FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Saturday, July 2, 2022

IronNet Added to Membership of Russell 2000Ⓡ and 3000Ⓡ Indexes

MCLEAN, Va.–(BUSINESS WIRE)–IronNet, Inc. (NYSE: IRNT), an innovative leader Transforming Cybersecurity Through Collective DefenseSM, today announced it joined the small-cap Russell 2000® and the broad-market Russell 3000® Indexes on June 27 as part of the 2022 Russell indexes annual reconstitution. In addition to joining both the Russell 2000 and the Russell 3000 Indexes, the stock also was automatically added into the portfolios of numerous growth and value investment funds.

“We are proud of IronNet’s inclusion in the Russell 2000 and 3000 Indexes, which we believe highlight the growing focus by investors on the power of our Collective Defense platform,” said General (Ret.) Keith Alexander, chairman and co-CEO of IronNet. “This milestone for our company, within the year of our business combination and entry into the public markets, is a recognition of our market opportunity and our momentum in key sectors, including energy, healthcare, space, government, and finance. Looking ahead, we aim to support our continued growth by further targeting these industries and by leveraging technology and go-to-market partnerships. We have also highlighted initiatives underway to streamline our operations for higher efficiency in order to accelerate our timeline to become cash flow neutral and to set IronNet up for rationalized growth.”

Russell indexes are widely used by investment managers and institutional investors for index funds and as benchmarks for active investment strategies. Approximately $12 trillion in assets are benchmarked against Russell’s U.S. indexes. Russell indexes are part of FTSE Russell, a leading global index provider.

About IronNet, Inc.

Founded in 2014 by GEN (Ret.) Keith Alexander, IronNet, Inc. (NYSE: IRNT) is a global cybersecurity leader that is transforming how organizations secure their networks by delivering the first-ever Collective Defense platform operating at scale. Employing a number of former NSA cybersecurity operators with offensive and defensive cyber experience, IronNet integrates deep tradecraft knowledge into its industry-leading products to solve the most challenging cyber problems facing the world today. Learn more at www.ironnet.com.

Forward-Looking Statements

This press release includes “forward-looking statements” within the meaning of the “safe harbor” provisions of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding IronNet’s ability to transform cybersecurity, execute on its business strategy and increase market share, the expansion of the cybersecurity market and demand for IronNet’s products and services, and IronNet’s strategy to streamline its operations for higher efficiency and its plans to become cash flow neutral. When used in this press release, the words “estimates,” “projected,” “expects,” “anticipates,” “forecasts,” “plans,” “intends,” “believes,” “seeks,” “aim,” “may,” “will,” “should,” “future,” “propose” and variations of these words or similar expressions (or the negative versions of such words or expressions) are intended to identify forward-looking statements. These forward-looking statements are not guarantees of future performance, conditions or results, and involve a number of known and unknown risks, uncertainties, assumptions and other important factors, many of which are outside IronNet’s management’s control, that could cause actual results or outcomes to differ materially from those discussed in the forward-looking statements. Important factors, among others, that may affect actual results or outcomes include: IronNet’s ability to execute on its plans to develop and market new products and the timing of these development programs; IronNet’s estimates of the size of the markets for its products; the rate and degree of market acceptance of IronNet’s products; IronNet’s ability to secure new contracts and renewals from public sector customers; the success of other competing technologies that may become available; IronNet’s ability to identify and integrate acquisitions; the performance of IronNet’s products; potential litigation; and general economic and market conditions impacting demand for IronNet’s products. The foregoing list of factors is not exhaustive. You should carefully consider the foregoing factors and the other risks and uncertainties described under the heading “Risk Factors” in IronNet’s Annual Report on Form 10-K for the year ended January 31, 2022, filed with the SEC on May 2, 2022, as updated by IronNet’s Quarterly Report on Form 10-Q for the quarter ended April 30, 2022, filed with the SEC on June 14, 2022, and subsequent filings with the SEC. These filings identify and address other important risks and uncertainties that could cause actual events and results to differ materially from those contained in the forward looking statements. Forward-looking statements speak only as of the date they are made. Readers are cautioned not to put undue reliance on forward looking statements, and IronNet does not undertake any obligation to update or revise any forward-looking statements, whether as a result of new information, future events or otherwise, except as required by law.

About FTSE Russell

FTSE Russell is a global index leader that provides innovative benchmarking, analytics and data solutions for investors worldwide. FTSE Russell calculates thousands of indexes that measure and benchmark markets and asset classes in more than 70 countries, covering 98% of the investable market globally.

