>Most of all, it means looking to the long term as well as making short-term decisions - ”duck and cover” will only work for so long.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Do risk awareness and risk management strategies actually make a difference? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference</link>
                                                                            <description>
                            <![CDATA[ If cyber attacks are a matter of when, not if, it's tempting to ask whether risk awareness and risk management are effective ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HUHw8f89tHe7WPYLLjT26W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/whPJc65oQLRkoJomfojyEd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 May 2023 09:31:49 +0000</pubDate>                                                                                                                                <updated>Wed, 24 May 2023 16:51:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sandra Vogel ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/whPJc65oQLRkoJomfojyEd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several green locked padlocks surrounding one orange unlocked padlock]]></media:description>                                                            <media:text><![CDATA[Several green locked padlocks surrounding one orange unlocked padlock]]></media:text>
                                <media:title type="plain"><![CDATA[Several green locked padlocks surrounding one orange unlocked padlock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/whPJc65oQLRkoJomfojyEd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Risk awareness and risk management are crucial to safeguarding an organization’s assets from cyber attack, according to conventional wisdom. But how effective are these strategies if businesses are now told it’s not a matter of if, but when, <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach"><u>disaster strikes</u></a>? </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training">Our 5-minute guide to security awareness training</a></p></div></div><p>This “when, not if” theme arises again and again in modern <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> discourse – suggesting falling victim to cyber crime is an inevitability. Being targeted, and cyber criminals successfully pulling an attack off, are two different things, though. Risk management and <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training"><u>risk awareness</u></a> are both concepts designed to make life as difficult as possible for an attacker. </p><p>By an entire business engaging in the process of identifying and evaluating potential threats, they can offer organizations a certain base level of protection. While many might question whether these efforts – from not just the security teams – are worth the bother if an attack is ‘inevitable, they might keep organizations just on the right side of a serious incident.</p><h2 class="article-body__section" id="section-building-risk-appetite"><span>Building risk appetite</span></h2><p>Risk awareness and risk management are different things, explains EY’s UK&I government and public sector cyber security lead, Rick Hemsley.</p><p>“Whereas risk awareness refers to the proactive measures taken by organizations to educate their employees and stakeholders about potential <a href="https://www.itpro.com/security/cyber-security/360456/how-the-cyber-security-threat-landscape-is-changing"><u>cyber security risks</u></a>,” he says, “[risk] management centers around the identification, assessment, and mitigation of potential risks to a company.”</p><p>Within these two definitions lie many distinct actions and activities: some technical and some cultural. Among the most important is defining the organization’s risk appetite, ensuring this is understood across the organization, and making sure mitigations are in place that respond to risk appetite. </p><p>Risk appetite is a fundamental element of risk awareness and risk management. You can’t protect against everything. A person leaving their home in the morning might get their pocketbook stolen or there might be a water leak while they’re away. They can insure against loss of credit cards and water damage. But only if they’ve assessed the possibility, and put in place a mitigating strategy. They’ll do neither if they don’t think the risks are worth addressing – which is where risk appetite factors in.</p><h2 class="article-body__section" id="section-risk-awareness-is-essential"><span>Risk awareness is essential</span></h2><p>Risk awareness is arguably the most crucial aspect, says David Adams, Grc security consultant at Prism Infosec. “Risk management won’t be effective if risk awareness is not included as a strategy.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360456/how-the-cyber-security-threat-landscape-is-changing">How the cyber security threat landscape is changing</a></p></div></div><p>Staff entrusted with implementing controls will only live up to expectations if they understand why it’s important to the organization and aware of the risks of not acting. But risk awareness isn’t just something for the tech team to consider. It must be embedded in the thought patterns and working practices across the organization. </p><p>“The risk management strategy may well advise that personnel only work on encrypted personal applications, and in the risk awareness strategy this would be regularly communicated to staff but made relevant to them, perhaps in the form of awareness training,” explains Adams.</p><h2 class="article-body__section" id="section-can-we-measure-how-effective-risk-management-is"><span>Can we measure how effective risk management is?</span></h2><p>One of the issues around promoting risk awareness through an organization is it’s not always easy to measure. A risk management strategy of, say, using <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting"><u>threat analysis to identify attempted cyber attacks</u></a>, and showing which attacks are thwarted, can generate data used to demonstrate how effective these systems are and justify spending on them. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p7aA9ci4nXKjR9pXsMHoAN" name="Mapping the digital attack surface_thumb.png" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/p7aA9ci4nXKjR9pXsMHoAN.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Mapping the digital attack surface</strong></p><p class="fancy-box__body-text"><em>Why global organisations are struggling to manage cyber risk</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370166/mapping-the-digital-attack-surface"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>It’s more difficult to measure the effectiveness of risk awareness in this way. An organization can, howeer, test how well its people understand the various risks it’s identified, and measure how they implement approved behaviors. It can ealso nsure that strong systems are in place, for example by implementing a <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust framework</a> for technology. </p><p>Frequent and overt testing, as well as measuring people’s attitudes towards risk, can itself alienate staff, as can putting in place technology requirements that feel intrusive to actually getting work done. </p><p>The goal should be to guard the organization, not to corral its people. And, in any case, we can’t compare two real-world scenarios – with and without a strong risk awareness strategy in place – to quantify the effect of the strategy.</p><h2 class="article-body__section" id="section-does-risk-management-make-a-difference"><span>Does risk management make a difference?</span></h2><p>What organizations can do is be aware of the risks humans bring. Last year, the <a href="https://www3.weforum.org/docs/WEF_The_Global_Risks_Report_2022.pdf"><u>World Economic Forum (WEF)</u></a> said 95% of cyber security  issues could be traced to <a href="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity"><u>human error</u></a>. </p><p>Normalising appropriate behaviours can help an organization diminish the risk of human error by increasing awareness of the consequences of certain actions – or absence of certain actions. </p><p>The key is for the organization to ensure people feel part of the strategy, not that the strategy is foisted upon them. “A good risk awareness strategy helps create a security-conscious culture across the company, making it more resilient against attacks,” Hemsley tells <em>ITPro</em>. </p><p>Adams puts it another way: “Security is the responsibility of us all and people are now much more conscious of this fact. But when it comes to the individual, relevance is key. It’s vital to make the strategy meaningful to staff.”</p><iframe width="100%" frameborder="0" allow="encrypted-media" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/2znUT5UIPFAM1pGya83iwT"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/five-zero-trust-pitfalls-to-avoid">Why zero trust strategies fail</a></p></div></div><p>In the end risk awareness is a key component of how an organization handles the risks its exposed to. When the organization’s people are aware of these risks, and understand how their individual actions can help – or hinder – the organization in facing up to the very real prospect of attacks, they can play a part in mitigation. </p><p>When cyber attacks are a matter of when, not if, every possible strategy and mitigation that helps an organization deal with its appetite for risk is a strategy worth having, regardless of how much effort it might take to implement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rogue IT worker extorted company after hijacking ransomware attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/rogue-it-worker-extorted-company-after-hijacking-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ Liles’ involvement in the scheme was revealed after unauthorized email access was traced to his home address ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">inLzNr2YLCf32ZjYyvRzXH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wb7MoJ27V8eh4C6Wz8GW9Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 May 2023 08:59:51 +0000</pubDate>                                                                                                                                <updated>Thu, 25 May 2023 07:24:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wb7MoJ27V8eh4C6Wz8GW9Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract Technology Binary Code Dark Red Background]]></media:description>                                                            <media:text><![CDATA[Abstract Technology Binary Code Dark Red Background]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract Technology Binary Code Dark Red Background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wb7MoJ27V8eh4C6Wz8GW9Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An IT worker in the UK has been convicted of unauthorized computer access and blackmail after attempting to take advantage of a ransomware attack on his employer. </p><p>Ashley Liles was found to have attempted to blackmail his employer, Oxford Biomedica, into paying a ransom in the wake of a 2018 security breach. </p><p>In February that year, the Oxford-based company suffered a security incident that saw threat actors gain unauthorized access to the company’s computer systems. </p><p>Jurors at Reading Crown Court heard that, during an investigation into the incident, Liles commenced a secondary attack against the company. </p><p>“Liles began to investigate the incident, in his role as the company’s <a href="https://www.itpro.com/security/369418/information-security-vs-cyber-security-vs-network-security"><u>IT security</u></a> analyst and worked alongside colleagues and the police to try to mitigate the incident,” according to a statement from the South East Regional Organized Crime Unit (SEROCU).</p><p>“However, unknown to the police, his colleagues, and his employer, Liles commenced a separate and secondary attack against the company.”</p><p>Liles accessed board members’ private emails more than 300 times and altered the original ransom note to change the payment address to his own <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining"><u>cryptocurrency</u></a> wallet.  </p><p>Prosecutors said that Liles’ intention was that, if a payment was made, it would be made to him rather than the original attacker. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9dA5Tkp445uoybcjDEhAsT" name="The near and far future of ransomware business models_listing.jpg" caption="" alt="Rear facing image of man sat in dark tech lab using VR headset and gloves" src="https://cdn.mos.cms.futurecdn.net/9dA5Tkp445uoybcjDEhAsT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The near and far future of ransomware business models</strong></p><p class="fancy-box__body-text"><em>What would make ransomware actors change their criminal business models?</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370159/the-near-and-far-future-of-ransomware-business-models"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The security analyst was also found to have created an “almost identical” email address to the original <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> attacker and began pressuring his employer to <a href="https://www.itpro.com/security/ransomware/370132/paying-ransomware-gangs-fund-10-additional-attacks"><u>pay the ransom fee</u></a>. </p><p>However, no payment was ever made and the unauthorized access to private emails was discovered, revealing that the access came from Liles’ home address.</p><p>A subsequent investigation by police officers from SEROCU’s cyber crime team arrested Liles in 2018 and conducted a search of his home. </p><p>Although digital devices were seized in the raid, Liles was found to have wiped all data from his devices to cover up his involvement in the scheme. </p><p>“Items seized from his address included a computer, laptop, phone and a USB stick,” SEROCU said. </p><p>“Liles had wiped all data from his devices just days before his arrest in order to try to hide his involvement, however the data was recovered and this provided direct evidence of his crimes.”</p><p>Liles initially denied his involvement despite this evidence being found, and did not plead guilty for around five years. </p><p>He is set to return to Reading Crown Court for sentencing on 11 July.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ExtraHop now lets business leaders see how safely employees are using generative AI ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-protection/extrahop-now-lets-business-leaders-see-how-safely-employees-are-using-generative-ai</link>
                                                                            <description>
                            <![CDATA[ The Reveal(x) platform now provides insights into potential data leaks to help protect against misuse of AI tools such as ChatGPT ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">z4PdNukpkPRiorDoZW9jSF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ECqSLRa3EpxwcRcj9aZnqX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 May 2023 11:49:57 +0000</pubDate>                                                                                                                                <updated>Wed, 24 May 2023 08:39:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ECqSLRa3EpxwcRcj9aZnqX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI: neon blue human head (right-side profile) with particle overlay to denote AI]]></media:description>                                                            <media:text><![CDATA[AI: neon blue human head (right-side profile) with particle overlay to denote AI]]></media:text>
                                <media:title type="plain"><![CDATA[AI: neon blue human head (right-side profile) with particle overlay to denote AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ECqSLRa3EpxwcRcj9aZnqX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Businesses using ExtraHop’s Reveal(x) 360 can now gain visibility into employees’ use of generative AI tools, thanks to the latest update to the network detection and response (NDR) platform.</p><p>The cyber security provider said the functionality will better protect organizations against accidental misuse of AI tools, such as OpenAI ChatGPT, helping them to better understand their risk exposure and whether AI tools are being used in compliance with AI policies.</p><p>The move comes at a time when generative AI and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/355400/how-ai-as-a-service-is-changing-the-game-for-business"><u>AI as a service (AIaaS)</u></a> tools are being increasingly adopted across the enterprise in a bid to boost productivity. </p><p>However, despite its benefits, ExtraHop CEO Patrick Dennis said customers have “expressed a real concern” about employees sending proprietary data and other sensitive information into AI services.</p><p>“Until today, there has been no good way to assess the scope of this problem,” he said. “Amid the proliferation of AIaaS, it’s extremely important that we give customers the tools they need to see what is happening across the network, what data is being shared, and what could be at risk. </p><p>“With this new capability, our goal is to ensure that they can reap the wide-ranging benefits of generative AI while still maintaining data protections.”</p><p>AIaaS and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> tools have skyrocketed in recent times as users get to grips with the new technology. </p><p>Since its release in November last year, <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>OpenAI’s ChatGPT</u></a> alone has gone on to amass more than 1 billion users. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRrgzsXGoa6Lpzkz6LcgbX" name="AI and cyber security_listing.jpg" caption="" alt="Purple whitepaper cover with white text over background image of suited female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/LRrgzsXGoa6Lpzkz6LcgbX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI and cyber security</strong></p><p class="fancy-box__body-text"><em>The promise and truth of the AI security revolution</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/ai-and-cyber-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The key issues for organizations that implement these new AIaaS tools revolve around data leaks and intellectual property (IP) risk as employees input potentially sensitive and confidential information into them.</p><p>Once proprietary information has been shared, the service will continue to use that data to process future requests from other users, with the <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> being unlikely to understand the effects of re-using the data to which it has access.</p><p>Reveal(x)’s new functionality works by providing organizations with visibility into the devices and users on their network that are connecting to external AIaaS domains, as well as information on how much data is being shared with these services. </p><p>In some cases, the offering can also detail the type of data and individual files that are being shared.</p><p>The platform can do this through its use of network packets as the primary data source for monitoring and analysis, the firm said. </p><p>By using a real-time processor, it turns unstructured packets into structured wire data and analyzes payloads and content from OSI Layer 2-7 for complete network visibility. </p><p>“ExtraHop believes the productivity benefits of these tools outweigh the data exposure risks, provided organizations understand how these services will use their data (and how long they’ll retain it),” the company said in a <a href="https://www.extrahop.com/company/blog/2023/detecting-data-leaks-from-chatgpt-and-generative-ai-tools-with-reveal-x/" target="_blank"><u>blog post</u></a>.</p><p>“And provided organizations not only implement policies governing use of these services but also have a control like Reveal(x) in place that allows them to assess policy compliance and spot risks in real time.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Inside the platform propping up the next generation of email crime ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/inside-the-platform-propping-up-the-next-generation-of-email-crime</link>
                                                                            <description>
                            <![CDATA[ Cyber criminals are flocking to BulletProftLink for additional protections as business email compromise surges ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QYkkUoCiJ6eCepMBSqAwY7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DhCuUCKmYpJZLZNejqvrd4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 May 2023 11:41:34 +0000</pubDate>                                                                                                                                <updated>Wed, 24 May 2023 08:37:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DhCuUCKmYpJZLZNejqvrd4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[BulletProftLink: Email security multicoloured mockup image]]></media:description>                                                            <media:text><![CDATA[BulletProftLink: Email security multicoloured mockup image]]></media:text>
