read.cash Log in

@M.Rosenquist

Joined 22 January 2020 · 411 posts

Cybersecuirty strategist and technologist focused on making digital technology trustworthy

120 KT

0 KT · $23.59 received · 0 KT · 8¢ given

Posts

@M.Rosenquist

Ransomware Explained  - How to Reduce Exposure https://www.youtube.com/watch?v=njXi-NoLZiQ Ransomware is one of the most devastating challenges in cybersecurity today. The attacks are vicious, expensive, impactful, and becoming commonplace. Over the years I have predicted its rise, discussed why it is so challenging, debunked myths like blaming cryptocurrency as a cause, and even strategized how undermine ransomware at it roots! But today, I want to dive deeper into the tactical side of things and explore what ransomware is, how attacks typically unfold, and what potential victims can do to reduce their exposure and protect themselves. Mike Gurau from Vizitek and I co-developed this interactive site, which you can visit at http://bit.ly/3XLKxYB If you like insights about cybersecurity, be sure to like subscribe: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Locked In - The Cybersecurity Event of the Year This is how to redefine CISO events! I had a spectacular time at the “Locked In — The Cybersecurity Event of the Year!” Organized by Rinki Sethi and Lucas Moody, it was nothing short of epic! Forget long boring sessions and tracks, this was about CISOs connecting at a social level, building relationships, and sharing insights. Prestigious guests included the indomitable Edna Conway, the venerable Gary Hayslip (who has a new book out — CISO Desk Reference Guide: A Practical Guide for CISOs), career facilitator Mike Piacente from Hitch Partners, coaching expert Kristin Tedford, Clarence Chio (who also has a new book out — Machine Learning and Security: Protecting Systems with Data and Algorithms), offensive cyber expert Nathan Sportsman founder of Praetorian, and many more! …don’t ask how I was able to sneak in unnoticed among these powerhouses! I am stealthy! Sunset was beautiful on the rooftop of The Graduate Hotel in Palo Alto, which made for a great backdrop. Everyone walked away with a pair of kicks, customized right before our eyes by a local graffiti artist. Thanks to the Sponsors — Cyera, SentinelOne, Red Canary, Bolster, and Orca Security. As well as to Katelyn Ruby and Christine Valenzuela for carefully herding all of us!

@M.Rosenquist

Empowering the Modern CISO: Leading the C-Suite & Boardroom with a Bold Digital Agenda The expectations of CISOs are rising and their influence must resonate with C-Suite and Boardroom audiences.  I am excited at moderating a panel at the upcoming HMGStrategy 16th Annual Silicon Valley C-Level Technology Leadership Summit on Oct 8th in Mountain View CA.    My panelist include: Jonathan Chan - CEO at Episource, Dusan Vuksanovic – CEO at Swisscom Outpost Silicon Valley, and Alex Bessonov – Security Lead at Amazon.   Our panel “*Empowering the Modern CISO: Leading the C-Suite & Boardroom with a Bold Digital Agenda*” will discuss the challenges, opportunities, and best practices for CISOs to showcase leadership to executive business audiences!   Free to Register for this in-person event: https://hmgstrategy.biz/SVCIO2024

@M.Rosenquist

SECURITYbreak podcast - The Even Darker Side of CyberCrime w/ Matthew Rosenquist https://www.youtube.com/watch?v=nKyET5PsPCM I had a great discussion on the SECURITYbreak podcast talking about security vulnerability research impacting Apple vision pro VR headsets, MasterCard’s acquisition of threat intelligence vendor Recorded Future, and some horrific aspects of cybercrime extremists.  An insightful discussion about some unpleasant realities of our digital world.

@M.Rosenquist

Frustration Trying to Opt-Out After the National Public Data Breach The National Public Data breach has been a nightmare, exposing names, addresses, birthdates, emails, phone numbers, and Social Security Numbers of countless individuals — including mine. As a California resident, I have the legal right to demand that they delete my personal data to prevent further exploitation. I simply don’t trust them ever having my data. However, my experience with their opt-out process has been incredibly frustrating and disheartening. I tried to take action. First, I checked whether my data was part of the breach via their lookup page (https://npdbreach.com/). Unfortunately, I was indeed affected. Next, I followed the instructions on their Opt-Out page (https://nationalpublicdata.com/optout.html). The automated call system repeatedly informed me that no one was available to take my call. It allowed me to leave a voicemail, but I have little faith that this will result in any action — especially considering the sheer scale of this breach, involving billions of exposed records. Curiously, they also direct privacy requests to their Sales email account (Sales@NationalPublicData.com). Why is this critical issue routed through their sales department? It doesn’t inspire confidence that my data deletion request will be handled properly or even taken seriously. I’ve left a voicemail and sent an email, covering all possible bases. Yet, I remain skeptical. My concern is that this difficult, convoluted process further disrespects the privacy rights of many citizens. My guess is that this friction for customers to request data deletion is purposeful and will become a serious liability for National Public Data. Has anyone else successfully navigated this data-deletion process with this company? And does anyone know if there is a California class action lawsuit related to this breach? We need to protect ourselves and hold organizations accountable for securing our personal information.

@M.Rosenquist

Featured in The Cyber Express Magazine It is my absolute honor to be in this month's issue of The Cyber Express by Cyble, discussing the importance of knowing your cyber adversaries, how good leadership is crucial to success, and the ways AI will change cybersecurity forever! I made the cover with Cathy Pedrayes, who discusses good cybersecurity practices for everyone, and Dr. Sheeba Armoogum, an expert on cyberpsychology who connects our behaviors to tech security! The Cyber Express magazine is free to download, but is behind a registration wall. https://thecyberexpress.com/critical-infrastructure-and-cybersecurity-challenges/

@M.Rosenquist

FBI Warns of North Korea Attacks Against the Crypto Industry The decentralized finance (DeFi) and cryptocurrency industries are being targeted by North Korean social engineering schemes in highly personalized and convincing ways. Here is an example that the FBI is showcasing: 1. A person from your dream company, using the name of an old colleague, contacts you on social media, mentioning a conference you both recently attended and discussing shared interests. 2. He asks if you’re job hunting and reveals his company needs your skills, offering a significant pay raise. He arranges an interview with his CTO and during the interview, the CTO gives you a “pre-employment” test that involves troubleshooting code from some GitHub repositories you do not recognize. 3. You clone the repositories, execute the code, find the bugs, and pass the test with flying colors. Congrats — you have fallen for a well-disguised social engineering scheme conducted by North Korean cyber actors. One of those GitHub repositories was malicious and landed a malware dropper on your machine which installed a key logger and acquired your credentials to access your company’s network. The North Korean attackers gain access and moving laterally, eventually getting access to the seed phrases and security signatures for your company’s cryptocurrency assets. Shortly thereafter all the company’s crypto assets disappear and everything you and your colleagues worked for is gone. The threat is real. Check out the full FBI public warning here: https://www.ic3.gov/Media/Y2024/PSA240903

@M.Rosenquist

Evolving Cybersecurity: Aligning Strategy with Business Growth The cybersecurity landscape is evolving at an unprecedented pace, driven by rapid technological advancements and increasingly sophisticated cyber threats. What was sufficient yesterday, will be lacking for tomorrow. Organizations must stay ahead of these changes to protect their assets and data effectively. To thrive, cybersecurity strategies need to evolve — moving beyond the reactive and fragmented approaches that are often commonplace. Instead, businesses must prioritize strategic foresight, adaptability, and maturity in their security programs. Cybersecurity risks are continually growing. CISOs, CIOs, CEOs, and Boards are under immense pressure to manage these threats while simultaneously enabling business success. The challenge is significant, but with the right approach and insights, organizations can achieve greater security and unlock new value that is necessary for sustainability. Here are several areas where the cybersecurity industry must evolve to meet these demands: 1. Strategic Alignment Cybersecurity is no longer just a technical issue — it’s a business issue. The industry must evolve to ensure cybersecurity programs are directly aligned with an organization’s strategic goals. This involves defining clear and impactful cybersecurity objectives that resonate with the C-suite and Board members. It’s essential that cybersecurity is seen as a business enabler rather than a cost center, helping drive business outcomes while protecting critical assets. 2. Building Dynamic Capabilities Static security programs are no longer sufficient in today’s fast-evolving threat landscape. Organizations need dynamic approaches to cybersecurity that adapts to emerging risks and threats. The industry must foster the development of continuously evolving security programs that are agile enough to respond to new challenges without compromising business operations. Building a strategic and adaptable cybersecurity framework is crucial for long-term success. 3. Optimizing Risk and Costs Effective cybersecurity does not have to be exorbitantly expensive. Organizations should focus on identifying areas where risk mitigation can be improved while simultaneously optimizing costs. The evolution of cybersecurity practices will increasingly involve finding the optimal balance between robust security measures, friction to users, and cost efficiency, allowing organizations to manage their security investments wisely without sacrificing protection. 4. Sustainable Risk Management Organizations must build cybersecurity programs that are not only effective but also sustainable. The future of cybersecurity lies in the creation of flexible, long-term risk management strategies that can scale with the organization. By ensuring that security efforts are adaptable and sustainable, organizations can continue to thrive in the face of changing threats and business needs. The focus must shift from quick fixes to long-term risk management. 5. Enhancing Maturity and Value The maturity of a cybersecurity program is a key indicator of an organization’s ability to handle threats effectively and efficiently in alignment with expectations. The cybersecurity industry needs to guide organizations on their journey toward greater maturity, helping them move from reactive measures to proactive and strategic cybersecurity initiatives. This evolution in maturity brings not only better security but also enhances overall business value, providing organizations with a competitive edge in their industry. 6. Executive Translation of Cybersecurity Concepts One of the biggest challenges in cybersecurity is the communication gap between technical teams and executive leaders. For the industry to truly excel, cybersecurity professionals must be able to translate complex cybersecurity concepts into language that resonates with both executives and employees. This ensures that risk-based decisions are understood and embraced across the organization, leading to smarter and more informed business practices. Conclusion The cybersecurity industry must evolve in key areas to remain effective and relevant in today’s challenging landscape. Strategic alignment, dynamic capabilities, cost optimization, sustainable risk management, maturity growth, and executive communication are all areas where organizations can excel. By embracing these approaches, businesses can enhance their cybersecurity programs and not only reduce risk but also create value and drive success. https://www.youtube.com/watch?v=0cWdH0K6VUc If your organization is ready to assess, improve, or enhance the maturity of its cybersecurity program, seeking expert guidance can help navigate this complex evolution. As a cybersecurity strategist, I offer flexible consulting engagements designed for CISOs, C-suites, and Boards to help drive meaningful change. Together, we can advance your security efforts and achieve sustainable growth in cybersecurity maturity.

@M.Rosenquist

Best Strategic Metric for Cybersecurity https://www.youtube.com/watch?v=kAsUjMP7ejI Conveying the risks and progress for a cybersecurity program to executives is difficult. Over the years, I have explored countless ways to quickly and effectively distill the complexities of cyber risk into a simple graphic that informs management teams so the best decisions can be made. This is my go-to graphic when talking with executives and boards because it:  1. Showcases strategic value  2. Conveys operational updates at a strategic level  3. Highlights important issues  4. Provides the right level of understanding for non-security audiences  5. Drives the right conversations for good risk decisions  6. Is easy to create and update In the video I discuss why it is powerful, how to use it to drive productive conversations, and walk through the steps to create one. Mercury Risk and Compliance: https://mercuryrisk.com/ Follow me on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ and on my YouTube channel for more Cybersecurity Insights: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Speaking at the CISO and Executive Leadership Event I am looking forward to speaking at the CISO/Executive Leadership Forum this October 24th-25th in Napa California! This will be such a stellar event and great opportunity to network with amazing leaders. Check out more details at: https://mind-fluence.com/napa-2024/ The Mindfluence Cybersecurity Leadership Forum provides a unique platform for today’s most influential leaders in cybersecurity. This two-day event includes Peer-To-Peer Councils and Panel Discussions that will stimulate thought, provoke debate and inspire dialogue. The venue will be at the boutique Andaz Napa — World of Hyatt hotel. https://www.hyatt.com/andaz/apcrn-andaz-napa Napa California is a world-renowned destination, known for its wineries. “Be inspired by the charm of Napa Wine Country from our boutique downtown hotel. Experience essential Napa, including Oxbow Public Market and the Napa Valley Wine Train, which are both located within walking distance of our hotel. Explore the arts, wine and culinary culture through exclusive hotel events, a tasting room and world-class dining.” Hope to see you there!

@M.Rosenquist

The Ongoing Battle of Detecting GenAI-Created Content The arms race continues between those attempting to detect GenAI-created content and those who want to keep their origins concealed. For example, detecting if ChatGPT was employed to write content, such as academic papers. According to reports, OpenAI has built a subtle watermarking system, based upon words chosen by its own ChatGPT system, that is an embedded indicator for AI generation. Although highly accurate, it only works on OpenAI’s ChatGPT system and not on AI-generated content created from other systems. It also can be intentionally circumvented by running the content through other systems or filters. https://techcrunch.com/2024/08/04/openai-says-its-taking-a-deliberate-approach-to-releasing-tools-that-can-detect-writing-from-chatgpt We have seen many GenAI detection systems come and go. They emerge with promise, only to be undermined quickly. This is not the first AI text detector that OpenAI has created. The previous version was withdrawn due to a rapid decline in accuracy. With the rise of deepfakes, there has been more focus on consistently detecting fabricated content, but nothing long-lasting has emerged.

@M.Rosenquist

Lessons Learned from the CrowdStrike Outage https://www.youtube.com/watch?v=9F43zTH1qtM The recent CrowdStrike outage provides valuable lessons in how to avoid causing problems and being more resilient when faced with 3rd party vendor issues. CEOs, CIOs, and Board members have a clear responsibility to protect the business and the investors. It is time for senior leadership to apply the lessons of the Crowdstrike incident.   Here are the Top 3 areas to focus on: 1. Reassessing 3rd Party Vendor Risks 2. Enhancing Crisis Management Preparedness 3. Verifying the Quality Assurance of Company Products   Check out the video where I dive into each of these areas with insights and details!   Video: https://www.youtube.com/watch?v=9F43zTH1qtM

@M.Rosenquist

Chaos in Cyber Regulations and Lawsuits https://www.youtube.com/watch?v=1QwJUjyojsI The Supreme Court struck down the Chevron Doctrine, sharply cutting back the power of federal agencies to interpret the laws they oversee and ruled that courts should rely on their own interpretation of ambiguous laws. The ramifications will have ripple effects across cyber litigation, regulations, and prosecutions. Ian’s LinkedIn profile: https://www.linkedin.com/in/ian-thornton-trump-cd-77473a26/  Matthew’s LinkedIn profile: https://www.linkedin.com/in/matthewrosenquist/ Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

California DMV Implementing Blockchain Tech California’s Department of Motor Vehicles will implement a blockchain to prevent vehicle title fraud. They will use Ava Labs’s Avalanche blockchain to allow over 39 million residents to claim and access their vehicle titles. https://qz.com/california-dmv-blockchain-car-title-fraud-ava-labs-web3-1851609271 The online service is intended to cut down on fraud and reduce the workload for DMV offices to process the requests. Love it or hate it, cybersecurity must adapt with technology innovation. With AI and quantum soaking up the spotlight, we cannot forget there are a host of other architectures making their way onto the stage. As new digital tools deliver better services at lower costs, they will be quickly embraced by the markets and require additional oversight to ensure the security, privacy, safety, and reliability. As a general fan of blockchains for attestable record keeping, I think it is a good direction and a great early use-case for Web3 technology at a state level. As strong as the inherent security benefits are, a lot depends on the implementation. Ultimately, blockchains will still require cyber protection and oversight.

@M.Rosenquist

Prestigious Cybersphere CISO Advisory Board Unveils Full Member Listing Tackling the biggest problems in cybersecurity requires superb insights and collaboration across the industry. This CISO Advisory Board will be a catalyst for constructive communication, practical innovation, and a showcase for leadership that drives adaptation to keep pace with evolving threats and rising business expectations.  I am honored to join the Cybersphere CISO Advisory Board with such a prestigious team of expert practitioners and look forward to our engagements! Cybersphere Full List of Esteemed CISO Advisory Board Members: Shira Rubinoff, President Cybersphere Marene Allison, Retired CISO, Johnson & Johnson Gary R. Hayslip, CISO, SoftBank Investment Advisors & SoftBank Group Stacy Mill, Chief Executive Officer, Pivot Tech Solutions Jonathan Nguyen-Duy, Field CISO, Intel Corporation Holly Ridgeway, EVP, Chief Security Officer, Citizens Bank Matthew Rosenquist, CISO, Mercury Risk Rinki Sethi, VP, CISO, & CIO, BILL Vaughn Hazen, Assistant VP & CISO, CN Rail Raymond Lipps, CISO, Broadcom Howard Israel, vCISO, Google https://finance.yahoo.com/news/prestigious-cybersphere-ciso-advisory-board-133000331.html

@M.Rosenquist

CrowdStrike Global Outage: Unpacking the Fallout and Future https://www.youtube.com/watch?v=sdsZRY9BKOs The Cybersecurity Vault - episode #36, with guest Ira Winkler Today we are going to talk about the massive global IT outage, effecting over 8 million devices, caused by the cybersecurity vendor CrowdStrike.  Although not a cyberattack, this incident is bringing to light potential issues for cybersecurity solutions and the potential fragility of the global computing ecosystem!   We discuss: - What they did wrong - What they did right - What they need to do going forward   Ira’s LinkedIn profile: https://www.linkedin.com/in/irawinkler/   Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Failures of CrowdStrike Quality Testing https://www.youtube.com/watch?v=wlBJBbkVkmc Details emerge on how a bad CrowdStrike update was allowed to land on Windows systems and cause over 8 billion computers to fail. I discuss their leadership and break down the preliminary Post Incident Review document to reveal the point of failure for their quality assurance infrastructure. I also give clear recommendations on how CrowdStrike must change to remedy this situation so it does not become a massive problem in the future! Cybersecurity Insights! Follow me on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ and on my YouTube channel for more Cybersecurity Insights: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Learning from CrowdStrike’s Quality Assurance Failures Let’s talk about CrowdStrike’s quality assurance failures! Thanks to Help Net Security for publishing my opinion piece. Take a look for a more in-depth explanation of how the bad update made it to over 8 million devices and caused widespread global outages. CrowdStrike has released preliminary details of how their bad update made it to client systems, which caused the BSODs. It showcases they have a complex product release architecture, which in this case failed. Improvements need to be made and I am concerned that their plans for incremental changes to a flawed Quality Assurance architecture won’t result in the desired long-term outcomes. CrowdStrike has a good reputation and leadership, as showcased by the CEO George Kurtz who quickly came out to take responsibility and rally his team to help their customers. There have been many companies, including security companies, who were not transparent or timely when their products caused problems. In fact, it seems more common to initially deny, downplay, or blame others. So, what George did is truly wonderful. It is a testament to CrowdStrike’s work ethics. However, this is a major outage and CrowdStrike needs to revisit their preliminary improvement plans to account for a flawed strategy that allows for dangerous code to make it to the endpoints — something that should never be allowed to happen. The world is watching and lessons-learned will likely be used to help improve the operating practices across the industry. Take read at the article and let me know your thoughts and concerns! https://www.helpnetsecurity.com/2024/07/25/crowdstrike-quality-assurance-failures/

@M.Rosenquist

New Microsoft Recovery Tool for CrowdStrike Issue on Windows Endpoints Not sure who need this resource, but Microsoft updated its Recovery Tool for the CrowdStrike issue on Windows endpoints: Here is the link to the Microsoft Tech Community Support Site: https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959 As a former cybersecurity Incident Commander for Intel, here are my additional recommendations: · Verify the source of every tool or procedure you plan on using! · For a large organization, have a single accountable tech savvy group create the recovery process and don’t allow other groups to home-brew their own fixes · Test the fix out on your different builds · Formalize the step-by-step process for your environment — break down instructions to keep each step simple · Make sure you have accounted for hard drive encryption hurdles (ex. Bitlocker or other 3rd party vendors), if applicable · Roll-out the recovery in phases, starting with non-critical systems, just in case there are unforeseen issues and system data loss · Have a process to record and report which systems have successfully been restored · If things go sideways, STOP and seek more advanced assistance Happy hunting!