FTSE Russell index expertise and products are used extensively by institutional and retail investors globally. Approximately $20 trillion is currently benchmarked to FTSE Russell indexes. For over 30 years, leading asset owners, asset managers, ETF providers and investment banks have chosen FTSE Russell indexes to benchmark their investment performance and create ETFs, structured products and index-based derivatives.

A core set of universal principles guides FTSE Russell index design and management: a transparent rules-based methodology is informed by independent committees of leading market participants. FTSE Russell is focused on applying the highest industry standards in index design and governance and embraces the IOSCO Principles. FTSE Russell is also focused on index innovation and customer partnerships as it seeks to enhance the breadth, depth and reach of its offering.

FTSE Russell is wholly owned by London Stock Exchange Group. For more information on the Russell 2000® and Russell 3000® Indexes and the Russell indexes reconstitution, go to the “Russell Reconstitution” section on the FTSE Russell website.

The post IronNet Added to Membership of Russell 2000Ⓡ and 3000Ⓡ Indexes appeared first on Cybersecurity Insiders.


July 03, 2022 at 09:08AM

Fortified Castles With Wooden Gates: Weak Keys and Outdated Machine Identity Management Undermine TLSv1.3 Adoption

SALT LAKE CITY–(BUSINESS WIRE)–Venafi®, the inventor and leading provider of machine identity management, today announced the findings of a new crawler report from security researcher and TLS expert, Scott Helme. The report, which Venafi sponsored, evaluates the use of encryption across the world’s top one million sites over the last six months and reveals the need for a control plane to automate the management of machine identities in increasingly complex cloud environments.

The research suggests that while progress has been made in some areas, more education is needed to ensure that machine identities are used in the most effective way to protect our online world:

  • Use of TLSv1.2 has declined by 13% over the last six months, with v1.3 in use by almost 50% of sites — more than twice as many sites as v1.2. The adoption of v1.3 is being driven by widespread digital transformation, initiatives, cloud migration and new cloud native stacks that default to v1.3.
  • Even though organizations are adopting stronger TLS protocols, they are failing to couple this with a move to stronger keys for TLS machine identities.
  • Industry-standard ECDSA keys are now used by just 17% of websites — up from 14% six months ago. Slower, less secure RSA keys are still used by 39% of the top one million websites.
  • Growth in the adoption of HTTPS has plateaued at 72% — the same level as in December.

“The fact that companies are deploying TLS v1.3 with machine identities using RSA keys shows there is still a lot of progress to be made with machine identity management. A strong algorithm means very little if it is used in conjunction with a weak key — it’s akin to building a stone fortress but leaving the wooden gate unprotected,” explained Scott Helme, security researcher and founder of Report URI. “The adoption of newer, more efficient and more secure EDCSA keys has been negligible over the last six months. This, coupled with the fact that HTTPS adoption has plateaued over the last six months, shows that the internet is no safer than it was half a year ago. Cybercriminals are constantly upping the ante, so it’s disheartening to see that companies aren’t following suit.”

Let’s Encrypt continues to be the Certificate Authority (CA) of choice for the top one million, but Cloudflare is making up ground. This uptake seems to be the driving force behind TLS v1.3 adoption, with 50% of the websites deploying v1.3 doing so through Cloudflare. The decline in use of Extended Validation (EV) certificates has also continued, with a 16% decrease in the past six months, following changes from browser makers that dramatically reduced the value of EV certificates to website owners.

There is some good news in this analysis. The data suggests that organizations are taking more steps to manage their machine identity environments. Since December, there has also been a 13% increase in the number of sites making use of Certificate Authority authorization (CAA), which enables companies to create a list of approved CAs that can be used within their organizations. The adoption of this control is a positive sign that organizations seem aware of the importance of machine identities in overall security and are showing increased vigilance in the ways in which they manage them.

“The recent boom in cloud migration means every business needs many more TLS machine identities to secure communication between devices, clouds, software, containers and APIs,” said Kevin Bocek, vice president, security strategy and threat intelligence at Venafi. “The fact that more and more companies are making use of CAA is a positive sign that companies are waking up to the need for machine identity management. CAA adoption also underscores the urgent need for a machine identity management control plane that can automate the use of machine identities in increasingly complex cloud environments.”

For more information on the report please visit the blog.

About Venafi

Venafi is the cybersecurity market leader in machine identity management. From the ground to the cloud, Venafi solutions manage and protect identities for all types of machines — from physical and IoT devices to software applications, APIs and containers. Venafi provides global visibility, lifecycle automation and actionable intelligence for all machine identity types and the security and reliability risks associated with them.

