720-891-1663

AI: Productivity Gains vs. Security Risks

No sane person can deny the allure of Generative Pre-trained Transformer AIs. Smart people are also concerned about the security risks they create. For example, if you use an AI to write code, could the AI include a back door? Or malware? How do you know without reviewing every line of code in detail? In […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Advanced Industrial Malware Could be Inside Our Critical Infrastructure

The world’s most advance industrial malware – malware that is designed to go after industrial control systems in places like power plants – called PIPEDREAM, may already have infiltrated some critical infrastructure control systems, waiting to unleash who knows what. Global business advisory firm Ankura said that they are concerned that PIPEDREAM cannot be stopped […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Financial Institutions Have 7 Weeks Until New FTC Safeguards Rule Becomes Effective

The FTC revised the Standards for Safeguarding Customer Information aka the Safeguards Rule in 2021 and in about 7 weeks the changes become effective. The FTC updates this rule every 20 years or so to make sure that it is still state of the art. The new rule borrowed a lot from New York’s financial […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News Update for April 14, 2023

Tech Industry Pain Good for NSA Rob Joyce, NSA’s cyber director, says that they are seeing a boost in recruitment following waves of layoffs in the tech sector. While he is not giving numbers, any help with mid and high level recruiting would be good for the good guys. Remember that due to the clearance […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Federal Civilian Agencies May Have to Comply with CMMC-Like Security Requirements

If you sell to the federal government – any agency – you need to pay attention to this. Until now only DoD contractors were going to have to comply with CMMC or NIST SP 800-171. The standard requires 100% compliance with 110 controls; some of them pretty straight forward like having each user having their […]

Continue reading → [DISPLAY_ACURAX_ICONS]

This is Why the Feds are Very Scared About Supply Chain Attacks

Last week it was revealed that VoIP communications company 3CX was compromised and was distributing a malicious version of their desktop software to hundreds of thousands of paying customers. This is not an attack where users go to find sketchy websites and download “free” software that should be paid for. Rather, this is licensed software […]

Continue reading → [DISPLAY_ACURAX_ICONS]