                                <media:title type="plain"><![CDATA[BulletProftLink: Email security multicoloured mockup image]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DhCuUCKmYpJZLZNejqvrd4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A years-old malicious platform is being used at a vastly accelerated rate by cyber criminals to launch “industrial-scale” email attacks on businesses.</p><p>Microsoft publicized the rapid adoption of platforms such as BulletProftLink in a report on Friday, saying the tools are being widely used to carry out highly sophisticated business email compromise (BEC) attacks.</p><p>These platforms offer cyber criminals a full-service toolkit for launching BEC attacks, including legitimate-looking email templates, hosting, and automated services for launching attacks.</p><p>Microsoft’s report noted the rising adoption of BulletProftLink and its ilk is offering new ways for the underground industry to successfully monetize cyber crime as a service (CaaS).</p><p>The company’s Digital Crimes Unit said it has observed a 38% increase in CaaS attacks targeting business email specifically between 2019 and 2020.</p><h2 id="how-does-bulletproftlink-work">How does BulletProftLink work?</h2><p>There are a number of unique capabilities that make attacks that are being carried out using BulletProftLink’s tools difficult to dissect.</p><p>The most notable of these is a trend in attackers evading impossible travel detections.</p><p>Many security products have detections for impossible travel that can often identify and neutralize accounts that have been compromised by cyber criminals.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5oSR5wUojQyhSYa8GwDH7K" name="State of Email Security 2023_listing.jpg" caption="" alt="Black whitepaper cover with strapline and image of man's face overlaid looking in different directions" src="https://cdn.mos.cms.futurecdn.net/5oSR5wUojQyhSYa8GwDH7K.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The state of email security 2023</strong></p><p class="fancy-box__body-text"><em>Cyber risk commands the C-Suite&apos;s focus</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/the-state-of-email-security-2023"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>An organization will be aware of the IP addresses used by its office-based workers and those working remotely.</p><p>If one worker is known to log in from London regularly, or did log into their account from a London-based IP address one morning, but one hour later logged into the same account from a Hong Kong-based IP address, for example, that would trigger an impossible travel detection.</p><p>Security teams would then typically investigate the case knowing a potential cyber attack is taking place. </p><p>That worker could not travel between the two cities in that time frame, meaning some malicious activity is likely occurring.</p><p>Armed with BulletProftLink, attackers purchase IP addresses from residential IP services that match their target’s location. </p><p>After creating residential IP proxies localized to their victim’s location, attackers can then launch attacks, masking their real location and avoiding any impossible travel detections.</p><p>“Residential IP addresses mapped to victim locations at scale provide the ability and opportunity for cyber criminals to gather large volumes of compromised credentials and access accounts,” said Microsoft in its Cyber Signals report. “Threat actors are using IP/proxy services that marketers and others may use for research to scale these attacks.</p><p>“One IP service provider, for example, has 100 million IP addresses that can be rotated or changed every second.”</p><p>BulletProftLink also goes a step further from the go-to phishing as a service platforms many cyber criminals flock to, such as Evil Proxy, Naked Pages, and Caffeine. </p><p>All of these platforms offer attackers the capabilities to launch phishing attacks at scale using compromised credentials, but BulletProftLink uses <a href="https://www.itpro.com/security/28031/what-is-blockchain"><u>blockchain</u></a> for its hosting.</p><p>This decentralized gateway design, Microsoft said, allows the platform to host phishing and BEC websites in a decentralized way, making it considerably more difficult to disrupt.</p><p>Typically, Microsoft and other web security organizations could track and locate the origin of malicious content and take steps to remove the source from the internet.</p><p>While each individual <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> link can either be blocked or taken down, tracking down the source on a public blockchain is much more challenging than a typical web2-hosted campaign.</p><h2 id="why-is-bec-such-a-threat">Why is BEC such a threat?</h2><p>BEC is a type of phishing attack that targets a specific individual, usually a high-ranking worker at an organization with the authority to make large financial transfers</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yGo7GQeyHmJHDfJa7iRGqc" name="Security awareness training strategies_listing.jpg" caption="" alt="Whitepaper cover with title on dark blue block and red and green coloured copy below" src="https://cdn.mos.cms.futurecdn.net/yGo7GQeyHmJHDfJa7iRGqc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Security awareness training strategies for account takeover protection</strong></p><p class="fancy-box__body-text"><em>Why you need an inside-the-perimeter strategy for internal threats</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/internet-security/359469/security-awareness-training-strategies-for-account-takeover"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The aim of the attacks is to convince that high-ranking individual to transfer funds into a seemingly legitimate account that’s actually controlled by the cyber criminals.</p><p>Microsoft’s telemetry indicates that there were 35 million <a href="https://www.itpro.com/security/34177/unfortunately-compromising-business-email-accounts-is-much-easier-than-you-might"><u>BEC attack</u></a> attempts last year, equating to 156,000 a day.</p><p>BEC can also lead to the distribution of malware in the form of email attachments. Such malware, as well as convincing email chains without the use of malware, can lead to sensitive or personally identifiable information (PII) being leaked and later used for follow-up scams or extortion. </p><p>“BEC attacks stand apart in the cyber crime industry for their emphasis on <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370366/social-engineering-attacks-generative-ai-soar-135"><u>social engineering</u></a> and the art of deception,” Microsoft said. </p><p>“Instead of exploiting vulnerabilities in unpatched devices, BEC operators seek to exploit the daily sea of email traffic and other messages to lure victims into providing financial information, or taking a direct action like unknowingly sending funds to money mule accounts, which help criminals perform fraudulent money transfers.”</p><p>The prevailing fear is that attacks are not only getting more sophisticated and more frequent, but tools like BulletProftLink are allowing for such attacks to be performed at greater scales, increasing the difficulty involved in detecting and disrupting them.</p><p>Microsoft’s recommendations are to maximize <a href="https://www.itpro.com/security/national-cyber-security-centre-ncsc/367628/ncsc-unveils-email-security-checking-tool"><u>email security</u></a> settings. Flagging all messages from external parties, enabling notifications for unverified senders, and blocking senders with identities that can’t be verified. </p><p>Lowering the risk tolerance for impossible travel can also help. It’s not uncommon for workers to take their devices and work from a coffee shop at some point during the day, for example. </p><p>Such a trip could be allowed under standard configurations but given the rise in these attacks, it could make sense to restrict movement even further from the main working location.</p><p>Enabling strong authentication such as <a href="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution"><u>MFA</u></a> or passwordless <a href="https://www.itpro.com/security/phishing/as-google-launches-passwordless-authentication-for-all-what-are-the-business-benefits-of-passkeys"><u>passkeys</u></a> can make compromising email accounts much more difficult for attackers and is seen as a must-have security measure for all sizes of organizations. </p><p>Training employees to spot these kinds of attacks can also be beneficial, leading to manual flags that can then be triaged by the IT admin or security team.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The rise of identity-based cyber attacks and how to mitigate them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them</link>
                                                                            <description>
                            <![CDATA[ If identity-based cyber attacks are successful, they can give hackers the opportunity to infiltrate an entire network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Dmdzt3Pb6T2ghHcUFX3EiF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 May 2023 08:20:49 +0000</pubDate>                                                                                                                                <updated>Tue, 09 May 2023 08:46:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sandra Vogel ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based cyber attacks]]></media:description>                                                            <media:text><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based cyber attacks]]></media:text>
                                <media:title type="plain"><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based cyber attacks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Identity-based cyber attacks are an increasing weapon of choice the more we work in a world increasingly reliant on identity-based authorization. This means, in essence, <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>stealing or faking our passwords</u></a> or other login credentials. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackershttps://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">The top 12 password-cracking techniques used by hackers</a></p></div></div><p>In response, organizations are adding new layers of authentication, which, inevitably, cyber criminals work to find ways through or around. In this <a href="https://www.itpro.com/security/cyber-security/368087/cyber-security-companies-must-remember-who-the-enemies-are"><u>cat-and-mouse game</u></a>, identity-based attacks are on the rise, and organizations must implement several measures to defend themselves from these.</p><h2 id="identity-based-cyber-attacks-are-a-growing-threat">Identity-based cyber attacks are a growing threat</h2><p>Hacking into computer systems is as old an activity as computer systems themselves. But the <a href="https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management"><u>attack surface</u></a> is wider than ever before; there are more systems around, <a href="https://www.itpro.com/solid-state-storage-ssd/31387/what-the-future-holds-for-data-storage"><u>storing more data</u></a> about individuals and organizations, offering more potential for exploitation. </p><p>“With so much more personal information now online, companies, institutions, infrastructure, and even democracies are being maliciously targeted by actors wishing to exploit it,” Del Heppenstall, partner and head of cyber at KPMG in the UK tells <em>ITPro</em>.</p><p>It’s <a href="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity"><u>people that are most often the source</u></a> of a data breach. The 2022 <a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank"><u><em>Verizon Data Breach Investigations Report</em></u></a> found 82% of data breaches involve the “human element”. That human element can be through sheer malevolence, such as <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one"><u>social engineering attacks</u></a>, of course. But more often than not, it’s a simple incident of human error, such as people falling prey to fake SMS messages, succumbing to a <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> exercise, or <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022"><u>reusing common passwords</u></a> across personal and professional logins. Mistakes are inevitable – after all, we are only human – which is why <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust strategies</u></a> are important. </p><p>“Adversaries can easily launch high-volume password spraying where they only need to be right once out of millions of attempts,” former BP CISO, Simon Hodgkinson, says. “Similarly, with <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas"><u>high-volume phishing attacks</u></a>, all it takes is one person to click on the link and provide their credentials. The defenders on the other hand need to be right 100% of the time.”</p><h2 id="guarding-against-the-inevitable">Guarding against the inevitable</h2><p>Not only do the attackers really know their business, they’re pushing hard and faster. The <a href="https://www.microsoft.com/en-us/security/business/security-insider/threat-briefs/anatomy-of-a-modern-attack-surface/" target="_blank"><u><em>Microsoft Digital Defense Report 2022</em></u></a> notes the volume of password attacks has risen to an estimated 921 attacks every second. That’s a 74% increase in just one year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">The rise of phishing as a service (PhaaS) and how to tackle it</a></p></div></div><p>So what is an organization to do? Hodgkinson tells <em>ITPro</em>: “One must be pragmatic. Cyber risk cannot be eradicated. Organizations can only put in place mitigations aligned to their risk appetite and have robust response plans in place. Every organization should assume that they will be compromised at some point.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YssANqmxxS4hiCype5M99b" name="Anatomy_of_Identity_Based_Attacks_listing.jpg" caption="" alt="Image of female and male colleagues looking at a computer" src="https://cdn.mos.cms.futurecdn.net/YssANqmxxS4hiCype5M99b.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Anatomy of identity-based attacks</strong></p><p class="fancy-box__body-text"><em>Helping security teams mitigate identity-based attacks</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/anatomy-of-identity-based-attacks"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>In this context, organizations must put security front and center. For Heppenstall, the security-first approach that most organizations now take can be strengthened by moving to an identity-focused approach. </p><p>He mentions features like least privilege, enhanced monitoring, threat analytics and controls, the establishment of communications guidelines both internally and with external entities and individuals, and continuous validation of end-users including internal, contractors, and third parties. He also suggests “keeping proactive and reactive risk management capabilities around identity and access management, then integrating it with business and security needs will be key to handling threats”.</p><h2 id="taking-a-nuanced-approach-to-tightening-the-net">Taking a nuanced approach to tightening the net</h2><p>For Kevin Curran, IEEE senior member and professor of cyber security at Ulster University, organizations can fall short if they don’t understand the difference between <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>identity management</u></a> and authentication. </p><p>It’s crucial to “establish how roles are identified in a system and how they are assigned to individuals”, he tells <em>ITPro</em>. This means “security teams need to pay attention when removing, adding, and updating individuals alongside their roles in a system”. </p><p>“There needs to be a sensible allocation of levels of access to individuals or groups of individuals,” he continues. “Only then can security teams assume that they have established a ‘foundation’ of protecting the sensitive data within the system and securing the organization itself.”</p><p>Best practice isn’t only about technology: there are <a href="https://www.itpro.com/security/cyber-security/370285/can-we-ever-achieve-cyber-security-buy-in"><u>cultural and process factors to take into account</u></a> too. Hodgkinson gives <em>ITPro</em> a strong example of how cultural shift has helped other industry sectors with different issues.</p><p>“The airline and oil and gas industries dramatically improved safety by embracing a culture of ‘speak up’,” he explains. “When there was an accident or a near miss, people were encouraged to share. This led to a culture of continuous improvement in safety. A similar approach is required in cyber – let’s encourage people to report and share their learnings.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370285/can-we-ever-achieve-cyber-security-buy-in">Can we ever achieve cyber security buy-in?</a></p></div></div><p>What would this look like in practice? “If one user clicked on a phishing link, they should share why so others learn from it,” he adds. “This will require organizations to positively support employees who have made a mistake.”</p><p>All in all, it would seem that organizations must accept the inevitable and assume attacks will happen. They must also understand that their best mitigation is not solely a matter of best technology practice. It’s also about organizational culture, accepting that people are fallible, and providing a culture of support and learning in that context.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why zero trust strategies fail ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/five-zero-trust-pitfalls-to-avoid</link>
                                                                            <description>
                            <![CDATA[ Zero Trust is the gold standard for organizations in protecting systems from cyber attacks, but there are many common implementation pitfalls businesses must avoid ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BL5vEydYUKbCiZEKFHDJZi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D6ZFS3xgHqChAfbizUojYN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 May 2023 07:00:24 +0000</pubDate>                                                                                                                                <updated>Fri, 05 May 2023 08:44:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sandra Vogel ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D6ZFS3xgHqChAfbizUojYN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A shot of a woman sat at her desk in a dimly lit office, with her eyes closed and a stressed expression on her face, her hands raised to massage her temples. In the foreground, blue code is rising to either side of the frame to indicate complexity in the task that her unseen screen is showing]]></media:description>                                                            <media:text><![CDATA[A shot of a woman sat at her desk in a dimly lit office, with her eyes closed and a stressed expression on her face, her hands raised to massage her temples. In the foreground, blue code is rising to either side of the frame to indicate complexity in the task that her unseen screen is showing]]></media:text>