Jetstack, a Venafi company, is a cloud native products and strategic consulting company working with enterprises using Kubernetes and OpenShift.

An open source pioneer, Jetstack has achieved notable industry recognition as the creator of cert-manager, the open source industry standard for cloud native machine identity management. Jetstack’s open source products and solutions protect the application environments and platform infrastructure of global banks, multinational retailing companies and defense organizations by providing enterprise platform and security teams the power to build, scale and security their cloud infrastructure.

With more than 30 patents, Venafi delivers innovative machine identity management solutions for the world’s most demanding, security-conscious organizations and government agencies, including the top five U.S. health insurers; the top five U.S. airlines; the top four credit card issuers; three out of the four top accounting and consulting firms; four of the five top U.S. retailers; and the top four banks in each of the following countries: the U.S., the U.K., Australia and South Africa.

For more information visit www.venafi.com and www.jetstack.io.

The post Fortified Castles With Wooden Gates: Weak Keys and Outdated Machine Identity Management Undermine TLSv1.3 Adoption appeared first on Cybersecurity Insiders.


July 02, 2022 at 09:08PM

Friday, July 1, 2022

All you need to know about data security and its benefits for small businesses

This blog was written by an independent guest blogger.

Cyberthreats don't affect only large enterprises and governments – they can also affect small businesses. According to research, nearly half of small businesses have experienced a cyberattack, and 69% are concerned about future attacks. Small businesses should be aware of cyber security statistics and take tangible steps to protect their businesses against cyberattacks.

Employee records, customer information, loyalty schemes, transactions, and data collection are critical pieces of information that businesses need to protect. This is to prevent third parties from using the information for fraudulent purposes, such as phishing scams and identity theft.

It's crucial to safeguard your company from cyberattacks, but some business owners are unsure how to do it.

This article is intended to help small business owners navigate the realm of cyber threats and fortify their data security. The benefits of data security for small businesses are also discussed.

Data security

Data security is the practice of keeping data safe from unauthorized access or corruption.

Data protection entails safeguarding not only your company's data but also that of your customers and vendors.

Data encryption, hashing, tokenization, and key management are data security strategies that safeguard data across all applications and platforms.

Small firms, unfortunately, appear to be a much easier target for hackers, as their security systems are typically less advanced than those of a medium or large company. Despite this fact, most small business owners believe they are not vulnerable to a data breach.

Why data security?

To secure their essential assets, organizations all over the world are investing extensively in information technology (IT) cyber security capabilities. Every business has to protect its brand, intellectual capital, and customer information. It also needs to provide controls for essential infrastructure. However, incident detection and response have three fundamental elements: people, processes, and technology.

Cyber security problems and their effect on small businesses

Security risks faced by small businesses?

Small businesses may not have the operational know-how or employees to protect their IT systems and networks appropriately.

Small firms confront a variety of cyber security challenges, including:

  • Attacks by phishers: Phishing refers to a type of social engineering attack that is frequently used to obtain personal data from users; such data includes login credentials and credit card details.
  • Malware attack: Malware attacks are common cyberattacks in which malware (usually malicious software) performs unauthorized actions on the victim's system.
  • Ransomware: Ransomware is a sort of cryptovirology malware that threatens to expose or permanently limit access to the victim's personal information unless a ransom is paid.
  • Internal threats: Internal threats are often the result of poor access controls or a lack of proper staff training. Hostile employees or ex-employees might perpetrate cyber attacks in the company, posing internal threats.
  • Weak passwords: Passwords that aren't strong enough can expose a company to unauthorized access and security risks.

Use a combination of at least eight different letters, numbers, and symbols in your password to make it strong. It is more difficult to guess a password that is longer and contains more character types (including upper and lowercase letters). For instance, M0l#eb7Qs? employs a unique mix of capital and lowercase letters, numbers, and symbols. It is also recommended to change passwords every 90 days or less.

Organizations should carefully review password security policies and password management since stolen or weak passwords are still the most common cause of data breaches.

What effect does an attack have?

A successful cyber attack on your business can be devastating. It can have a negative impact on your financial line, as well as your company's reputation and consumer trust. A security breach has three major consequences: financial, reputational, and legal.

Financial cost of a cyberattack

Cyber breaches frequently cause a significant financial loss due to:

  • Unauthorized access to corporate data
  • Theft of corporate data
  • Financial information theft (e.g., bank details or payment card details)
  • Theft of funds
  • Trading disruption (e.g., inability to carry out transactions online)
  • Loss of contract or business

In addition, businesses would typically pay fees for fixing systems, networks, and devices affected, as part of their response to the breach.

