Latest Publications

Share:

After Supreme Court Upholds Ban, Trump Issues EO Giving TikTok an Extension

Despite bipartisan support for banning TikTok – essentially spyware presenting a national security threat from the People’s Republic of China (PRC) – in the United States (as done by India) and the Supreme Court’s upholding...more

Trump Rescinds Biden’s AI EO

Well, it was good while it lasted. Former President Biden issued an Executive Order (EO) in October 2023 designed to start the discussion and development of guardrails around using artificial intelligence (AI) in the United...more

Privacy Tip #428 – Getting Text Messages From E-ZPass or Toll Road Operators? They’re Scams Coming from China

This week, I received a fake text message (a smish) saying my E-ZPass account was overdue and that I urgently needed to pay it. That’s a new one and, apparently, quite effective. Luckily, I knew it was a scam, but others were...more

Privacy Tip #426 – CyberArk Report Confirms Employees Bypass Cybersecurity Policies

CyberArk, an identity security provider, has issued a new report on employee risk that is a must-read for IT Professionals and executives. The report highlights several findings that are directly related to the risks...more

Rhysida Hits American Addiction Centers + Publishes 2.8TB of Data

American Addiction Centers (AAC) has notified 422,424 individuals that their personal information was stolen in a cyber-attack attributed to the Rhysida criminal organization. The incident was discovered on September 26,...more

Ascension Health Notifying 5.6 Million of Data Breach

We previously reported that Ascension Health detected a cyber-attack on May 8, 2024, that affected clinical operations in Ascension facilities in six states....more

Adobe Issues Patches for ColdFusion “High Severity” Vulnerability

Adobe recently issued a patch for a high-severity vulnerability for ColdFusion versions 2023.11 and 2021.17 and earlier; according to the National Institute of Standards and Technology  (NIST), “an attacker could exploit this...more

Supreme Court to Hear TikTok Case

The United States Supreme Court announced on December 18, 2024, that it will hear the TikTok ban case and has scheduled oral arguments to be held on January 10, 2025, before the ban’s effective date of January 19, 2025....more

Privacy Tip #425 – Late Shoppers: Beware of Scammers Sending You to Fake Websites

Scammers prey on us when we are most vulnerable. Although some of us are early holiday shoppers, others wait until the last minute to complete their holiday shopping....more

Cl0p Exploiting Cleo Software

According to Cyberscoop, the cyber gang Cl0p “has claimed responsibility for attacks tied to vulnerabilities in software made by Cleo, an Illinois-based IT company that sells various types of enterprise software.” The gang...more

Privacy Tip #424 – Recent Big Win for Law Enforcement Over Cybercriminals

I often get asked whether law enforcement is making any headway in catching cybercriminals. Although it is a challenging task, a recent example of a big win for law enforcement deserves celebration....more

OCR Active with Settlements and Enforcement Actions in November and Early December

The Office for Civil Rights of the Department of Health and Human Services (OCR) was busy negotiating and settling enforcement actions in November and early December. Since October 31, 2024, the OCR has settled five separate...more

Rhode Island Becomes First State to Implement PDNS in All School Districts

My home state of Rhode Island may be the smallest in the union, but it has taken on a significant initiative to implement the Protective Domain Name Service (PDNS) in all 64 public school districts. PDNS, an initiative...more

FTC Settles with Companies Over Sale of Sensitive Data

The Federal Trade Commission (FTC) has been on a mission to get the message across that it is serious about companies collecting, using, and selling sensitive location data of consumers and that it is closely watching these...more

Privacy Tip #423 – FTC Files Complaint Against Mobilewalla for Selling Consumers’ Precise Location Data

I have commented before that I do not enable location-based services unless I use an app that requires it, like a ride-sharing app or directions. One of the reasons is to prevent data brokers and others from using precise...more

Telecoms Still Trying to Evict Salt Typhoon

According to statements by the Cybersecurity and Infrastructure Security Agency (CISA), the People’s Republic of China-backed (PRC) hacking group Salt Typhoon, which attacked telecommunications providers last month, is still...more

Enfield, NH Victim of $742K Wire Fraud Scheme

The Town of Enfield, New Hampshire, appears to have been the victim of a man-in-the-middle scheme involving the transfer of $742,000 to a fraudulent bank account. The town is constructing a new $7.2 million public safety...more

Chinese Manufactured Batteries Pose Cybersecurity Threat to Critical Infrastructure

The U.S.-China Economic and Security Review Commission, released its annual report to Congress this month.  The 793-page report responds to the Commission’s mandate to “monitor, investigate, and report to Congress on the...more

Privacy Tip #422 – Youville: For You and Your Kids Aged 8-12

The Federal Trade Commission provides consumers with tips and advice, including online privacy. Its Scam Alerts are helpful and timely....more

Privacy Tip #421 – Threat Actors Using DocuSign API to Send Fake Invoices

DocuSign is a great and efficient way to obtain authentic signatures for contracts and invoices. As with other efficient tools, threat actors will and have found a way to use the DocuSign API to send fake invoices to divert...more

Joint Advisory Lists Top Routinely Exploited Vulnerabilities

On November 12, 2024, the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the National Security Agency, along with its security partners in Australia, Canada, New Zealand, and the...more

Privacy Tip #420 – Is that Consumer Review Real or Generated by AI?

I admit that when I am looking online for restaurants, consumer products, and places to stay, I generally look at reviews and they influence my decision. However, there have been numerous reports that reviews are often fake...more

Columbus, Ohio Notifies 500,000 of Data Breach from Ransomware Attack

The city of Columbus, Ohio, announced on May 29, 2024, that it was forced to take its systems offline due to a ransomware attack. According to its notice, the attack was perpetrated by “an established, sophisticated threat...more

The Impact of Stolen Credentials

This week, Schneider Electric confirmed that it is investigating a security incident involving its JIRA internal development platform. The attacker group, “Grep,” allege that it stole 40 GB of data from the JIRA platform by...more

Scary Halloween News: Jumpy Pisces Using Play Ransomware to Attack Organizations

Unit 42 recently reported that it has identified “Jumpy Pisces, a North Korean state-sponsored threat group associated with the Reconnaissance General Bureau of the Korean People’s Army, as a key player in a recent ransomware...more

2,195 Results
 / 
View per page
Page: of 88

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide