720-891-1663

Security News for the Week Ending March 22, 2024

Like Everyone Else, Reddit Plans to Sell User Content to AI Model Devs Seeing dollar signs in their future, Reddit decided to “license” their user created content to AI developers to train their models. The FTC is investigating in light of Reddit’s planned IPO. Reddit says it isn’t breaking the law to sell their user’s […]

Continue reading → [DISPLAY_ACURAX_ICONS]

DoD Contractors: Will You Have to Replace Your MSP?

If you are a defense contractor, then over the next few years you will likely have to be compliant and maybe certified for CMMC, either at level one or level two. Level one has about 17 controls and 59 assessment objectives; level two has 110 controls and about 315 assessment objectives. Assessment objectives are the […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Feds Say CISA Not Prepared to Defend OT

If that headline doesn’t keep you up at night, I don’t know what will. The Government Accountability Office (GAO) says they have have found inefficiencies in CISA’s information sharing practices, in particular with critical infrastructure stakeholders. They also say that CISA is understaffed for handling OT incidents. Just to make sure everyone is on the […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Microsoft Plans to Deprecate 1024 Bit RSA Keys

Microsoft is often between a rock and a hard place. They would like to be more secure but not at the expense of offending their customers. Here is an example of that. Microsoft has announced that RSA keys shorter than 2048 bits will soon be deprecated in Windows Transport Layer Security (TLS) to provide increased […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending March 15, 2024

No Honor Among Crooks – Darknet Site Extorts Vendors, Buyers I guess we should not be surprised, but darknet narcotics bazaar Incognito Market has posted a threat on its homepage that if its vendors and buyers don’t pay an extortion of between $100 and $20,000, they will publish all of their transaction and chat records. […]

Continue reading → [DISPLAY_ACURAX_ICONS]

FCC Releases Voluntary CYBER TRUST MARK for IoT

The program allows manufacturers to put a new “U.S Cyber Trust Mark” on devices that comply with cybersecurity standards developed by the National Institute of Standards and Technology (NIST), including what the White House described last year as “unique and strong default passwords, data protection, software updates, and incident detection capabilities.” FCC commissioners voted unanimously for it. […]

Continue reading → [DISPLAY_ACURAX_ICONS]