@M.Rosenquist

CrowdStrike Outage Impacts Over 8 Million Computers https://www.youtube.com/watch?v=u4gOhZXLO_U The recent CrowdStrike outage, that continues to have global implications, reinforces the fact that cybersecurity solutions help manage cyber attack risks, but can also be a source of risk. The level of system access, which is necessary to provide security, can also be used to disrupt systems and used maliciously by attackers. We are fortunate that the CrowdStrike incident was accidental, as reported by their CEO, instead of malicious. The cybersecurity industry must learn and adapt to maintain the right balance to provide protection and not unnecessarily increase risks in other areas.   Follow me on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ and on my YouTube channel for more Cybersecurity Insights: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Massive CrowdStrike IT Outage Has Global Implications for Cybersecurity The world experienced a digital pandemic of systems going offline and displaying the dreaded Windows Blue Screen of Death (BSOD), due to a catastrophic failure caused by a flawed file in an update to CrowdStrike cybersecurity customers. The impacts have been obscenely widespread, with many banks, airlines, train stations, financial exchanges, news agencies, supermarkets, and health care providers to name a few. CrowdStrike is used by almost 60% of Fortune 500 companies and over half of the Fortune 1,000. It is popular in the financial sector, with deployments in eight of the top 10 financial services firms. Many of the biggest technology, healthcare, and manufacturing companies are also customers. So far, the faulty CrowdStrike update is not attributed to malicious activities, but the impacts have been massive, prompting social media to unofficially designate today as BSOD day! Implications This outage of CrowdStrike customers on Windows 10 systems reinforces three important aspects. First, cybersecurity solutions need deep and privileged access to systems, making them more impactful if they are hijacked or malfunction. This access is necessary to make preventative defensive changes before attacks occur, to monitor for stealthy attacks, and to coordinate system-level remediation actions when necessary. But when things go wrong, those permissions then can cause equally impactful damages. The computing stack is like a layered cake, with data at the top, followed by applications, virtual machines, operating systems, VM managers, firmware, and finally hardware at the bottom. The deeper you go the more potential for problems to be impactful and difficult to remedy. Cyber attackers try to get as far down the stack as possible because they can avoid detection from any layer above and are more difficult to evict. When errors occur, the same relevance applies. Second, the risk of supply chain attacks is real, and depending on the vendor, they could be catastrophic. CrowdStrike is one of the biggest cybersecurity players in the industry. An accidental or malicious problem in their flagship product, as we have seen, can deliver widespread impacts to the most important sectors. Let’s be glad that this was simply a technical glitch. A malicious package inserted into an update could completely take over systems or permanently destroy them. Third, bad updates, code bugs, and misconfigurations happen all the time. No software, firmware, or hardware company is immune. More effort is needed as part of development and quality assurance, but even for the best organizations, it is possible for a series of mistakes to be made. That is why it is important to not only invest in defense and prevention but also architect ways to securely recover and resolve issues when they arise. A Perfect Storm This event has a combination of attributes that amplify the impacts: the issue causes catastrophic system impacts (i.e. the dreaded BSOD), across a large number of systems, in Critical Infrastructure sectors, and the offending code possesses deep permissions within the computing stack. This is the case we are seeing with Crowdstrike. This outage reinforces the fact that cybersecurity solutions mitigate risks but also can become a source of risk. Mistakes were made. Trust was lost. The entire cybersecurity industry will be scrutinized, and that is probably the only good outcome of this mess.

@M.Rosenquist

AT&T Data Breach: Understanding the Fallout https://www.youtube.com/watch?v=I8dwYF40lQQ As an AT&T customer, I did receive the unwelcome news that they suffered a data breach. Here is a rundown for what you should to know. BREACH DETAILS · This is a sizable data breach of about 109 million customers · Call and text interactions from May 1, 2022 to October 31, 2022 · AT&T is blaming a 3rd party cloud platform — Snowflake · FBI Investigating and 1 arrest has been made · Hackers accessed and exfiltrated the files sometime from April 14th to 25th · Telephone numbers and phone logs were acquired, but AT&T says call and text message content wasn’t exposed. The breach does not contain customers’ personal information, like birthdays or social security numbers. Apparently, AT&T Paid the ransom — which is not smart. Wired magazine reported that AT&T paid the hackers over $300,000 to delete the stolen information and provide video proof. OVERALL RISK Given that personal information was not exposed, the risk is nominal. So far there is not conclusive proof that the data has been released in the wild, but that could change Expect more phishing attacks There could be some ramifications for those who need to keep their call logs secret — undercover agents, supreme court justices, cheating spouses, etc. The geolocation data, which identifies the cellular towers that phones were connected to during activities, is interesting but likely not too valuable to attackers SEC rules for mandatory shareholder notification were followed, with the US Government granting 2 delays to AT&T. Normally it is a 4 day rule. AT&T has not deemed this breach a material event to its shareholders. Overall, the scale of this breach is unfortunate, but the sensitivity of the data in not too worrying for the vast majority of those effected. However, this breach does show an unfavorable trend in AT&T’s security posture. ISSUES and RECOMMENDATIONS AT&T, “Protecting customer data is a top priority. “ is not true. This is the second major breach in just 3 months, with 70 million customer’s affected back in April. So, let’s talk about what I expect as a cybersecurity professional: First, protect your data better! Use MFA, encrypt at rest, clean up the access permissions, institute data blocking for exfiltration Second, remove all sensitive PII data you really don’t need. Why do you need my SSN, actual date of birth, the tower I most use during the day or evening, even my home address is questionable for my mobile phone and I pay electronically. Remove these. And if it is required by dated regulations, then drive the charge to have those regulations updated so all the telecommunications vendors aren’t a weak point for data harvesters. Third, implement a data destruction policy to destroy old customer data. Do you really need to keep call logs of people dating back 2 years? I would argue there is likely a mound of data you want to have, but don’t actually need to have. Clean that up, lighten your servers, and focus on keeping your network up. FALLOUT AT&T is getting proficient at handling major data breaches, which is not really a compliment. I hope its big competitors lean-in and invest in cybersecurity to showcase how they can protect their customers, thus leveraging security as a competitive advantage for consumers to choose a communications provider that really is making customer data protections a top priority! AT&T, I will be considering how you protect my data when my contract is up and I look at other providers! Be sure to like and follow me on LinkedIn and the Cybersecurity Insights channel Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ Follow for more Cybersecurity Insights: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Rise of Aggressive Nation State Activities https://www.youtube.com/watch?v=ONTYJvB9w4s This is the replay of the live LinkedIn interview with Matthew Rosenquist (CISO at Mercury Risk. - Formerly Intel Corp, Cybersecurity Strategist, Board Advisor, Keynote Speaker) to discuss the Rise of Aggressive Nation State Capabilities. Hosted by Aaron Stillwell, David Cross, and Alex Mavro. Nation State attacks impact everyone! The discussion covers the evolving threats, their motivations, targets, and what organizations can do to help avoid becoming a victim. https://www.youtube.com/watch?v=ONTYJvB9w4s