                                <media:title type="plain"><![CDATA[A shot of a woman sat at her desk in a dimly lit office, with her eyes closed and a stressed expression on her face, her hands raised to massage her temples. In the foreground, blue code is rising to either side of the frame to indicate complexity in the task that her unseen screen is showing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D6ZFS3xgHqChAfbizUojYN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zero trust strategies are one in which nothing and nobody can use an organization’s digital resources without being verified. This isn’t just about verification upon entry into the system, but also when individuals are moving around within the system.</p><p>Such a strict regime is required because a cyber criminal or an automated agent might breach a system and move about freely within it if, once inside, there were no verification checks. <a href="https://www.itpro.co.uk/security/network-security/358282/what-is-zero-trust"><u>Zero trust</u></a> has, therefore, become a gold standard for <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> in today’s enterprise landscape. </p><div  class="fancy-box"><div class="fancy_box-title">More on zero trust</div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">What is zero trust?</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model">How to build a zero trust model</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/366925/four-key-benefits-zero-trust-can-bring-to-your-channel-firm">Four key benefits zero trust can bring to your channel firm</a></p></div></div><p>Implementing zero trust requires a root and branch examination of the entire technology estate. The organization needs to identify its vulnerabilities, both technological and human, and figure out <a href="https://www.itpro.co.uk/security/cyber-security/368543/six-cyber-security-holes-you-need-to-plug-now"><u>how to best plug the holes</u></a>. This should be done in the context of minimal disruption to everyday workload, and an understanding that zero trust is not a one-time fix but an evolving idea. </p><p>Implementing such a regime, however, isn’t without its potential pitfalls and pain points. It’s a time-consuming and complex process that requires input from many roles across the organization, as well as external expertise. </p><h2 id="1-failing-to-look-beyond-the-corporate-network">1. Failing to look beyond the corporate network</h2><p>When hybrid working is the norm, people will be using all manner of locations to work including their homes and public networks. Everything is part of the <a href="https://www.itpro.co.uk/security/cyber-security/369983/what-is-attack-surface-management"><u>attack surface</u></a> and the organization should trust nothing. Every endpoint is a potential vulnerability. </p><p>This also, by the way, includes devices that might sit outside the network such as printers, security cameras, and other <a href="https://www.itpro.co.uk/cloud-computing/28037/what-is-iot"><u>Internet of Things (IoT)</u></a> devices.</p><p>A thorough audit of devices will be required before work begins, with a strategy in place to protect each device and to ensure that each device is updated as regularly as needed. </p><h2 id="2-implementing-zero-trust-too-quickly">2. Implementing zero trust too quickly</h2><p>Implementing a Zero Trust approach might require significant changes to technologies and also to how people go about their daily business. Go too fast and it’s easy for mistakes to happen. Single devices or applications might slip through the net of compliance assurance at the time of implementation or later. Security hygiene – ensuring that <a href="https://www.itpro.co.uk/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>all hardware and software is up to date and patched</u></a> – is a central aspect of zero trust.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/27713/the-importance-and-benefits-of-effective-patch-management">Patch management vs vulnerability management</a></p></div></div><p>Ensuring every piece of hardware and software is known and its security can be optimized at all times takes time. It is important to allocate enough time to managing everything from the outset, and to develop processes for ensuring existing and new acquisitions are accommodated going forward. </p><h2 id="3-ignoring-the-principles-of-least-privileged-access">3. Ignoring the principles of least privileged access</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FRD22ayLuvtE64VjirP8YB" name="Why_Customer_Identity-thumb.png" caption="" alt="Whitepaper cover with image of multi generation colleagues smiling together at table" src="https://cdn.mos.cms.futurecdn.net/FRD22ayLuvtE64VjirP8YB.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Businesses at work</strong></p><p class="fancy-box__body-text"><em>Discussing the most popular apps and top performing apps of 2022, and the rise of Zero Trust security</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/collaboration/368250/businesses-at-work"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Least privileged access refers to the policy of ensuring users only have the bare minimum permission level to do what they need to do. It’s designed to keep access to resources tightly controlled and prevent the kind of sprawling access through systems that can be most helpful to bad actors. </p><p>However, it can be difficult to implement, particularly in the case of <a href="https://www.itpro.co.uk/cloud/34476/what-is-multi-cloud"><u>multi-cloud environments</u></a> in which data and apps are hosted with different providers, each with different policies and security protocols. In the end, budget, available time, and sheer workload can mean in-house teams assign wider privileges than necessary.</p><p>Using a class of software called entitlement management, or cloud infrastructure entitlement management, access to a multitude of software, systems, devices, and cloud platforms can be managed centrally. </p><h2 id="4-failing-to-focus-on-users">4. Failing to focus on users</h2><p>An organization’s employees are not the only stakeholders it’ll have to work with. There may also be contractors, suppliers, purchasers, delivery partners, and others. Presenting users with new protocols, hoops to jump through, and processes – without understanding whether these are seen as barriers – can cause resentment and foster non-compliance strategies. Users who work around security protocols are users who create risk. </p><p>High-quality user education on how to achieve compliance with security protocols is only part of the solution. People must also understand why certain behaviors are required, and be comfortable with any required actions or approaches. <a href="https://www.itpro.co.uk/security/cyber-security/370285/can-we-ever-achieve-cyber-security-buy-in"><u>Creating a ‘culture of security’ across the organization</u></a> takes time, effort, and leadership – from chief officers, senior managers, and line managers. </p><h2 id="5-assuming-zero-trust-is-bought-into-by-default">5. Assuming zero trust is bought into by default</h2><p>Every organization is different. Its technology setup will be unique. How people use technology will vary too. Where its people work will vary too, including in-office, remote or hybrid, one city, with national offices, or multinational. The variables are many and complex. While certain principles and approaches apply to zero trust, their implementation in any one organization will be unique. Simply going to a vendor and expecting them to do everything without any input is a fallacy.  </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/cyber-security/368543/six-cyber-security-holes-you-need-to-plug-now">Six cyber security holes you need to plug now</a></p></div></div><p>Organizations need to commit their own staff resource to work alongside vendors and understand that the implementation of zero trust will take time. This is and will continue to be an ongoing process.</p><p>With cyber attacks showing no signs of slowing down, and with organizations of all sizes and in all markets potentially vulnerable, securing data and networks is paramount. It’s no longer adequate to take a piecemeal approach to this challenge. A zero trust approach can help an organization implement a risk-based strategy toward data security. It isn’t without pitfalls, and organizations should be alive to these, and willing to commit the time and energy required to work them through. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malware being pushed to businesses by search engines remains a pervasive threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware-being-pushed-to-businesses-by-search-engines-remains-a-pervasive-threat</link>
                                                                            <description>
                            <![CDATA[ High-profile malvertising campaigns in recent months have surged ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pchGDUBTRbnkWNFyK5X3N3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 May 2023 11:37:34 +0000</pubDate>                                                                                                                                <updated>Tue, 02 May 2023 12:55:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware and security denoted by blue and gold mockup of motherboard with lock]]></media:description>                                                            <media:text><![CDATA[Malware and security denoted by blue and gold mockup of motherboard with lock]]></media:text>
                                <media:title type="plain"><![CDATA[Malware and security denoted by blue and gold mockup of motherboard with lock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Search engines pushing malware to users continue to be one of the most pervasive cyber security threats facing organizations around the world.</p><p>Netskope’s 2022 Cloud and Threat report found that nearly 10% of all malware downloads in Q1 2022 were referred from search engines. </p><p>Downloads of malicious software “mostly resulted” from weaponized data voids, or a combination of search terms that specifically appealed to business web users, the study found. </p><p>Data voids occur when there is a lack of clearcut information available on search terms found in Google. Netskope said this means that content matching certain terms appears “very high in search results” - which in turn appeals to threat actors targeting certain users. </p><p>The research revealed that threat actors are increasingly relying on malicious web content to target users by developing finely-catered websites spanning a range of categories, such as business, marketing, technology, education, and retail. </p><p>These websites are often developed and populated in a patient manner by attackers to ensure they appear legitimate and dupe unknowing users. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aciHQVJDYgcjpVWvmP9mYF" name="How to reduce the risk of phishing and ransomware_listing.jpg" caption="" alt="Whitepaper cover with title over shaded green letter O" src="https://cdn.mos.cms.futurecdn.net/aciHQVJDYgcjpVWvmP9mYF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>How to reduce the risk of phishing and ransomware</strong></p><p class="fancy-box__body-text"><em>Top security concerns and tips for mitigation</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360247/how-to-reduce-the-risk-of-phishing-and-ransomware"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Attackers have been populating their websites with enough content to make them seem legitimate, and only using them to host malicious content after they have been around long enough to blend in,” the <a href="https://www.netskope.com/wp-content/uploads/2023/01/cloud-and-threat-report-2022-year-in-review.pdf" target="_blank"><u>report stated</u></a>. </p><p>“They have also been abusing free hosting services and compromising existing websites to deliver malicious content.”</p><p>Netskope’s findings on malvertising align with previous research into this attack method, which has surged in popularity among threat actors in recent months. </p><p><a href="https://www.itpro.com/security/369951/bitwarden-users-raise-alarm-over-highly-convincing-google-malvertising-risks"><u>An investigation by Bitwarden in January</u></a> found that the volume of fake ads promoting malicious software and websites impersonating popular brands has increased markedly over the last year.  </p><p>Similar research from HP Wolf Security’s threat research division observed a surge in malvertising across 2022. </p><p>In a blog post in January, the security firm warned that businesses were facing a significant volume of malicious websites aimed at compromising user accounts and targeting operations. </p><p>“In the last two months, we’ve seen a significant increase in malware distributed through malvertising, with multiple threat actors currently using this technique,” researchers said.</p><p>The rise of malvertising has reached such a point in the last 12 months that researchers have <a href="https://www.itpro.com/security/malware/369892/google-ads-malvertising-campaign-prompts-questions-around-search-security"><u>raised questions over Google’s handling of the issue</u></a>.</p><p>In a January Twitter thread, security researcher Will Dormann questioned why VirusTotal, which is owned by Google, was not being used to automatically examine sponsored links for malware. </p><p>Dormann’s criticism followed an incident in which a popular crypto influencer fell victim to a malicious OBS link promoted in Google Search results. </p><h2 id="social-engineering-risks-still-acute">Social engineering risks still acute</h2><p>Malvertising represents “just one of many” <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering techniques</a> frequently employed by threat actors, the Netskope study warned. </p><p>In addition to leveraging search engines, attackers still focus heavily on targeting users via <a href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services">email platforms</a>, collaboration apps, and chat applications to dupe victims. </p><p>The study noted that the two most prevalent forms of malware still harnessed by attackers include Trojans, which accounted for 60% of all malware downloads in Q1 2022, and phishing downloads, which accounted for 13% of all incidents.</p><p>“Phishing scams, credit card skimmers, exploit kits, and other malicious web content continued to rise in 2022,” the report stated. </p><p>“Compromised sites, sites created using free hosting services, and fake websites hosting seemingly legitimate content have helped attackers disguise malicious web content, making it difficult to filter malicious content using URL categorization alone.”</p><p>“The rise in cloud malware delivery and malicious web content underscores the importance of inspecting all content, from all destinations, for both web and cloud.”</p><h2 id="cloud-apps-placing-users-at-risk-xa0">Cloud apps placing users at risk </h2><p>Malware delivery via cloud applications remained a key point of concern, the study found. </p><p>Over the last year, cloud malware delivery increased significantly, with malware downloads occurring from more than 400 cloud apps. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z56E3EaY7r8uT8bzBsoUrm" name="Destination Cyber resilience_listing.jpg" caption="" alt="Whitepaper cover with red title over shaded image of female working at a desk in an office" src="https://cdn.mos.cms.futurecdn.net/z56E3EaY7r8uT8bzBsoUrm.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Destination: Cyber resilience</strong></p><p class="fancy-box__body-text"><em>Cyber preparedness report</em></p><p class="fancy-box__body-text"><strong>DOWNLOAD FOR FREE</strong></p></div></div><p>Microsoft <a href="https://www.itpro.com/cloud-storage/34661/how-to-use-onedrive-a-guide-to-microsofts-cloud-storage-service">OneDrive</a> remained the most popular weapon of choice for threat actors in this regard. </p><p>However, Netskope observed a marked increase in the popularity of Google Cloud Storage, which saw “significant increase in usage as it gained popularity for object hosting across the web”. </p><p>To mitigate rising malware threats, Netskope recommended that organizations deploy “multi-layered, inline threat protection” for cloud and web traffic.</p><p>In doing this, businesses can prevent inbound and outbound <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> communications.</p><p>Similarly, it advised implementing “real-time coaching” for users to ensure safer app alternatives and to monitor unusual activity. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Cloud’s new security AI will explain how you’ve been breached ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/google-clouds-new-security-ai-will-explain-how-youve-been-breached</link>
                                                                            <description>
                            <![CDATA[ The new suite of tools could prove vital to security practitioners reacting to incidents in real-time ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5wMuBk39wDKzze8WqfP8BB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eGBuw7HPn9vDjv5Gf2jZwg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Apr 2023 10:46:04 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Apr 2023 08:32:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eGBuw7HPn9vDjv5Gf2jZwg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Google Cloud Platform logo displayed on their stand during the Mobile World Congress 2023]]></media:description>                                                            <media:text><![CDATA[The Google Cloud Platform logo displayed on their stand during the Mobile World Congress 2023]]></media:text>
                                <media:title type="plain"><![CDATA[The Google Cloud Platform logo displayed on their stand during the Mobile World Congress 2023]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eGBuw7HPn9vDjv5Gf2jZwg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Cloud has unveiled a raft of new generative AI tools that will provide security practitioners with detailed insights into how their organization could be breached. </p><p>Announced at the RSA conference, the Google Cloud Security AI Workbench is described as an “industry-first extensible platform”, powered by a specialized security-specific large language model (LLM) known as ‘Sec-PaLM’.</p><p>“This new security model is fine-tuned for security use cases, incorporating our unsurpassed security intelligence such as Google’s visibility into the threat landscape and Mandiant’s frontline intelligence on vulnerabilities, malware, threat indicators, and behavioral threat actor profiles,” said Sunil Potti, VP of Google Cloud Security. </p><h2 id="security-command-center-ai-xa0">Security Command Center AI </h2><p>A key feature within this announcement is the launch of Security Command Center AI, a premium version of Google Cloud’s existing Security Command Center service which is integrated within the new AI Workbench. </p><p>Google said this can provide security operators with “near-instant analysis of findings and possible attack paths”. </p><p>This enhancement to Security Command Center Premium could help organizations: </p><p>The inclusion of AI-generated explanations for attack paths and methods could prove vital to security practitioners, Potti said. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3DYEhHKEDmgGr8nVwhynFg" name="Avoiding cloud migration pitfalls for SAP_listing.jpg" caption="" alt="Whitepaper cover with logo and digital image of a data cloud with cables connecting to a digital globe" src="https://cdn.mos.cms.futurecdn.net/3DYEhHKEDmgGr8nVwhynFg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Avoiding cloud migration pitfalls for SAP</strong></p><p class="fancy-box__body-text"><em>Determining the best approach to SAP HANA</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-deployment/370391/avoiding-cloud-migration-pitfalls-for-sap"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>It’s said they can provide easily-digestible information in real time to reduce toil on operators and greatly enhance their ability to react to ongoing security incidents. </p><p>“Security Command Center will translate complex attack graphs to human-readable explanations of attack exposure, including impacted assets and recommended mitigations,” he said. </p><p>Potti added that this will also provide AI-powered risk summaries for security, compliance, and privacy findings for Google Cloud. </p><h2 id="cloud-security-for-x2018-non-specialists-x2019-xa0">Cloud security for ‘non-specialists’ </h2><p>A key message Google Cloud pushed during its address at RSA was that by embedding <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> into cloud security operations, it believes complexity will be greatly reduced.</p><p>Google said that the integration of Security Command Center features and the new AI Workbench will empower “non-security specialists to handle security tasks that were previously out of reach due to lack of specialized knowledge”.</p><p>This could represent a marked shift in how organizations handle <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security"><u>cloud security</u></a>, opening up responsibility to a wider range of practitioners and alleviating stress on frontline security operators, the company said. </p><p>“Security Command Center Premium can discover, identify, and recommend remediations for hundreds of cloud misconfigurations, software vulnerabilities, and external threats,” Google Cloud said in a statement.  </p><p>“Integration with Security AI Workbench will provide straightforward explanations of findings so security and non-security specialists can help keep their organization safe.” </p><p>AI-generated summaries coming through Command Center Premium will, once again, aim to offer easily-digestible answers to key security questions, tips on remediation for ongoing incidents, and assess security risks within cloud environments.  </p><h2 id="generative-ai-in-cyber-security-xa0">Generative AI in cyber security </h2><p>The rollout of generative AI security tools by Google Cloud follows the <a href="https://www.itpro.com/security/370348/microsoft-security-copilot-could-be-a-seismic-success-for-the-tech-industry"><u>launch of Microsoft’s Security Copilot</u></a> last month, and once again pits industry heavyweights Microsoft and Google against each other in the ongoing generative AI contest. </p><p>Microsoft Security Copilot uses <a href="https://www.itpro.com/technology/artificial-intelligence-ai/368288/what-is-gpt-4"><u>GPT-4 generative AI</u></a> to provide users with prompt-based security detection and remediation functionalities, and was met with great excitement upon launch. </p><p>However, while Google appeared to have been ‘beaten to the punch’ by Microsoft with the Copilot launch, the integration of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370322/can-generative-ai-change-security"><u>generative AI security</u></a> tools within Google Cloud - a key service for the tech giant - could mark a significant tipping point for the company in an <a href="https://www.itpro.com/cloud/370001/hyperscaler-earnigns-highlight-new-era-of-maturity-in-global-cloud-market"><u>increasingly competitive cloud landscape</u></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Outpost24 appoints M&A expert Brendan Hogan as chief strategy officer ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/outpost24-appoints-manda-expert-brendan-hogan-as-chief-strategy-officer</link>
                                                                            <description>
                            <![CDATA[ The former VMware executive will lead the cyber security firm’s long-term product strategy and growth ambitions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BmCiVdquEBNMDx4nDecMpW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xEUqeBavsXFWBjLvZNJkYK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Apr 2023 10:26:26 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Apr 2023 16:20:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xEUqeBavsXFWBjLvZNJkYK-1280-80.jpg">
                                                            <media:credit><![CDATA[Outpost24]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Outpost24 company logo]]></media:description>                                                            <media:text><![CDATA[Outpost24 company logo]]></media:text>