@M.Rosenquist

Google Wants to Up-Sell AI Security to Gmail Customers https://www.youtube.com/watch?v=T1FrJG8FuOo Google wants to up-sell enterprise Gmail users for AI security enhancements, when in reality the feature is mitigating the advances that attackers are making through their own innovative use of AI, making their Social Engineering attacks more effective. I am a firm believer that cybersecurity can be a competitive advantage and even generate new revenue for organizations. …BUT up-selling cybersecurity features only makes sense when it is an over-the top capability and not foundational or necessary to preserve the current risk mitigation levels. Keeping spam, phishing, and malware out of the Inbox is fundamental for security, privacy, and safety. Don’t upsell this capability Google. There are other options for add-on features. This is needed just to maintain cybersecurity risk parity with attackers. Watch the full video where I discuss the issue more in depth and give some examples of innovation that would be embraced by enterprise customers for additional costs. Follow me on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ and on my YouTube channel for more Cybersecurity Insights: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Microsoft in Cybersecurity Leadership Crisis – Open Letter to the CEO There is no indication that the root of Microsoft’s cybersecurity issues is being addressed. In fact, all indications are that the executive team is somewhat worried and bewildered at the diverse and numerous issues arising. After many embarrassing incidents, which recently culminated in the President of Microsoft being called to answer questions before Congress, the Board and senior executive team once again instituted security measures to resolve the problems. Confidence among the cybersecurity community was not high, as this was not the first time such promises were made. Shortly thereafter, more security failures occurred. Microsoft has announced additional measures as part of their Secure Future Initiative, which was actually created in November last year to solve the previous embarrassing problems that plagued them in 2021–2023, in another attempt to stem the cybersecurity failures. Based upon events that happened in July 2023, the U.S. Cyber Safety Review Board criticized the company’s leadership and culture which led to a “cascade of Microsoft’s avoidable errors”. Since then, two more major breaches have occurred and a myriad of other unsettling security issues. Highlights of their best hacks and missteps 2021–2024 · Jan 2021: Microsoft Exchange Server Vulnerability Leads to 60,000+ Hacks · April 2021: 500 Million LinkedIn Users’ Data Scraped and Sold · Aug 2021: Thousands of Microsoft Azure Customer Accounts and Databases Exposed · Aug 2021: 38 Million Records Exposed Due to Microsoft Power Apps Misconfiguration · Mar 2022: Lapsus$ Group Breaches Microsoft · Oct 2022: 548,000+ Users Exposed in BlueBleed Data Leak · July 2023: Chinese Hackers Breach U.S. Agencies Via Microsoft Cloud · Sept 2023: 60k State Department Emails Stolen in Microsoft Breach · Jan 2024: Microsoft Azure Breached by Russian Intelligence Group, Source Code Stolen · May 2024: Microsoft Announces Recall Feature, a Privacy and Security Nightmare · June 2024: Microsoft Fails to Renew Their Security Certificates for Office* *Unexpected expiration of Microsoft security certificates has happened numerous times, causing disruption (including to Teams in Feb 2024 and 2020, and to Azure in 2023 and 2013). Failures Ahead Sadly, it is clear they are attempting to leverage the same flawed framework, that created the systemic issues, to somehow solve the problem. Well, the problem is leadership which does not see the broader security issues, so having the same leaders guiding the way, will not get them out of this predicament. I have been discussing, talking, and analyzing the many recent cybersecurity issues with colleagues, and in one of my most recent posts, I asked if anyone was willing to reach out to Satya, perhaps the most powerful person in the world of digital technology. No takers. So, I put pen to e-paper and have published an open letter to him to paint the picture on the problems and offer recommendations on how Microsoft can evolve to be a much better steward of trust for its products and as a foundation for our global electronic ecosystem. For context, I have seen nearly identical issues in other large organizations and have written many articles on the failures of cybersecurity leadership. In fact, I have identified and wrestled an identical issue in one of the biggest tech firms in the US. It is addressable. Let’s Raise Expectations! But I believe it will take Satya Nadella to be aware and engaged. It is time we raise our collective voices to the top. To the CEO himself, Satya Nadella, who at the end of the day is ultimately responsible. I think at this point it will take his direct intervention. If you have a chance, take a read of the full letter to Mr. Nadella. If you like it, upvote, share, and comment. If you don’t feel free to add your thoughts on how Microsoft should tackle this persistent problem. Let’s get this in front of the CEO of Microsoft, so we all can be safer in our computing and have a trustworthy foundation for digital innovation, productivity, and success. https://www.helpnetsecurity.com/2024/07/09/microsoft-cybersecurity-dilemma/ Read the Open Letter to Satya Nadella, to address Cybersecurity Leadership Issues - Posted to Help Net Security: https://www.helpnetsecurity.com/2024/07/09/microsoft-cybersecurity-dilemma/