                                <media:title type="plain"><![CDATA[Outpost24 company logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xEUqeBavsXFWBjLvZNJkYK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sweden-based cyber risk management specialist Outpost24 has announced the appointment of Brendan Hogan as its new chief strategy officer (CSO).</p><p>A former VMware executive, Hogan brings more than 20 years of experience to the role and will spearhead the company’s M&A strategy, corporate development, as well as alliance strategy.</p><p>As CSO, he is tasked with driving long-term product strategy, scaling operations to support further growth opportunities, and seeking expansion across new global markets.</p><p>In an announcement, Outpost24 emphasized Hogan’s expertise in strategic planning, in organic growth, and deal execution, having previously led and advised on more than 50 global <a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/370086/why-blockbuster-tech-mas-might-be-a-thing-of-the"><u>M&A deals</u></a>, totaling $30 billion. </p><p>“Brendan is an exceptional strategist and operator with deep industry experience, we at Outpost24 are thrilled to bring his valuable expertise onboard,” said Karl Thedéen, CEO at Outpost24. </p><p>“He will have an instrumental role in our continued development which will see a positive change in strategy to help us deliver our goals and cement us further as a serious market player within cyber security.”</p><p>Prior to joining Outpost24, Hogan was vice president and head of strategy and corporate development for Massachusetts-based <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> firm Carbon Black, which went on to be acquired by VMware. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LXUGMsM76TZFUMCwm9Eu27" name="Build_vs_Buy.png" caption="" alt="Webinar screen with title, logo, and contributor information" src="https://cdn.mos.cms.futurecdn.net/LXUGMsM76TZFUMCwm9Eu27.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Build vs. buy: Is managing Customer Identity slowing your time to market?</strong></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/build-vs-buy-is-managing-customer-identity-slowing-your-time-to-market"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Post-acquisition, Hogan continued to lead strategy across VMware’s security portfolio, with partnerships and acquisitions being a key focus.</p><p>He was also senior director for strategy, mergers, and acquisitions at KPMG, and served as part of the strategy and corporate development executive team at VeriSign.</p><p>“I’m delighted to have joined Outpost24 at an exciting time,” Hogan said. “Over the past year, they have made big moves within the industry, and I am eager to continue to accelerate the business growth and further enhance our product innovation through strategic acquisitions that will support our customers who want to reduce their cyber security risk.”</p><p>Based in Kariskrona, Sweden, Outpost24 provides vulnerability management, application security testing, threat intelligence, and <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>access management</u></a> via its unified security platform. </p><p>The offering’s user base has grown to include more than 2,500 customers across 65 countries. </p><p>Back in July 2022, Outpost24 revealed it had been acquired by private equity firm Vitruvian Partners and underlined its goal of further international expansion.</p><p>Last month, the company also announced the appointment of Ola Burmark as its new chief financial officer (CFO), replacing Jonas Alfredson. </p><p>Burmark most recently served as CFO at telecommunications and cyber security firm ENEA Group and has previously held CFO positions at various Nasdaq Stockholm listed companies. </p><p>“Under the new ownership of Vitruvian Partnerships, the growth and expansion seen over the past year has been exciting,” Thedéen said at the time. </p><p>“Ola’s business acumen and strategic financial vision will benefit us greatly as we continue to seek out new opportunities and meet the demand for cyber security in this digital economy.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI acceleration represents a ‘tectonic shift’ for DevSecOps ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/ai-tectonic-shift-for-devsecops-gitlab</link>
                                                                            <description>
                            <![CDATA[ David DeSanto, chief product officer at GitLab, believes there’s still much more to come for AI use cases in DevSecOps ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BKaqDa3ppREbGXk33WeyMD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7Z9RWN6uMPPppzJwvHxTWE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Apr 2023 13:00:01 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Apr 2023 11:14:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7Z9RWN6uMPPppzJwvHxTWE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The GitLab logo on a smartphone in front of a background of data]]></media:description>                                                            <media:text><![CDATA[The GitLab logo on a smartphone in front of a background of data]]></media:text>
                                <media:title type="plain"><![CDATA[The GitLab logo on a smartphone in front of a background of data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7Z9RWN6uMPPppzJwvHxTWE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The recent acceleration in the <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>artificial intelligence (AI)</u></a> space represents a “tectonic shift” in <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important"><u>DevSecOps</u></a> and could herald a new era of efficiency and productivity for software developers, according to GitLab chief product officer David DeSanto. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important">What is DevSecOps and why is it important?</a></p></div></div><p>DeSanto notes <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> developments have been a source of great excitement across the global tech industry, he tells <em>ITPro </em>at KubeCon 2023, not least of all in <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer"><u>software development</u></a> and <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a>. </p><p>Within days of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT’s</u></a> launch last November, devs the world over were fawning over the prospect of harnessing the tool in their daily workflows. The ability to generate and even test code proved tantalizing and appeared to be the silver bullet many had dreamt of. </p><h2 id="how-ai-can-power-software-development">How AI can power software development</h2><p>DeSanto believes the industry is currently “at the precipice” of a revolution with regard to the practical implementation of AI within the software development lifecycle. That’s not to say AI or <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning"><u>machine learning</u></a> isn’t already being used in this regard, but the scale of potential is highly evident across the ecosystem. </p><p>This potential for improved productivity comes amid a period of troubling <a href="https://www.itpro.com/business/business-strategy/369807/uk-tech-economic-storm-recession-in-2023"><u>macroeconomic conditions</u></a> that are prompting <a href="https://www.itpro.com/business-strategy/digital-transformation/369788/budgeting-for-tech-projects-in-a-financial-squeeze"><u>tightening purse strings</u></a> and placing a strain on already stretched workforces. Simply put, AI tools could make or break how well teams work moving forward.</p><p>“I’ve been calling it a tectonic shift in how DevSecOps is done,” he says. “ The reason I feel that way is that there are still many companies who struggle to get a large enough workforce to support what they want to do.</p><p>“If you can make your existing team members more effective, then you also make them more engaged, and by making them more engaged, they’re more likely to stay. You are now building a retention component within how you support your team.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370348/microsoft-security-copilot-could-be-a-seismic-success-for-the-tech-industry">Microsoft Security Copilot could be a seismic success for the tech industry</a></p></div></div><p>DeSanto points to code suggestions as an example, noting an AI-based support functionality within the development process could deliver significant benefits to both individuals and broader teams. </p><p>Last week, GitLab announced it had moved its own code suggestions functionality into open beta. The signs so far are promising, with indicators it’s led to efficiency gains as well as improving both quality of life and quality of performance among developers. </p><p>“Now you could have an intermediate developer, for example, functioning and performing like a senior developer,” he suggests. </p><p>Other potential use cases, such as leveraging AI to identify <a href="https://www.itpro.com/security/exploits/360411/top-30-most-exploited-vulnerabilities">vulnerabilities</a>, would also drastically improve efficiency throughout the development lifecycle and help streamline a notable pain point in the process. </p><p>“Those sorts of things are going to make everyone more effective, but also as a team, as a company. One of Gitlab’s core tenets is that everyone can contribute. You’re truly going to make it everyone can contribute if you apply AI properly.”</p><h2 id="how-to-implement-ai-in-devsecops">How to implement AI in DevSecOps</h2><p>GitLab’s own research correlates with what DeSanto tells <em>ITPro </em>about the increasing use – and potential – of AI tools in DevSecOps. </p><p>The company’s annual Global DevSecOps report, published today, finds nearly two-thirds (65%) of developers are now using <a href="https://www.itpro.com/strategy/28087/machine-learning-vs-ai"><u>AI or machine learning</u></a> in testing processes, or expect to be doing so within the next three years. </p><p>Similarly, 62% of developers told the company they use AI or machine learning to check code. DeSanto notes, this marks an increase from 51% last year. This, he says, highlights the fact developers view AI as a valuable tool within their proverbial kit. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9trkJWQXGPZq5ZryjQrwJB" name="GitOps and Shift Left security_thumb.jpg" caption="" alt="Whitepaper cover with title and logo over image of a female worker facing the camera, writing on a clear board in a meeting with colleagues sat behind her" src="https://cdn.mos.cms.futurecdn.net/9trkJWQXGPZq5ZryjQrwJB.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Walking the line: GitOps and Shift Left security</strong></p><p class="fancy-box__body-text"><em>Scalable, developer-centric supply chain security solutions</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/walking-the-line-gitops-and-shift-left-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>DeSanto was keen to emphasize there are certain nuances within this shift in appetite toward AI tools, though. While research shows a notable increase in interest, he believes seniority plays a role in how receptive developers or security personnel may be toward this trend. </p><p>“It depends on the maturity of the developer in their career, or on their skillset in terms of the true impact [of AI tools],” he says. “A lot of the time, when it comes to improving developer productivity we see it tends to be newer developers who are getting almost like a coach to support them.</p><p>“But developers who are mature don’t have that same big thirst. They view it as a way to get things done faster and spend some of that saved time in code reviewing.”</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53320039&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/370416/generative-ai-mark-zuckerberg-metaverse-in-the-dust">Generative AI has left the metaverse in the dust</a></p></div></div><p>DeSanto also suggests for teams seeking to leverage AI tools, it isn’t a case of deploy and relax. Deployment requires a concerted effort and razor-sharp focus across the enterprise to maximize the use of AI, else it’ll merely amount to a poorly harnessed stack of tools that add little value. </p><p>“For AI to be effective, and for everyone to be effective as a result of this, it can’t just be applied to one part of the software development lifecycle,” he continues. “This is not just the developer, it’s everything involved in delivering software.</p><p>“GitLab is an enterprise DevSecOps platform, so obviously we’re focused on covering the entire development lifecycle. In our opinion, you can’t just apply AI to the developer experience and to developer efficiency, you’re not solving the whole problem.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CyberCX appoints Phil Mason as new UK CEO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/cybercx-appoints-phil-mason-as-new-uk-ceo</link>
                                                                            <description>
                            <![CDATA[ Industry veteran will lead CyberCX’s growth efforts in the UK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZynQA7BLzETZLfdQbMchoU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Apr 2023 09:00:09 +0000</pubDate>                                                                                                                                <updated>Thu, 20 Apr 2023 06:13:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:description>                                                            <media:text><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:text>
                                <media:title type="plain"><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Australian cyber security services provider CyberCX has announced the appointment of Phil Mason as its new CEO in the UK. </p><p>By appointing a new CEO in the UK, the company says it is now looking to replicate its success and growth on UK shores.</p><p>A seasoned industry veteran, Mason brings two decades of cyber security experience to the role, having previously held senior positions at IRMSecurity, part of the Capgemini Group. </p><p>There, he led cyber transformation strategies for influential public-sector organizations and global enterprises.</p><p>As CEO of CyberCX’s UK business, Mason will work to drive growth in the UK market, focusing on supporting new business and <a href="https://www.itpro.com/business-strategy/careers-training/369654/one-in-four-uk-businesses-hiring-overseas-talent-shortage"><u>talent acquisition</u></a>. </p><p>The firm said the appointment will ensure a “consistent, global approach” that is also tailored to UK-specific needs. </p><p>“CyberCX has burst onto the global cyber security scene, and I am thrilled to be leading the UK business to replicate the success it has seen in Australia,” Mason said. </p><p>“With cyber threats becoming increasingly complex and frequent, there has never been a more important time to safeguard businesses against <a href="https://www.itpro.com/security/malware/the-top-malware-and-ransomware-threats-for-april-2023"><u>cyber security threats</u></a>. </p><p>“I look forward to leading our UK team in helping our clients navigate this complex landscape and stay ahead of the curve.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FRD22ayLuvtE64VjirP8YB" name="Why_Customer_Identity-thumb.png" caption="" alt="Whitepaper cover with image of multi generation colleagues smiling together at table" src="https://cdn.mos.cms.futurecdn.net/FRD22ayLuvtE64VjirP8YB.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Why customer identity?</strong></p><p class="fancy-box__body-text"><em>Learn how a renewed focus on Customer Identity can unlock innovation and inspire new capabilities</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/why-customer-identity"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Formed in 2019, CyberCX has grown to become a prominent name in the cyber security space across Australia and New Zealand. </p><p>The firm specializes in the provision of <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> and cloud services, partnering with organizations to manage their cyber risk, respond to incidents, and build resilience.</p><p>Since its inception, CyberCX has grown its workforce to more than 1,300 cyber security and cloud professionals and has offices in Australia, New Zealand, the US, and the UK. </p><p>The firm partners with both private and public sector organizations, providing end-to-end cyber capabilities, and helps customers securely accelerate their <a href="https://www.itpro.com/strategy/28047/what-is-digital-transformation"><u>digital transformation</u></a> strategies. </p><p>With Mason as the new UK CEO, CyberCX said it is well-positioned to meet the growing demand for security services as threats continue to escalate. </p><p>“Phil’s extensive experience and track record for growth in revenue and services, combined with his dedication to customers and building high-performance teams, make him the ideal person to lead our operations in the UK,” said John Paitaridis, CEO at CyberCX. </p><p>“We look forward to working with him to become the UK’s leading independent provider of cyber security.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft angers admins as April Patch Tuesday delivers password feature without migration guidance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/windows/microsoft-april-patch-tuesday-password-feature</link>
                                                                            <description>
                            <![CDATA[ Security fixes include a zero day exploited by a ransomware group and seven critical flaws ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">92PXHhi4fpg7Cv4b8VNdFn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Apr 2023 11:51:19 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Apr 2023 09:40:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:description>                                                            <media:text><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:text>
                                <media:title type="plain"><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft’s April 2023 Patch Tuesday delivered not just the usual score of security fixes for Windows admins, but also a new feature that has attracted criticism from the IT community.</p><p>The Windows 11 22H2 KB5025239 cumulative update, among other fixes and features, delivers the new Windows Local Administrator Password Solution (LAPS) to IT teams managing both on-prem and cloud environments.</p><p>Microsoft LAPS manages and backs up local admin account passwords on Azure Active Directory-joined devices. </p><p>It’s seen as one of the most secure ways to ensure unauthorized users aren’t able to access things they’re not supposed to.</p><p>The new LAPS is available for Windows 10&11 Pro, EDU, and Enterprise versions, as well as Windows Server 2022, Windows Server Core 2022, and Windows Server 2019.</p><p>LAPS for Azure AD is not yet available. It’s now bundled into Microsoft Entra - the name given to Microsoft’s identity and access products that can be managed through a single portal.</p><p>The Azure AD version of LAPS is expected to go from private to public preview “later this quarter,” said Jay Simmons, development lead at Microsoft, and will deliver new features such as password encryption, password histories, an emulation mode, and automatic rotation.</p><p>“Windows LAPS is a huge improvement in virtually every area beyond Legacy LAPS,” he added.</p><p>Online IT admin communities have not greeted the news as warmly as expected.</p><p>The main issue among these communities relates to concerns over how to migrate. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="stxf8shwiEd3uXTVtmCZAD" name="Leaked today, exploited for life_thumb.png" caption="" alt="Red whitepaper cover with title" src="https://cdn.mos.cms.futurecdn.net/stxf8shwiEd3uXTVtmCZAD.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Leaked today, exploited for life</strong></p><p class="fancy-box__body-text">How social media biometric patterns affect your future</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370153/leaked-today-expolited-for-life"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The new LAPS feature has been released but Microsoft has not supplied the community with any documentation detailing how to complete the migration.</p><p>Some professionals have already encountered issues where the new LAPS has stopped working due to nuances in the migration process. </p><p>The prevailing advice is to stop deploying the legacy LAPS MSI immediately after the April Patch Tuesday update is applied. </p><p>Failure to do so reportedly breaks the new LAPS and prevents legacy LAPS from updating passwords.</p><p>“You need to update documentation and guidance very soon,” one user told Simmons in an <a href="https://www.reddit.com/r/sysadmin/comments/12itqb9/windows_laps_available_today/"><u>online discussion</u></a>.</p><p>“I hate spending my day discovering something that is about to hit 100,000 of our machines doesn&apos;t have guidance, and we have to action something,” they added.</p><p>“If migration docs aren’t available yet, [why] was this released,” another asked. “This tells me that documentation, upgrades, and coexistence, were not given any priority - which is bloody shocking but given how Microsoft pushes stuff out the last few years, I suppose it really shouldn’t be any more.”</p><p>Simmons responded to users by saying that he “should have been better prepared” to allay the global community’s concerns.