@M.Rosenquist

YouTube's Deepfake Removal Feature YouTube has announced that it will facilitate requests to remove AI generated content that is created to look or sound like you. It is a nice gesture on behalf of YouTube, but the process to protect from deepfakes is not scalable.  The attackers will be able to create vast amounts of videos for publishing and the YouTube review team will be flooded with requests, unable to keep up.  Additionally, it will be difficult for victims to identify when a new video is published with their likeness on the platform.  If YouTube doesn’t shut down repeat offending accounts, then this will provide little relief and continue to be a growing problem.  New tools and stronger enforcement are needed in the fight for privacy, dignity, and to undermine harmful disinformation. This is a good start and a signal to other social sites, but more advancements are needed to truly protect people. https://techcrunch.com/2024/07/01/youtube-now-lets-you-request-removal-of-ai-generated-content-that-simulates-your-face-or-voice/

@M.Rosenquist

Rising Threat of Russia’s Cyber Warfare with Mikko Hypponen https://www.youtube.com/watch?v=E6OvLbAHM6s Rising Threat of Russia’s Cyber Warfare with Mikko Hypponen The Cybersecurity Vault — episode 35 Some of the most aggressive cyber attacks originate out of Russia. The 2022 invasion of Ukraine was a pivotal moment for nation state attacks. Mikko is close to the front lines and one of the best sources of current research and perspectives. Listen to his pragmatic insights and let’s separate the fear from reality. Purchase your copy of Mikko’s book: “***If It’s Smart, It’s Vulnerable***” https://www.amazon.com/If-Its-Smart-Vulnerable/dp/1119895189 More information on his website: https://www.ifitssmartitsvulnerable.com/ Mikko’s LinkedIn profile: https://www.linkedin.com/in/hypponen/ Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ Visit Cybersecurity Insights at https://www.cybersecurityinsights.us Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

Cybersecurity is Adversarial – Our Failures are Attackers Opportunities https://www.youtube.com/watch?v=C4L26qjO0G4 The Cybersecurity Vault - episode 34, with guest Chase Cunningham. We take a hard look at when organizations make big cybersecurity mistakes, how the attackers see those as opportunities, and how they will maneuver to take advantage Chase’s LinkedIn profile: https://www.linkedin.com/in/dr-chase-cunningham/ Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ Visit Cybersecurity Insights at https://www.cybersecurityinsights.us Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights

@M.Rosenquist

How Leaders Build a Strong Security Culture and Bridge the Gap Between Psychology and Cybersecurity https://www.youtube.com/watch?v=AdMU5v3hUiU As the saying goes “Culture trumps strategy”, which very much holds true when it comes to cybersecurity!   Pooja Shimpi, Sameer Gemawat, and I discuss strategies leaders can use to promote a robust security mindset and a security-first approach within their organizations. Additionally, we explored the vital connection between Psychology and Cybersecurity.   Check out the full The People Show podcast https://www.youtube.com/watch?v=AdMU5v3hUiU