</p><p>“New Windows LAPS has been designed to be an almost entirely opt-in feature, using a separate brand new GPO policy and separate brand new AD schema attributes, which – at least to my Microsofty-mind – mostly mitigates the risk of applying the patches to existing environments,” he said.</p><p>“But regardless yes we should have preemptively called this out in the post so as to not scare folks.”</p><p>Error-strewn Patch Tuesday releases are becoming something of a commonality from Microsoft, with the monthly updates often presenting major issues for IT teams.</p><p>Most recently in last month’s March Patch Tuesday updates, IT admins complained about a <a href="https://www.itpro.com/security/370264/windows-admins-plagued-issues-outlook-zero-day-patch"><u>variety of problems after installing patches for an Outlook zero day</u></a>.</p><p>Windows 10 users were hit with the infamous <a href="https://www.itpro.com/operating-systems/microsoft-windows/369757/windows-10-blue-screen-of-death-patch-tuesday-updates"><u>blue screen of death after installing December’s updates</u></a>, and around a year earlier <a href="https://www.itpro.com/server-storage/microsoft-windows-server/362009/windows-server-admins-agree-to-forgo-broken-patches"><u>IT admins were forced to ignore the security fixes for a month</u></a> as a result of the rampant issues reported by the community.</p><h2 id="april-2023-patch-tuesday-summary">April 2023 Patch Tuesday Summary</h2><p>Microsoft’s April 2023 Patch Tuesday brought fixes for 97 total security vulnerabilities including seven critical-rated flaws and one zero day that’s been actively exploited by a <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> group.</p><p>Tracked as CVE-2023-28252, the privilege escalation vulnerability in Windows Common Log File System (CLFS) Driver grants SYSTEM-level privileges if successfully exploited.</p><p>Kaspersky identified exploit attempts dating back to February 2023 that it said were very similar to other types of exploits it had been tracking. </p><p>The team investigated and discovered that it was a zero day affecting different versions of Windows, including <a href="https://www.itpro.com/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business"><u>Windows 11</u></a>.</p><p>The Nokoyama group is described as “sophisticated” and used a newer version of its ransomware payload, which has historically been a rebranded version of JSWorm. Now <a href="https://www.itpro.com/development/programming-languages/369499/move-away-from-memory-unsafe-languages-c"><u>written in C</u></a> with encrypted strings.</p><p>In previous attacks, Nokoyama has also deployed the Cobalt Strike penetration testing tool to evade antivirus products, and a custom modular backdoor called Pipemagic in other attacks.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KEWTygV2eNQU2nkeskB3sn" name="Trend Micro security predictions for 2023_thumb.png" caption="" alt="Whitepaper cover with shattered image of female using a VR headset" src="https://cdn.mos.cms.futurecdn.net/KEWTygV2eNQU2nkeskB3sn.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Security predictions for 2023</strong></p><p class="fancy-box__body-text"><em>Prioritise cyber security strategies on capabilities rather than costs</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/ransomware/370157/trend-micro-security-predictions-for-2023"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Kaspersky said it believes “CVE-2023-28252 could have been easily discovered with the help of fuzzing” - a technique that sees automated injections of invalid or unexpected inputs into a target system to reveal security vulnerabilities.</p><p>It said that the clfs.sys driver extensively uses try/catch blocks to handle exceptions, so code continues to execute as if no errors were thrown. </p><p>Kaspersky’s <a href="https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/"><u>analysis</u></a> showed that a possible access violation that follows after the vulnerability is triggered was masked by one of these exception handlers, and because there was no crash, fuzzers were most likely ‘finding’ the vulnerability but not reporting it as a potential issue.</p><h2 id="april-2023-patch-tuesday-breakdown">April 2023 Patch Tuesday breakdown</h2><p>This month’s 97 security fixes slightly exceeded March’s total of 83, with the overall count not including the 17 <a href="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge"><u>Microsoft Edge</u></a> issues patched on 6 April.</p><p>All seven of the critical-severity vulnerabilities were remote code execution (RCE) flaws.</p><p>The two most serious of which, CVE-2023-21554 and CVE-2023-28250, affecting Microsoft Message Queuing and Windows Pragmatic General Multicast (PGM) respectively, both scored a near-maximum 9.8/10 on the CVSS v3 severity scale.</p><p>Four RCEs were also found in <a href="https://www.itpro.co.uk/desktop-software/19337/office-365-review"><u>Microsoft Office</u></a>, Microsoft Word, and Microsoft Publisher, and were exploitable by opening malicious documents.</p><p>All four were categorized under “exploitation less likely” by Microsoft. This classification is designated to vulnerabilities for which attackers would either have difficulty writing the code, require expertise and/or sophisticated timing, or would experience varied results when testing the vulnerable target.</p><p>These flaws are also not recently exploited in the wild but given the potential impact of successful abuse, the vulnerability warrants an update regardless.</p><p>The full breakdown of the vulnerabilities’ types can be found below:</p><ul><li>45 remote code execution</li><li>20 elevation of privilege</li><li>10 information disclosure</li><li>9 denial of service</li><li>7 security feature bypass</li><li>6 spoofing</li></ul><p>Microsoft&apos;s full dashboard of the month’s updates can be found on <a href="https://msrc.microsoft.com/update-guide/vulnerability"><u>its website</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Can we ever achieve cyber security buy-in? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/370285/can-we-ever-achieve-cyber-security-buy-in</link>
                                                                            <description>
                            <![CDATA[ Members of the IT Pro Network share their experiences of trying to encourage good cyber hygiene in the workplace ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hfSr9KpLcgMpfpn95zXurW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Bix86UMXkwxbu6LBeZ9Yh7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Mar 2023 16:33:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Bix86UMXkwxbu6LBeZ9Yh7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman using her phone as a device for 2FA]]></media:description>                                                            <media:text><![CDATA[A woman using her phone as a device for 2FA]]></media:text>
                                <media:title type="plain"><![CDATA[A woman using her phone as a device for 2FA]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Bix86UMXkwxbu6LBeZ9Yh7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you ask IT professionals what their top concerns are, security will certainly be among the top five. Whether it’s preventing <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attacks, regular <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">patch management</a> or trying to ensure users don’t click risky links, cyber threats are always lurking in the background ready to cause a crisis.</p><p>While the idea of hackers trying to <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">brute force</a> their way into systems may make for better TV, internal threats – be they actively malicious internal actors or employees falling for <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attempts – are a far more common attack vector.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="/careers/28212/a-guide-to-cyber-security-certification-and-training">A guide to cyber security certification and training</a></p></div></div><p>According to <a href="https://www.kroll.com/en/insights/publications/cyber/threat-intelligence-reports/q3-2022-threat-landscape-insider-threat-trojan-horse">a report from Kroll</a> published in November 2022, <a href="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity" target="_blank" data-original-url="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity">insider threats</a> are actually increasing, making up close to 35% of unauthorised access incidents recorded in the third quarter of the year. The company also noted an uptick in credential theft, particularly via <a href="https://www.itpro.com/security/phishing/361625/what-is-smishing" data-original-url="https://www.itpro.com/security/phishing/361625/what-is-smishing">‘smishing’</a>.</p><p>One mitigation often put forward is increasing understanding and ‘buy-in’ from employees across the breadth of an organisation. What this actually means, however, can be hard to pin down, let alone implement.</p><p>Members of the IT Pro Network have come together to discuss exactly this problem and whether there really is a solution to effective security training for all.</p><h2 id="cyber-security-starts-at-home">Cyber security starts at home</h2><p>“Something I have done in the past which has worked.... Don’t look for buy-in for <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> at work,” says Mark Evans, interim information technology director at construction firm Tilia Homes. “Teach people how to protect their children, their bank accounts, their car insurance, their NHS information, their banking details – those learned behaviours will come back into the business.</p><p>“People need to be aware that they have a responsibility to themselves to protect their data and that gives them all of the context they need in order to develop good cyber hygiene.”</p><p>Paul Watts, distinguished analyst at the Information Security Forum feels the same, adding that making the conversation less ‘corporate’ can help people actually focus on what’s being said.</p><p>“When I was CISO at Network Rail, I borrowed a whole primary school year group. They came in and helped me get people talking about staying safe in cyber space. That was a great day and the business was much more receptive to a conversation with no corporate agenda (although the health and safety prep was hard work),” he says.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness" data-original-url="/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">10 ways to get employees invested in cyber security awareness training</a></p></div></div><p>For some organisations, this marriage of cyber security at work and cyber security at home is easier to bring together. Peter Donlon, group <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do" target="_blank" data-original-url="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO</a> at online greeting cards business Moonpig, says: “One of the more successful approaches for me has been educating the company on what it is we need to protect and bring to life the consequences of not doing so. In our case holding millions of people's personal photos, messages to loved ones, addresses, etc. </p><p>“When you highlight what it is we're all trusted to look after and what the consequences of breaking that trust are, I've found it becomes easier to educate people on how they need to play their part.”</p><h2 id="speak-softly-and-carry-a-big-stick">Speak softly and carry a big stick</h2><p>While it’s good to be understanding and wish to educate, there’s only so far this attitude can go if someone is unwilling to cooperate or participate in an organisation’s cyber security strategy.</p><p>“You need to do everything you can to educate people of the importance, and constantly remind people,” says Gerard McGovern, director of digital strategy. “I like the idea of centring it on activities out of work that will then permeate into the workplace, but it must be backed up with consequences. If reception let someone into the office without checking ID, there would be consequences. The same must be true with cyber.”</p><p>Watts makes a similar observation, adding: “We've gone out of our way to demystify technology and make it more accessible without educating people on the risks.</p><p>“I do wonder sometimes whether that is on us as a community of practice; you don't give someone a car and expect them to know how to drive it without giving them some tuition first.”</p><h2 id="a-generational-divide">A generational divide</h2><p>IT leaders are often faced with the challenge of different age groups being more adept with technology, depending on when digitisation became part of their lives. For the baby boomer generation, computers arrived relatively late in their career. Many were in middle age by the time there was a computer on every desk, with the internet becoming ubiquitous even later.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HZj96Z5myU4QbgD5zye974" name="HZj96Z5myU4QbgD5zye974.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HZj96Z5myU4QbgD5zye974.png" mos="https://cdn.mos.cms.futurecdn.net/HZj96Z5myU4QbgD5zye974.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The WFH cyber security checklist</strong></p><p class="fancy-box__body-text">Ten ways to win the remote access game with ZTNA</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/remote-access/370179/the-wfh-cyber-security-checklist" data-original-url="/mobile/remote-access/370179/the-wfh-cyber-security-checklist">FREE DOWNLOAD</a></p></div></div><p>For the younger members of generation X and the older millennials – once shorthand for ‘young people’ – computers have been around in some form or another for most of their lives. They still remember a world before the internet, however, which crept into schools, universities and workplaces when they were in their teens and twenties.</p><p>Now, it’s generation Z, often given the moniker “digital natives”, who are entering the workplace and shaking things up, having never known a pre-internet, pre-PC world.</p><p>Yet while these younger generations may be more tech savvy, they’re not necessarily more knowledgeable when it comes to cyber security.</p><p>“Yes, younger people who have grown up with technology are generally more familiar with digital apps and devices and may be more comfortable using them,” says Craig York, <a href="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do" target="_blank" data-original-url="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do">CIO</a> at Milton Keynes University Hospitals NHS Trust. “However, being tech-savvy doesn't necessarily equate to being more aware of cyber security concerns. The younger generation at my organisation are perhaps more lax about cyber security than their older counterparts.”</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369758/the-scariest-cyber-security-horror-stories-of-2022" data-original-url="/security/cyber-security/369758/the-scariest-cyber-security-horror-stories-of-2022">The scariest cyber security horror stories of 2022</a></p></div></div><p>In Watts’ experience, not only are younger people no better at cyber security than their older counterparts, they bring a whole new wave of challenges.</p><p>“You've only got to look at the herd mentality when following a trend on social media, a new (unproven) app that an influencer shoves down their throats, they will literally do anything for 'likes' and, of course, FOMO [the fear of missing out],” he says. </p><p>“I always thought the young would … pay more attention to their digital persona and footprint. I'm being proven very wrong there.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kali Linux releases first-ever defensive distro with score of new tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/370257/kali-linux-releases-first-ever-defensive-distro-score-new-tools</link>
                                                                            <description>
                            <![CDATA[ Kali Purple marks the next step for the red-teaming platform on the project's tenth anniversary ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">unrADLURAspNaGwLVwKfnV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DXyATm7k6CbbwJC5rPAeCK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Mar 2023 12:00:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DXyATm7k6CbbwJC5rPAeCK-1280-80.jpg">
                                                            <media:credit><![CDATA[Kali / Offensive Security]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of a Linux operating system with Kali Purple windows open on the desktop and a stylised dragon in the background next to the text &amp;#039;KALI&amp;#039;]]></media:description>                                                            <media:text><![CDATA[A screenshot of a Linux operating system with Kali Purple windows open on the desktop and a stylised dragon in the background next to the text &amp;#039;KALI&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of a Linux operating system with Kali Purple windows open on the desktop and a stylised dragon in the background next to the text &amp;#039;KALI&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DXyATm7k6CbbwJC5rPAeCK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The team behind the Kali Linux project has released a brand-new version called Kali Purple, designed specifically for defensive security practitioners - a first for the project.</p><p>Kali Purple was released as a technical preview this week and marks the first time the platform has catered to defenders, previously being used as a tool for <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">red teamers</a> and penetration testers.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nx6u3z9cbusK7Hm4Z2UHgJ" name="nx6u3z9cbusK7Hm4Z2UHgJ.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nx6u3z9cbusK7Hm4Z2UHgJ.png" mos="https://cdn.mos.cms.futurecdn.net/nx6u3z9cbusK7Hm4Z2UHgJ.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Datto SMB cyber security for MSPs report</strong></p><p class="fancy-box__body-text">A world of opportunity for MSPs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/smb/370209/datto-smb-cyber-security-for-msps-report" data-original-url="/business-strategy/smb/370209/datto-smb-cyber-security-for-msps-report">FREE DOWNLOAD</a></p></div></div><p>As of now, Kali Purple is a proof of concept distro for security testing, described by Kali as a “reference architecture for the ultimate SOC In-A-Box”.</p><p>It will allow teams to engage in internal wargames, learn how to protect small-to-medium-sized IT environments, and practice <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting" data-original-url="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting">threat hunting</a>, among other activities.</p><p>The name references the addition of blue and purple team capabilities to Kali Linux’s existing suite of red team testing tools, expanding the distro from its offensive testing pedigree to encompass the entire security testing spectrum.</p><p>More than 100 defensive tools are included within Kali Purple. These include CyberChef, which can <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypt or decrypt data</a> as well as compression and data analysis, Elastic’s security information and event management (SIEM), and the <a href="https://www.itpro.com/software/28109/what-is-open-source" data-original-url="https://www.itpro.com/software/28109/what-is-open-source">open source</a> network intrusion detection system Zeek.</p><p>Kali Autopilot, a script builder for automated attacks is also included in Kali Purple. Through a community hub developers will be able to share scripts for blue teams to go up against, as well as practice packet captures to train in network analysis.</p><p>The developers outlined their goal of making Kali the <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros" data-original-url="https://www.itpro.com/operating-systems/28025/best-linux-distros">best Linux distro</a> for security tests, and expanding enterprise-grade security to all.</p><p>“Remember what we did a decade ago with Kali Linux? Or with BackTrack before that? We made offensive security accessible to everyone,” Kali wrote in its <a href="https://www.kali.org/blog/kali-linux-2023-1-release/#new-tools-in-kali">blog post</a>.</p><p>“No expensive licenses required, no need for commercial grade infrastructure, no writing code or compiling tools to make it all work… just download Kali Linux and do your thing. We are excited to start a new journey with the mission to do exactly the same for defensive security: Just download Kali Purple and do your thing.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/28025/best-linux-distros" data-original-url="/operating-systems/28025/best-linux-distros">Best Linux distros 2023: The finest open source operating systems around</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system" data-original-url="/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Windows vs Linux: What's the best operating system?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/operating-systems/370109/linux-edges-closer-full-apple-silicon-with-version-62" data-original-url="/software/operating-systems/370109/linux-edges-closer-full-apple-silicon-with-version-62">Linux edges closer to full Apple silicon support with version 6.2</a></p></div></div><p>Kali Purple has been structured around the National Institute of Standards and Technology’s <a href="https://www.nist.gov/cyberframework/online-learning/five-functions">(NIST’s) five functions</a> as outlined in the Cybersecurity Framework: “identify, protect, detect, respond, and recover”.</p><p>In addition to the announcement of Kali Purple, the firm highlighted eight new tools included in Kali Linux 2023.1.</p><p>These include the aforementioned Cyberchef, as well as packet capture system Arkime, <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important" data-original-url="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important">DevSecOps</a> and vulnerability management tool DefectDojo, network scanner Dscan, <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes" data-original-url="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes</a> package manager Kubernetes-Helm, password analysis and cracking kit 2 (PACK2), <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">pen test</a> data management tool RedEye, and cryptographic <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm" data-original-url="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithm</a> interface Unicrypto.</p><p>The update also brings a visual refresh to the distro, with new wallpapers and Kali Purple themes, as well as a new tiling and widget system with the introduction of the graphical workspace environment KDE Plasma 5.27.</p><p>Kali Purple is available as a pre-launch technical preview now, with a dedicated Discord server and <a href="https://gitlab.com/kalilinux/kali-purple/documentation/-/wikis/home">wiki</a>. Further details on its full launch are expected in the future.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Freshworks CISO Jason Loomis embraces the ‘shift left’ amid surging supply chain threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/chief-information-security-officer-ciso/369909/freshworks-ciso-jason-loomis</link>
                                                                            <description>
                            <![CDATA[ Fewer than 100 days in the role, Jason Loomis reveals his plans for the future of security at Freshworks, and discusses the rising threat of API vulnerablities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rXgU6stQK2ukNtkKpoFE8b</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/95VBDPk5uxUzj8tEd2d9pH-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Jan 2023 09:19:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/95VBDPk5uxUzj8tEd2d9pH-1280-80.png">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up photo of Jason Loomis, CISO at Freshworks]]></media:description>                                                            <media:text><![CDATA[Close-up photo of Jason Loomis, CISO at Freshworks]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up photo of Jason Loomis, CISO at Freshworks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/95VBDPk5uxUzj8tEd2d9pH-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It’s been just over eight weeks since Jason Loomis took the reins as Freshworks CISO, and the seasoned security veteran is relishing the opportunity to lead one of the most dynamic <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> teams in the software industry. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359213/it-and-ot-how-cisos-can-best-handle-the-dangers-of-integration" data-original-url="/security/cyber-security/359213/it-and-ot-how-cisos-can-best-handle-the-dangers-of-integration">IT and OT: How CISOs can best handle the dangers of integration</a></p></div></div><p>Arriving at the firm in late November, Jason joined after serving as <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do" target="_blank" data-original-url="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> at California-based <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas" target="_blank" data-original-url="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a> company Mindbody for nearly four and a half years, where he played a key role in building a robust security programme and scaling the security function. </p><p>While Loomis notes he was sad to leave a company with which he’d established a long-term emotional connection, he says the time was right to embark on a new challenge. “It’s almost heart-breaking leaving when you’ve built something so great with a team so strong,” he tells <em>IT Pro</em>. “ I will always love the team that I built at Mindbody. But I did what I wanted to do, and so, I was looking for a new opportunity.” </p><h2 id="the-first-100-days-is-like-drinking-from-the-fire-hose">The first 100 days is like ‘drinking from the fire hose’ </h2><p>Jason boasts a wealth of experience in the cyber security industry. Prior to his time at Mindbody, he served as CISO at TechStyle Fashion Group, the company behind notable brands such as Fabletics, Savage X Fenty and Kate Hudson’s yoga wear line. </p><p>This breadth of experience appears to have embedded a deep appreciation for continuous learning and understanding the varied and acute requirements of security teams. Since joining Freshworks, he says he‘s continued in this vein.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="78CrzifhezWRDqAMHNPPxD" name="78CrzifhezWRDqAMHNPPxD.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/78CrzifhezWRDqAMHNPPxD.png" mos="https://cdn.mos.cms.futurecdn.net/78CrzifhezWRDqAMHNPPxD.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building intelligent, resilient and sustainable supply chains</strong></p><p class="fancy-box__body-text">The new engines of transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/supply-chain-management-scm/369373/building-intelligent-resilient-and" data-original-url="/business-operations/supply-chain-management-scm/369373/building-intelligent-resilient-and">FREE DOWNLOAD</a></p></div></div><p>Still within his first 100 days as CISO, a period often described as a ‘drinking from the fire hose’ experience by <a href="https://www.itpro.com/business-strategy/careers-training/361089/how-to-become-a-cyber-security-expert" target="_blank" data-original-url="https://www.itpro.com/business-strategy/careers-training/361089/how-to-become-a-cyber-security-expert">security professionals</a>, Jason says he’s relished the opportunity to take a step back. He’s learing how the Freshworks security apparatus operates and is gaining a deeper understanding of the unique challenges the company faces. </p><p>Thus far, he seems impressed. Freshworks boasts a mature security function, which he admits is quite a contrast to his previous role building a team and scaling operations. “At my previous company, I partially had to build a team. But here I’ve got a fully functioning team,” he explains. </p><p>“For me to come in and make changes would be like coming into the <em>Avengers</em> and telling them ‘hey, why don’t you try things this way’ – I literally inherited a bunch of superheroes and there’s not a single person out of a team of close to 70 that isn’t a rock star.” </p><p>“For the first 100 days, it’s a lot of shut up and listen, learn and absorb. I try not to even make decisions in the first 100 days,” he adds. </p><p>This initial bedding in period has also given Jason room to breathe, observe how his teams function, and to embed his own <a href="https://www.itpro.com/business-strategy/32611/leadership-in-it-what-are-the-secrets-to-success" target="_blank" data-original-url="https://www.itpro.com/business-strategy/32611/leadership-in-it-what-are-the-secrets-to-success">leadership style</a>, which he describes as being highly collaborative and democratised.</p><p>“Every single decision that’s made is a team decision,” he says. “How my teams make decisions are more important that the decisions themselves. I never make a decision on my own, so it’s a group effort. And while I’m ultimately the quarterback and I’ve sometimes got to make a call; I’m always asking everyone on the team for their input. Everyone has a say.” </p><h2 id="getting-the-basics-right">Getting the basics right </h2><p>In leading a sizeable security function, Jason says this role gives him the opportunity to focus on getting the <a href="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of" target="_blank" data-original-url="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of">basics right</a>. He’s keen to ensure customers are in safe hands amidst heightened security risks and concerning developments across the <a href="https://www.itpro.com/security/369744/podcast-transcript-surveying-todays-threat-landscape" target="_blank" data-original-url="https://www.itpro.com/security/369744/podcast-transcript-surveying-todays-threat-landscape">global threat landscape</a>. </p><p>“One of the approaches I really like to focus on is the basics. There are basic controls that reduce 85% of cyber security risks,” he explains. “If you do those things well, the majority of your risk is reduced.” </p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52201813&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>The data-driven mindset Jason has adopted as part of his leadership style means he “doesn’t care about <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">certifications</a>”. "I’m a <a href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics" target="_blank" data-original-url="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics">data-driven</a> CISO,” he adds. “So, I want really well-defined metrics and I want to be able to measure the efficacy of what we are doing. Because, and to quote Peter Drucker, “if you can’t measure it, you can’t manage it.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications" data-original-url="/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications">IT Pro Panel: Do we still need certifications?</a></p></div></div><p>This is not to suggest that he doesn’t acknowledge the value in <a href="https://www.itpro.com/security/359719/what-is-a-soc-audit" target="_blank" data-original-url="https://www.itpro.com/security/359719/what-is-a-soc-audit">SOC 2</a> or ISO certification, but to Jason these are business requirements and often don’t truly reflect how effectively a team or organisation handles its security obligations. Simply put, by getting the basics right, these regulatory and compliance obligations should be something of an afterthought. </p><p>“For me it’s about asking, are we doing what we say we’re doing in our policies and standards? I could care less when SOC 2 comes in and says what we’re doing. I want to know that we’re doing our job effectively and covering this,” he explains. “I don’t want someone to tell me we’re doing a good job; I want the data to show it.” </p><h2 id="adapting-to-the-evolving-threat-landscape">Adapting to the evolving threat landscape</h2><p>It goes without saying that Jason joins Freshworks, a SaaS solutions provider, during a challenging period. Over the last two years, a series of deeply troubling attacks have rocked the global software supply chain, with the <a href="https://www.itpro.com/security/367644/five-eyes-leaders-issue-guidance-for-msps-to-prevent-second-solarwinds-attack" target="_blank" data-original-url="https://www.itpro.com/security/367644/five-eyes-leaders-issue-guidance-for-msps-to-prevent-second-solarwinds-attack">SolarWinds</a> and <a href="https://www.itpro.com/channel/369612/qa-fred-voccola-kaseya" target="_blank" data-original-url="https://www.itpro.com/channel/369612/qa-fred-voccola-kaseya">Kaseya</a> breaches arguably the standouts due to the scale and severity of their impact.</p><p>The <a href="https://www.itpro.com/security/vulnerability/360185/kaseya-patches-vsa-flaws-exploited-in-revil-ransomware-attack" data-original-url="https://www.itpro.com/security/vulnerability/360185/kaseya-patches-vsa-flaws-exploited-in-revil-ransomware-attack">Kaseya ransomware attack</a> in July 2021 saw thousands of customers and <a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service" target="_blank" data-original-url="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service">managed service providers (MSPs)</a> exposed. Similarly, the SolarWinds incident affected thousands of organisations worldwide, including several US Government departments. Noted as a landmark moment in the cyber security industry, Jason believes very few organisations would have seen the SolarWinds breach coming. He adds the situation is “only going to get worse”.</p><p>“With SolarWinds, probably one of the biggest and most famous supply chain issues, I guarantee you that 99% of companies with very mature third-party risk management programmes would not have seen that coming,” he says. “So even sometimes just having basic third-party risk management, you’re not going to be able to stop things like that.” </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Zs4CPG6JMVVr6PNeMcArVb" name="" alt="SolarWinds logo" src="https://cdn.mos.cms.futurecdn.net/Zs4CPG6JMVVr6PNeMcArVb.jpg" mos="https://cdn.mos.cms.futurecdn.net/Zs4CPG6JMVVr6PNeMcArVb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p><em><strong>The SolarWinds attack of late 2020 was one of the most significant in recent cyber security history</strong></em></p><p><a href="https://www.itpro.com/security/cyber-security/369082/c-suite-executives-say-software-supply-chain-hacks-have-become-chief-concern" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/369082/c-suite-executives-say-software-supply-chain-hacks-have-become-chief-concern">Cloudbees research</a> published last year found that C-suite executives are becoming increasingly concerned about software supply chain attacks in the two years since SolarWinds. While 40% were ‘somewhat more concerned’, 42% were ‘much more concerned’ of attacks, since 2019. </p><p>This growing issue has prompted a more robust approach from regulators and authorities. At present, there is a concerted focus on <a href="https://www.itpro.com/business/policy-legislation/368843/us-government-set-to-outlaw-leaky-software-in-military" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/368843/us-government-set-to-outlaw-leaky-software-in-military">Software Bill of Materials (SBOM)</a> – the equivalent of a food ingredients label outlining the various components found in software products. Jason welcomes this focus, noting that the move “is going to help incredibly” and enable organisations to mitigate growing risks. </p><p>Supply chain vulnerabilities aren’t the only issue that keeps Jason up at night, however. Across 2023 he believes one of the key threats that Freshworks and the broader industry will face is the increasing focus on <a href="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced" target="_blank" data-original-url="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced">APIs</a> among cyber criminals. </p><p><a href="https://salt.security/blog/api-security-fundamentals" target="_blank">Salt Security recently found</a> 95% of companies reported some form of API-related security incident across 2021/22, while another <a href="https://www.imperva.com/company/press_releases/vulnerable-apis-costing-businesses-up-to-75-billion-annually" target="_blank">study</a> revealed API vulnerabilities cost businesses up to $75 billion each year. With a rapidly evolving threat landscape, Jason believes businesses will continue to face API-related risks and highlighted the issue as a “top concern coming into the next year or two”.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369758/the-scariest-cyber-security-horror-stories-of-2022" data-original-url="/security/cyber-security/369758/the-scariest-cyber-security-horror-stories-of-2022">The scariest cyber security horror stories of 2022</a></p></div></div><p>A key factor in this rising problem, he notes, is the proliferation of APIs and their critical role in supporting businesses to provide services. “It’s becoming core to anybody who’s a SaaS company and core to many products,” he says. “Because of that growth [in APIs] sometimes security might not have played a key role in its development. When you’re growing a new technology, as we know, security often takes a back seat. </p><p>“Are all these APIs out there being developed securely? Not as secure as in other code areas. APIs are often overlooked. And because API security is more on the business logic side, I think there’s a lot of ripe opportunity for hackers to go after due to the proliferation and the scale of it.” </p><h2 id="shifting-left-to-combat-key-threats-in-2023">Shifting left to combat key threats in 2023</h2><p>Jason says Freshworks views API security as a key area of concern and, as such, he is placing a strong focus on mitigating risks. “My goal over the next year, and I know it’s one of the most overused marketing terms in security over the last few years – is to shift left,” he explains.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yseJUxqgZswHFUvY3v8Qr4" name="yseJUxqgZswHFUvY3v8Qr4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/yseJUxqgZswHFUvY3v8Qr4.png" mos="https://cdn.mos.cms.futurecdn.net/yseJUxqgZswHFUvY3v8Qr4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IBM LinuxONE for dummies</strong></p><p class="fancy-box__body-text">Secure your data, build an open hybrid cloud environment, and realise the cost benefits of consolidation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369851/ibm-linuxone-for-dummies" data-original-url="/security/369851/ibm-linuxone-for-dummies">FREE DOWNLOAD</a></p></div></div><p>Shifting left is a principle employed in <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer" target="_blank" data-original-url="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer">software development</a> which helps identify potentially troublesome flaws in products earlier on in the development process. In doing this, organisations can not only fine-tune products from a security standpoint earlier on, but deliver longer-term cost savings.</p><p>“This is a cost-saving thing,” Jason explains. “Because the further right you go before fixing bad code in production costs up to 700 times what it would have if you had caught it beforehand. There are a bunch of gates and chains in place within the lifecycle which mean you could spend $1 now to fix it, or $700 later on. This doesn’t include other factors such as breaches, or penalties and the costs associated with that bug exposing something bad.”</p><p>Despite contending with a challenging threat landscape and heightened security risks, Jason believes he joined Freshworks at an ideal time, and looks forward to the prospect of building on the company’s established security function and being part of the future growth journey. “I want to be there for the growth at Freshworks, and I want to scale with them and ensure that security is scalable.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Going passwordless ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless</link>
                                                                            <description>
                            <![CDATA[ Something you are, or something you have, could be more important than a password you know in the near future ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gFLpzoAsrEnfKmzKDL7anB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jan 2023 13:05:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Passwords: they can be tricky at the best of times. Proper password hygiene is one of the most important factors in endpoint security, as it keeps sensitive data secure and prevents threat actors from getting into important systems. </p><p>But despite the risks, the use of weak or recycled passwords continues to be a problem even amongst IT professionals. While systems such as two factor authentication have been used as an extra layer of security, groups like the FIDO Alliance and World Wide Web Consortium have been working to make passwords a thing of the past, in favour of more secure methods.</p><p>This week, we spoke to Richard Meeus, EMEA director of security & technology strategy for Akamai Technologies, to explore the solutions driving secure sign ons, and how the sector can adapt to this change.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights">Highlights</h2><p>“The criminals know that we are bad with passwords, and we just use something like our pet's name or something like that. And it's relatively easy for people to get the passwords or, as most commonly happens, an organisation will be breached and their password and username database will be leaked out onto the internet. And then, those usernames and passwords are reused against websites all over the planet.”</p><p>“The concept of security authentication has always been based around, sort of, one of three concepts. So there's something you know, which is a password, something you are, which is your biometric. So use your face print or your thumbprint, or something like that. Or something you have, which could be a USB token, or something that you can punch numbers into as a handheld device. So one of those three things, and we've relied upon the something you know, predominantly, which is the password.”</p><p>“Anything that we can do within security that actually makes lives easier for end users, and makes them more secure, is a good thing. And reducing passwords, reducing the use of passwords is a good thing, because nobody likes them.”</p><p><a href="https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless" data-original-url="https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></li><li><a href="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what" data-original-url="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what">If not passwords then what?</a></li><li><a href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">What are biometrics?</a></li><li><a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">What is two-factor authentication?</a></li><li><a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue" data-original-url="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">What is multi-factor authentication (MFA) fatigue and how do you defend against attacks?</a></li><li><a href="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication" data-original-url="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication">How to implement passwordless authentication</a></li><li><a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">Best password managers</a></li><li><a href="https://www.itpro.com/software/368045/best-free-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368045/best-free-password-managers-in-2022">Best free password managers</a></li><li><a href="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better" data-original-url="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better">The sooner the FIDO Alliance can shut down passwords, the better</a></li><li><a href="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security" data-original-url="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security">Will FIDO passwordless authentication save cyber security?</a></li><li><a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">The top 12 password-cracking techniques used by hackers</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: Going passwordless ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uoaH42Y3cyW7SJ5m8ruydz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jan 2023 12:40:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>​​This automatically-generated transcript is taken from the IT Pro Podcast episode</em> ‘<a href="https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless" data-original-url="https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless">Going passwordless</a>'. <em>We apologise for any errors.</em></p><h2 id="rory-bathgate">Rory Bathgate </h2><p>Hi, I'm Rory Bathgate. </p><h2 id="jane-mccallion">Jane McCallion </h2><p>And I'm Jane McCallion </p><h2 id="rory">Rory</h2><p>And you're listening to the IT Pro Podcast, where this week we're discussing passwordless security.</p><h2 id="jane">Jane </h2><p>Good password hygiene is one of the most important factors in endpoint security. If passwords are managed improperly, threat actors can access critical systems, and the use of weak or recycled passwords continues to be a problem even amongst IT professionals.</p><h2 id="rory-2">Rory </h2><p>In place of legacy systems such as one time passcodes sent via SMS, groups like the FIDO Alliance and World Wide Web Consortium are working to make passwords a thing of the past.</p><h2 id="jane-2">Jane </h2><p>Today, we're speaking to Richard Meeus, EMEA director of security & technology strategy for Akamai Technologies, to discuss the solutions that can enable more secure sign ons, and how the sector is handling this change. Richard, thank you for joining us.</p><h2 id="richard-meeus">Richard Meeus </h2><p>Thank you very much, delighted to be here.</p><h2 id="jane-3">Jane </h2><p>So everyone's been using passwords on their computers for decades. How come now they're being called insecure?</p><h2 id="richard">Richard</h2><p>Well, I don't think it's now that they're being thought of as being insecure, I think they've been insecure for a long time. I mean, passwords have been utilised as an authentication mechanism for centuries. And it's always been fairly trivial to find out what they were. What we've been doing recently is with a plethora of websites and services, especially after the pandemic that everybody went online. Everybody reused the same passwords. People, humans, users we're rubbish at passwords, we have a limited capacity to remember passwords. And therefore we tend to use the same one repeatedly. Or we just try and be very clever and add a ‘1’ to the end, to try and make it uncrackable. And because of this, the criminals know this, the criminals know that we are bad with passwords, and we just use something like our pet's name or something like that. And it's relatively easy for people to get the passwords or, as most commonly happens, an organisation will be breached and their password and username database will be leaked out onto the internet. And then, those usernames and passwords are reused against websites all over the planet. And if you look at some of the database repositories, the legitimate repositories which are used for you to see if you have had your username and password put out onto the internet, there's about 10 million — 10 billion sorry, username and password combinations in there. That's a lot more than the internet-connected population. In fact, it's about four times more than the internet connected population. So there's a good chance there's a criminal somewhere who has your username and your password, and is trying them on a number of websites. Right now. What we want to do is move to a situation where that risk is mitigated to a certain degree.</p><h2 id="rory-3">Rory </h2><p>With this risk of reusing passwords, certainly, or generating weak passwords. I know that a lot of businesses rely on things like password managers, can those be continued to be relied upon by businesses?</p><h2 id="richard-2">Richard </h2><p>I think password managers, as well as with organisations looking to protect their users, it's important that password managers are used properly. A password manager is a great tool, I use one for my home business use for creating complex passwords, complex unique passwords. So I don't know what my passwords are, because they are a random bunch of 25 alphanumeric and special characters. I have no idea what they are. And the password manager remembers that, so every single asset that I talk to has a unique password. Password managers, I think, are very useful especially in the short term and within enterprises. It's not so great for end users because the vulnerable people in society, and people who are not familiar with technology, may find them quite difficult to use. But in enterprises they're certainly very useful because it allows you to create complex, distinct, unique user passwords for every single application that you go to. My passwords are often 25 characters long and a stream of unrecognisable characters, and numbers, and estimation marks, and question marks, and special characters that will be impossible to guess or impossible to do a brute force hack upon. So I think they definitely have a position, especially in the enterprise.</p><h2 id="jane-4">Jane </h2><p>I mean, Richard, once again, I also use password managers. Are there risks associated with those? Recently we have seen LastPass, breached. And every time I see something like that my heart goes in my mouth. And then you realise, actually, your passwords are typically safe. But is there any kind of real chance that either the database itself could be breached particularly say, if you're reusing password for them? Or something a bit more sophisticated than that?</p><h2 id="richard-3">Richard</h2><p>Well, I think a lot of the time, there's always been that concern about “if I put all my eggs in one basket, is that creating more of a risk? I think that's been the typical response to people not wanting to use password managers. But I think when you actually look at the security that is around the actual passwords, and how they're stored and how they're utilised, I think that that overweighs any of that concern about the risk about having all your passwords in one basket, or eggs in one basket. So I don't think there's a chance that if you, people do use them, I think they are very good, they're very useful. It again, outweighs the risk of just having very simple passwords that you can try to remember.</p><h2 id="jane-5">Jane </h2><p>Yeah. </p><h2 id="rory-4">Rory </h2><p>So in response to this, to focus on passwordless security as an option. When someone says passwordless security, I mainly think of biometric security, fingerprints, facial recognition. Is this the most promising avenue for this technology? And what are some of the other methods that are in place?</p><h2 id="richard-4">Richard</h2><p>Yeah, well I mean the concept of security authentication has always been based around sort of one of three concepts. So there's something you know, which is a password, something you are, which is your biometric. So use your face print or your thumbprint, or something like that. Or something you have, which could be a USB token, or something that you can punch numbers into as a handheld device. So one of those three things, and we've relied upon the something you know, predominantly, which is the password. And we tend to use the something you have, like the USB key, or the something you are like the biometrics as an additional level and commonly called this is like two factor or multi factor authentication. So that what the concept is of going passwordless, is actually shifting away from using passwords as the primary method of authentication. And say, why do we need to use passwords as a primary, when we can use one of the other two, such as having a hardware device or using biometrics to do that first part of authentication? Obviously, there are many benefits to using the hardware device, or your thumbprint, or your face print. Because they're not likely to have the same level of simplicity around them. You know, it's not going to be quite as simple as password 123, when you're talking about your thumbprint, so there's a lot of sort of intrinsic benefit to that already.</p><h2 id="jane-6">Jane </h2><p>I mean, when we're talking about this, we've sort of talked to him a little bit. When we talk about passwords you're speaking about moving the second part of two factor authentication to the front, the something you have, the something you are. Are we talking about getting rid of passwords completely, or do they become the second part of this 2FA? Or is it going to be my face and my token?</p><h2 id="richard-5">Richard</h2><p>Passwords can still be used, but I would suggest that they are taken away largely completely, because they prove that they can't really be utilised effectively or securely. Certainly, if you have a three factor authentication it’s often used when you're going into very secure facilities. Where you have to sort of take in your access card, do a thumbprint, and then you have to type a PIN code in there. And then the PIN code would be sort of synonymous with your normal password. So that sort of three factor authentication will still be relevant in a lot of cases. But I think the concept of using a password to log on to a website will eventually go away, because it's not an effective way to access that level and proportionate that level risk.</p><h2 id="rory-5">Rory </h2><p>And when you're talking about, I guess, in some cases this is consumers would be able to use, say a passkey, a physical passkey to verify their identity on a multitude of different accounts. In an enterprise model, could this be hard to, this specific something you have, could that be hard to implement in that if you left the company, you'd have to return what you had. It would potentially be harder than do changing a password?</p><h2 id="richard-6">Richard</h2><p>Absolutely, I think the same thing you have part is an interesting concept about what it can actually be. And something, because I think everybody's sort of familiar with the, the old dongles which have the sort of rotating password pass key on them, that have been around from people like RSA for many, many years. And if you look in your desk drawer, you'll probably find two or three of them where the batteries died that you've had from many years ago. And that's not an unusual situation. And so there is an overhead to managing all those additional keys, and people will forget them, people will lose them. So there is an additional overhead in terms of that. So ideally, you want to try and use something that you already have, and you're never likely to let go of. And that's probably something like a mobile phone. And you can use a mobile phone as the something you have component. And it also allows you to do the something you are component because it allows you to do, especially with the modern smartphones, the biometrics and things like facial recognition and fingerprint recognition.</p><h2 id="jane-7">Jane </h2><p>And I suppose if you've got company provided phones, then it's as easy as just returning the phone or remotely wiping it or any of that kind of thing if somebody leaves the company but they are, for whatever reason, not returning the phone.</p><h2 id="richard-7">Richard</h2><p>Yes, if you're provided a company phone you will normally have some sort of MDM, some mobile device management software on the phone. Whereas as soon as they leave the company or as soon as the employment is terminated, then it's a question of just hitting a button on the central console and it would remove any of those components. </p><h2 id="jane-8">Jane </h2><p>Yeah, I've thought of all kinds of nefarious things for employees to do. I think most of us more inclined to sort of lose our phone, on a train or whatever as well. </p><h2 id="richard-8">Richard </h2><p>Yeah,absolutely. But also remembering that without the knowledge of where you're going, and what you're going to, because you still have to get the thumbprint to actually authenticate because it's part of that you would have something you have, something you are. Smartphones make it very easy to do two factor authentication, by taking the biometrics and the something you have. So that gives you the two factor based on that. So if you do lose your phone, they may be able to guess the pin number or the swipe pattern you have to get into the phone. But it's unlikely then they'll have the biometrics to actually get through the next level, to get on to the corporate assets as required. </p><h2 id="jane-9">Jane</h2><p>Sure.</p><h2 id="rory-6">Rory </h2><p>Through things like FIDO, there's been talks — I know that some manufacturers at Google Apple, Microsoft, have been in talks — to standardise this kind of technology that you're talking about. So that regardless of the hardware you were using, like the standardised keys across either your business interactions, or on a consumer basis across all of your different accounts, do you think a unified approach like that will be necessary to avoid there being a different kind of tool sprawl for businesses and consumers in the future where they're having to oh, you know, “which passkey am I going to be doing through my phone?”</p><h2 id="richard-9">Richard</h2><p>I think there's going to be an argument for that. Not quite sure what things are going to happen in the short term, but it remains to be seen. I do think the work that FIDO is doing to promote easier and more secure access online is something that will be followed by more and more organisations. The current iteration, which is FIDO2, so fast identity online version two, even goes so far as to provide solutions that allow you to do phish proof MFA, because that is also a problem with MFA. It's not 100%. It's a lot better than not having multi factor authentication. But MFA is not 100%, and with the next generation, which is FIDO2, it will be phish proof. Again, it's never going to be 100%, but it's going to be a lot closer to where we want it to be.</p><h2 id="jane-10">Jane </h2><p>So Richard, you've mentioned, FIDO2 briefly there. Could you tell us a bit more sort of what that's about?</p><h2 id="richard-10">Richard</h2><p>Yeah, so FIDO2 is a methodology to make MFA sort of even better, because surprisingly, MFA doesn't solve all problems. You know, we think that it's going to address all of our authentication issues, but it doesn't and there's been several organisations that have been breached fairly publicly. So a very well known video game manufacturer, a well known taxi company, a global taxi company has recently been breached by what's called an MFA bypass. And an MFA bypass technique basically means that the device is talking to the website or the application, and the device that is doing the multi factor authentication are not linked. So this means that if you have stolen credentials, you can put those into the asset, put those into the website, the website will respond with an MFA challenge. And the attackers realise that the MFA challenge is going to be sent to the user, and they will try and persuade them to actually accept the challenge. And it's surprisingly easy to do that, with things like push MFA challenges. If you start sending people that at 3am in the morning, it's remarkable how quickly people will just click on ‘accept’, rather than have to listen to the bing, bing, bing, bing, bing, bing, constantly being reminded in the middle of the night. And this is what's happened to many, many organisations, is that because the device that’s making the request to the asset and the device are not linked, you can get this what's called push MFA or MFA bypass. So what FIDO2 wants to do is to locally connect the devices making the request to the origin and your external device. Now, you can do this through a USB key, plug the USB key into your device, they're now locally linked. Or you can do it through NFC, or you can do it as we do with Akamai, you can link them together through cryptographic keys. So my phone and my laptop are cryptographically linked, which basically means that the MFA is not valid unless it comes from my laptop. So if my credentials are stolen, and somebody tries to log in in another part of the world, and then tries to do a push MFA exertion on me, it won't even happen because the request has to come from my laptop. And this is what FIDO2 is doing, it’s ensuring that local MFA connectivity before it actually goes on to the next stage. And by doing this, it gets round a lot of the big MFA bypasses that have happened this year.</p><h2 id="jane-11">Jane </h2><p>So this all sounds really great. And as a consumer, I can see myself adopting it. I already have, I use my thumb on my phone, people use their faces on their phone. And, you know, really consumers can turn on a penny when it comes to adopting new technology, anything like that. For businesses, it can be a little bit more difficult, especially if there's some kind of integration that they need to do with legacy systems. So how quickly can that be done? I mean, is it a problem? Am I throwing up a problem where one doesn't exist? But if I'm not, how can this be managed, and how quickly can things change?</p><h2 id="richard-11">Richard</h2><p>I think with enterprise, it'll be a lot easier than it will be for consumers. For two different reasons. The main reason for consumers is that there will be a long tail of users who, for want of a better word, maybe a sort of Luddite about adopting the new technology. There are many people who don't want to have a smartphone with biometric controls on them for whatever reason. So for a service, such as public services, public sector, where they have to provide a fully inclusive service, there's gonna be a long tail of people there who won't fit into the parameters where you can do that full technology, but for multi factor authentication using biometrics or smartphone, so there will have to be solutions there to cater for those people. But with the enterprise, you have a lot more control. And you can certainly start linking all of your assets to talk to a central identity provider, be it Active Directory or some other form. And once you have authenticated with your main IDP, your main identity provider that can provide authentication tokens to every single other device within your estate, meaning once you're logged in, you're logged in across your estate. And that identity is protected by authentication through multifactor.</p><h2 id="jane-12">Jane </h2><p>So the other way around to what you find quite often then, is that for businesses actually, this is quite easy. I mean, are there any sort of key hurdles that might hold up passwordless security in businesses or is it really just as easy as kind of going, “right this is our, you know, the method that we do now internally, at least. And, and off we go”?</p><h2 id="richard-12">Richard</h2><p>There's always going to be some legacy applications that don't have the ability to use authentication. So there's a functionalities like OAuth, which allows applications to be authenticated elsewhere. If they don't have the functionality to have that capability, then you're going to have to have another way of authenticating with those legacy applications. So it's not necessarily going to be applicable across the board. But most modern organisations will have the facility to deploy the majority of their applications through that one password, or one authentication process, and then being able to pass that assertion through to all the relevant applications.</p><h2 id="rory-7">Rory </h2><p>Do you think that implementing a system like this might also help with oversight of who has access to which systems? Because currently, obviously with passwords, it's very easy within an organisation for someone to ping a password across on a Google chat to someone who maybe shouldn't have access to, to a back end system. So using authenticators might also improve observability across the system?</p><h2 id="richard-13">Richard </h2><p>I think there's a potential for that, I think that where that particular area’s going is more into is looking at the authorisation component. So with identity, you’ve got the identification, which is the username, you've got the authorisation. Sorry, the authentication, which is the something you are, something you have, something you are. And then there's the authorisation component, and authorisation is something that's being looked at when you look at things like zero-trust network access, which is a way of giving users access just to applications that they need. So it's really sort of going down heavy on lease privilege. This is a really good way to ensure that only the users authorised to access an application, get that level of access. Which means that anybody else does not have that level of access. So, if you gave somebody else a password, you'd have to have the username and have the password, but they still wouldn't be authorised, they still wouldn't physically be able to get to that particular asset. And I think that's why a lot of organisations are looking into it. Because I know zero trust is a word that bandied around a lot with, with wanton carelessness, sometimes, but it fundamentally comes down to lease privilege, which is something that IT professionals have been familiar with for many, many years. And that's where it's trying to get to, if you don't have the right identity, authentication and authorisation, you can't actually get to that application.</p><h2 id="jane-13">Jane </h2><p>So Richard, if the worst does happen, and a business is hit by a cyberattack, can using a passwordless solution help minimise the impact? Or does it just minimise the risk?</p><h2 id="richard-14">Richard</h2><p>That's a really good question. I think initially, it minimises the risk. Because I think if you, there was a report I think in the Verizon data breach incident report last year, that credential vulnerabilities were responsible for 84% of all breaches. So if you can get to addressing that vulnerability, that reduces the risk significantly of having a breach. So I think that's the first aspect. Once somebody has got inside your organisation, then absolutely, having good identity controls is in place, but it's a little bit late at that point, you then need to be looking at other security elements to be able to protect your organisation. And that can be through things like zero trust, network access, or micro segmentation to throw another technology into the mix to prevent them moving laterally through your organisation. But I think this is where passwords can be used, especially within the enterprise as part of a layered security model of trying to reduce the risk at all levels, reduce the level at authentication time, reduce the risk at connection time, whether connecting via IP or just the application layer, and then reducing the risk of moving throughout an organisation when deployed as part of a managed strategy, then you're able to reduce the risk at all levels as best as possible.</p><h2 id="jane-14">Jane </h2><p>Yeah, and I think you've kind of hit on something important there really, which is whether this is passwordless or really any other kind of security technology, or any technology, that it's not a panacea, it's not a cure-all, it has to be used as part of a wider security strategy. Whether that's training or like you say, other technologies that can help the progress or at least to slow the progress of anybody who's staging an attack. Is that a fair observation?</p><h2 id="richard-15">Richard</h2><p>Absolutely. I think that there aren’t many things that as security professionals we can do, that actually makes things easier for end users. Normally, we are seen as the Department of No, the Fun Police. So I think that anything that we can do within security that actually makes lives easier for end users, and makes them more secure, is a good thing. And reducing passwords, reducing the use of passwords is a good thing, because nobody likes them. Nobody likes them, nobody likes trying to have to remember them. There's always a challenge, there’s always some times you forget, or whatever. It's a problem. It's a massive security risk. So getting rid of that pain point from users would be a boon I would say.</p><h2 id="rory-8">Rory </h2><p>So you think that there's real potential for this to improve, maybe, productivity within the workforces? Or at least improve the use of access for vital systems within workforces?</p><h2 id="richard-16">Richard</h2><p>Absolutely. I think when you look at most organisations where you have, you know, probably thousands of applications within an organisation, although most users will only have access or need to use 10 or 20 of them. The ability to reduce the access to just the applications you need, and the ability to have to worry about a password is fantastic. At Akamai we've been passwordless for many years now. So I don't use a password to log on. I don't use a password to access applications, it's just all done through passwordless technology. And that makes it a lot easier for me not having to worry about, “oh, I need to access that particular system. Where is it located? What password do I need?” All that, it's a lot easier to use? And yes, it's anything that gets rid of that, “oh, what's the password for that application that I haven't used for two months?” Anything gets around that problem, which everybody has, if you can get if you can solve it, it's bound to help all sorts of users.</p><h2 id="jane-15">Jane </h2><p>So Richard, at Akamai you are ahead of the curve. But how far away do you think we are from universal adoption of this kind of security across businesses?</p><h2 id="richard-17">Richard</h2><p>I think that's a very difficult question. Because there are many companies and many verticals that are on all sorts of that journey, all different areas of the passwordless adoption journey. I think people will want to go there because the benefits are manifold. But there is always going to be an issue with inclusivity. Because you have to make sure that everybody is catered for. And if you can't cater to everybody, then there's always going to be an issue. So in the consumer space, I think it's going to be utilised to enable users, I still think you're going to have to have passwords for inclusivity. But if you're using it in the consumer space, and you want to get access to all of your favourite music sites, or TV sites, or shopping sites without having to remember a password all the time, I think people are going to embrace that. And that it will be seen as a benefit not only for the consumers, but also the vendors as well. In the enterprise space, I think that organisations will want to go down this level to a certain degree, I think there's always going to be legacy applications that won't suit that. Or the infrastructure will not benefit it as a whole. But I think overall, it's certainly a methodology that will be broadly adapted. The big vendors, as you mentioned at the beginning, are doing this. Microsoft has things like Microsoft Hello, which allows you to do passwordless authentication. It's something that's being adopted through many different vectors, so it will increase. Am I going to put a date on it and say you have no more passwords in five years. That’s a crystal ball I would love to have, but I couldn't say that.</p><h2 id="jane-16">Jane </h2><p>No fun, no fun.</p><h2 id="rory-9">Rory </h2><p>Well, Richard, thank you so much for being on the show.</p><h2 id="richard-18">Richard</h2><p>Thank you Rory, thank you Jane. It's been a pleasure. Thank you very much indeed for having me.</p><h2 id="jane-17">Jane </h2><p>Thank you. As always, you can find links to all of the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk</p><h2 id="rory-10">Rory </h2><p>You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro podcast wherever you find podcasts. And if you're enjoying the show, leave us a rating and a review</p><h2 id="jane-18">Jane </h2><p>I will be back next week with more from the world of it but until then goodbye. </p><h2 id="rory-11">Rory</h2><p>Goodbye</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lab-based cyber attacks are no serious threat – yet ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/369536/lab-based-cyber-attacks-are-no-serious-threat-yet</link>
                                                                            <description>
                            <![CDATA[ There’s no need to fret when it comes to research-based cyber security threats, but the future is a different matter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3WjC8JbuWeYZVeSVvx9W3N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dXT8s6c5LBeXubNquhNhG5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 19 Nov 2022 08:00:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dXT8s6c5LBeXubNquhNhG5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cyber security researcher at their desk]]></media:description>                                                            <media:text><![CDATA[A cyber security researcher at their desk]]></media:text>
                                <media:title type="plain"><![CDATA[A cyber security researcher at their desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dXT8s6c5LBeXubNquhNhG5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most cyber scare stories have more in common with horror fiction than practical reality, and I’m not talking purely about the hyped-up cyber warfare stuff that appears online. Me being me, I’m focussed on the hacking threat stuff. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361839/the-scariest-security-horror-stories-of-2021" data-original-url="/security/cyber-security/361839/the-scariest-security-horror-stories-of-2021">The scariest security horror stories of 2021</a></p></div></div><p>Admittedly, I have a thirst for oddball <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> research papers, but there’s a secret to digesting these papers in a way so as not to confuse the theoretical risk with the practical one. There’s a huge difference between fascinating research work, conducted by hugely talented folk, and the practical risk you are likely to be exposed to as a result of it. </p><p>This isn’t to say that such research is pointless; far from it in fact. The most technologically fanciful lab-based threats can evolve into very real-world ones, albeit often bearing little resemblance to the original. There are three fascinating pieces of research that stand out, and all fall down as far as the current real-world threat stakes are concerned. </p><h2 id="attack-of-the-mechanical-keyboards">Attack of the mechanical keyboards</h2><p>Let’s start with Keytap3, which immediately announces it has already evolved somewhat from the original research by Georgi Gerganov. The name also suggests, quite rightly, that this involves typing. </p><p>That involvement is an attempt to be able to remotely and quite literally listen in to what you are typing and then convert that audio into written output. It does this by analysing n-gram frequency – the contiguous sequence of items in a sample – of recorded audio clusters. </p><p>Gerganov isn’t the first to look into this as a spying methodology, nor will he be the last, and I applaud him for his efforts so far. Despite, I have to say, my not being able to replicate the success he has had in the lab when taking part in a demonstration of the technology. You can try it by visiting the <a href="http://keytap3.ggerganov.com" target="_blank">demo website</a> and allowing your typing audio to be analysed. </p><p>Gerganov says he doesn’t have access to the recordings, as the test runs within your client browser and none of the data is uploaded or stored by the researcher. This is one of the reasons the results are poor: without the wider input data from a broad, real-world, range of both <a href="https://www.itpro.com/hardware/360286/best-business-keyboards" target="_blank" data-original-url="https://www.itpro.com/hardware/360286/best-business-keyboards">keyboards</a> and microphones, plus different typing speeds and styles, the experiment is likely to perform best with the variables it understands from the lab development. </p><p>“One possible explanation for the results that you observe is that simply Keytap3 is somehow overfitted to my setup or style,” he tells me. “Even though I have tried to keep the implementation as general as possible, without making unnecessary assumptions about the typing style or the devices (keyboard and mic) it is still possible that the <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm" target="_blank" data-original-url="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithm</a> performs well only in the limited set of environments that I have tested it with.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/360286/best-business-keyboards" data-original-url="/hardware/360286/best-business-keyboards">Best business keyboards for 2023: Top choices for homeworkers and the office</a></p></div></div><p>GGerganov only has two <a href="https://www.itpro.com/hardware/360300/5-best-mechanical-keyboards-of-2021" target="_blank" data-original-url="https://www.itpro.com/hardware/360300/5-best-mechanical-keyboards-of-2021">mechanical keyboards</a> and says the results are “pretty good” when using that small set of data points. He would welcome more data from participants of the demo: it’s up to you whether or not to upload the recording after the demo so that he can broaden the input data.</p><p>In case you’re wondering, he doesn’t think typing speed is a huge factor. Instead, the main factor is the ability to match key sounds to determine if separate sounds are made by the same key, for example. “Currently, Keytap uses a time-domain cross-correlation metric to match the keys with one another and it is definitely not perfect,” Gerganov says, before adding he was surprised it performs as well as it does. He’s currently working on improving the algorithm using frequency-domain metrics. </p><h2 id="ghost-touch-doesn-t-send-shivers-down-my-spine">‘Ghost touch’ doesn’t send shivers down my spine</h2><p>Next up is an experimental <a href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy" target="_blank" data-original-url="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy">smartphone</a> threat vector that grabbed my attention by virtue of being one that works with both iPhone and Android devices. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sr7PL6RyX4xfWCPshjfCie" name="sr7PL6RyX4xfWCPshjfCie.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" mos="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a better password strategy for your business</strong></p><p class="fancy-box__body-text">Exploring the strategies and exploits that hackers are using to circumvent password security measures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369393/building-a-better-password-strategy-for-your-business" data-original-url="/security/369393/building-a-better-password-strategy-for-your-business">FREE DOWNLOAD</a></p></div></div><p>There are always ways into devices, although most of them require either temporary physical ownership of the device or the actual owner to have installed something malicious. Or, in the case of <a href="https://www.itpro.com/security/cyber-attacks/361932/fbi-warning-badusb-attacks-us-businesses" target="_blank" data-original-url="https://www.itpro.com/security/cyber-attacks/361932/fbi-warning-badusb-attacks-us-businesses">BadUSB attacks</a>, a subtle combination of the two. Rather than ownership of the phone, BadUSB attacks require ownership, or usage of, a malicious memory drive or even a specially crafted data/charging cable. The Wired Ghost Touch (WIGHT) attack model uses the malicious charging port approach. The type of cable is irrelevant, and bypassing data blockers allows attackers to remotely “swipe” the touchscreen. </p><p>Researchers from the Zhejiang University, China and two from the Technical University of Darmstadt, Germany, have <a href="https://www.computer.org/csdl/proceedings-article/sp/2022/131600b537/1FlQCm4Upqg" target="_blank">demonstrated how this works</a> using both a <a href="https://www.itpro.com/mobile/mobile-phones/354749/samsung-galaxy-s20-hands-on-review-another-slam-dunk" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/354749/samsung-galaxy-s20-hands-on-review-another-slam-dunk">Samsung Galaxy S20</a> and an <a href="https://www.itpro.com/operating-systems/ios/356703/apple-iphone-se-2020-review-cheap-at-twice-the-price" target="_blank" data-original-url="https://www.itpro.com/operating-systems/ios/356703/apple-iphone-se-2020-review-cheap-at-twice-the-price">Apple iPhone SE</a>, and some other less popular smartphones. </p><p>It works by injecting specially crafted “malicious noise” signals that evade noise reduction and voltage management filtering while still impacting the capacitive touchscreen measurement systems. In fact, the researchers say they can perform three attack types by syncing the injected noise with the device touchscreen scanning cycle: a “ghost touch” that doesn’t require physical user input, an “alteration attack” that changes the actually touched position to another, and a denial of service that prevents any touch from being recognised. </p><p>I’ve read about previous ghost touch research but that all requires the target device to be screen-down and within a few millimetres of a table or desktop, with some cumbersome equipment installed underneath. For me, that reduces the threat level to negative, as even a highly targeted individual that would merit such attention would almost certainly already have defensive measures in place to defeat it. </p><p>The WIGHT model doesn’t require data access permission from the USB cable, which is a plus point, nor does the electromagnetic radiation approach of those under-the-table devices. Instead, by injecting a common-mode signal that can’t be absolutely filtered but still produces a differential-mode signal, thanks to asymmetric circuits, the necessary touchscreen interference can be achieved. </p><p>It’s a lot more advanced than Keytap3, but still doesn’t give me the collywobbles, nor should it you, because the touchscreen positioning precision remains in the 50/50 ballpark. </p><p>There is one scary aspect to the attack methodology, though. The researchers say that as the attack signal is a high-voltage alternating current, it could give a smartphone user a very nasty shock outside of carefully controlled lab conditions.</p><h2 id="scary-in-a-minority-report-kind-of-a-way">Scary in a Minority Report kind of a way</h2><p>What if your account was compromised <em>before</em> you opened it? Although this might sound like a third entry in the “that doesn’t apply to real-world, labs-based threat research” stakes, it isn’t. This threat vector sounds unbelievable – but it’s actually doable right now. Researchers found that 35 of 75 leading web services were vulnerable in some way or other. </p><p>The work, using a Microsoft Security Response Centre (MSRC) grant, was undertaken by independent security researcher Avinash Sudhodanan and Microsoft senior researcher Andrew Paverd. The <a href="https://arxiv.org/abs/2205.10174" target="_blank">research paper</a> is well worth a read and a genuine;y worrying one. </p><p>Andrew Paverd describes it as a “new class of attacks affecting websites and other online services”. It’s scary precisely because a cyber criminal can gain access to an account before you even create it. It gets worse, in that they could then take over that account once you have. It has a kind of <em>Minority Report</em> feel to it – but is far from a fictional fancy. </p><p><strong><iframe src="https://widget.spreaker.com/player?episode_id=44556716&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019" width="100%" height="200px" frameborder="0"></strong></iframe></strong></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting" data-original-url="/security/cyber-security/368481/what-is-threat-hunting">What is threat hunting?</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xNmKJxzCRh6XRqz4cwbq2W" name="xNmKJxzCRh6XRqz4cwbq2W.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/xNmKJxzCRh6XRqz4cwbq2W.png" mos="https://cdn.mos.cms.futurecdn.net/xNmKJxzCRh6XRqz4cwbq2W.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Enabling secure hybrid learning in schools</strong></p><p class="fancy-box__body-text">The importance of creating security awareness among key players</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369505/enabling-secure-hybrid-learning-in-schools" data-original-url="/security/369505/enabling-secure-hybrid-learning-in-schools">FREE DOWNLOAD</a></p></div></div><p>Using one of five different attack scenarios, an attacker creates an account for a web service that’s subsequently reactivated by a user and then, having given them time to use the account and add value by way of financial and other data, subsequently retakes control. The five methods require differing scenarios to play out and involve exploiting a weakness in the merging of classic and federated accounts: not signing users out after a <a href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">password reset</a>; <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus" target="_blank" data-original-url="https://www.itpro.com/security/30081/what-is-a-trojan-virus">Trojan</a> identifiers; a failure to invalidate email change capability URLs in the password reset process; and by exploiting a non-verifying Identity Provider vulnerability. </p><p>It’s all rather complicated, but you can’t ignore the test result of almost half of the service providers targeted falling victim. That said, it’s not a given that it works even beyond that 50/50 test result. It requires a user not to have joined a service yet, the attacker to know that fact along with them wanting to start using it at some point soon, and the email address they will use – which is a stretch. </p><p>It also requires the web service in question not to send a verification email to the user-provided address while at the same time preventing any further actions until that verification had been received. Using unique email addresses for every account would also effectively mitigate the success of such an attack, and the ease with which this can be achieved these days it’s a route I’d recommend. Not least as unique email identifiers, especially when also used as account login usernames, makes other attack scenarios harder to pull off as well. Win-win.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>