Damage to the company’s reputation

A good customer relationship must be based on trust. Cyberattacks can harm your company's reputation and reduce client trust in you. This might ultimately result in:

  • Loss of clients
  • Sales decline
  • Decrease in profits

Reputational damage may also have a negative impact on your relationships with partners, investors, suppliers, and other interested parties.

Legal consequences of a cyberattack

You are required by data protection and privacy laws to manage the security of all personal data you hold, whether it relates to your customers or your personnel. You may be subject to penalties and regulatory sanctions if this data is compromised unintentionally or on purpose, and you fail to implement the necessary data security measures.

Essential tips for data security

1. Manage mobile devices, apps, and computer operations

To ensure the user's experience is as smooth as possible, manage important applications rather than the device itself. Also, make sure everything you're doing is transparent, particularly when it comes to your employees' devices.

2. Enable secure collaboration

To guarantee that your staff has access to the information they require, set up secure tools for data sharing.

If you're sending sensitive information via email, ensure you've set up a digital rights management system (or another secure email solution).

3. Reduce malware exposure

Create a training plan that ensures your employees get adequate awareness training on a regular basis.

It would help if you also considered using an email protection solution that includes time-of-click protection to guard against the inevitable human errors.

Implement regulations and procedures that limit specific actions, such as checking personal emails at work or installing apps from a trusted source, among other things.

4. Prevent data loss via email

Data Loss Prevention (DLP) skills can aid in the security of your company's data. Identify how DLP can be implemented in your workflow.

Also, limit the circulation of specific emails or files, or impose a digital rights management condition that limits who has access to the information.

5. Set up other key security measures

Securing your company's data is crucial, especially in today's world of remote work. Antivirus software, network analytics, firewalls, virtual private networks (VPNs), AI-enabled behavioral monitoring, data encryption, and other security measures may be used.

6. Focus on sensitive data

The sensitive data you are storing and processing can be an asset, but it is also a liability in terms of security and compliance. It is important to always know where sensitive data (such as personal identifiable information) is stored, and to apply measures like dynamic data masking to protect its anonymity while keeping it valuable.

Benefits of data security for small businesses

Small businesses that take data security seriously and take strategic actions to improve it are less prone to attack.

These businesses will also be able to meet their compliance obligations more efficiently and prevent reputational damage. All of these factors make business more convenient and profitable.

Because the cybersecurity world is constantly changing, you'll need to commit to monitoring and updating your network security on a regular basis to reap these benefits. This will help you stay current and safe.

Here are some proven strategies to help your business reap these benefits while avoiding cyber threats.

• Protect your business from external threats

Outsiders were responsible for over 70% of data breaches this year.

Minimizing external risks necessitates the use of thorough device security measures and the appropriate cybersecurity software.

• Protect your business from internal threats

While internal threats aren't as widespread as externally perpetrated attacks, they still warrant special attention.

Many of these attacks are absolutely avoidable. While hostile employees or ex-employees can always cause problems, many internal attacks result from poor access controls or a lack of staff training.

• Ensure your business is compliant

Ensuring that your company is compliant with data protection regulations is very important.

When it comes to data protection, a number of businesses are already living up to expectations by intensifying their cybersecurity.

Many regulatory agencies now require you to make the necessary efforts to secure your company and its data from hackers. You could risk substantial fines or trading restrictions if you don't comply.

• Ensure customer data security

It's not just the regulators that are concerned about data security. Consumers have been more interested in how firms protect their data; their awareness of the risks of organizations having large amounts of personal data has grown.

Furthermore, if you can establish an active dedication to data protection, you may gain loyal, long-term clients and increase your revenue.

Summary

Cyberattacks are becoming increasingly common among small businesses, but you don't have to be affected. You can avoid falling victim to preventable cyberattacks by implementing the necessary security measures, from employee training to suitable cybersecurity software. This will not only save you time and effort, but it will also save you money by preventing revenue losses, regulatory fines, and other costs.

The post All you need to know about data security and its benefits for small businesses appeared first on Cybersecurity Insiders.


July 02, 2022 at 09:09AM

Unconscious Bias: How to Understand, Identify and Manage It

We all have unconscious bias. In fact, our ability to use pattern recognition and informed judgement can be a benefit in many professions, especially cybersecurity. However, unconscious biases in areas of hiring, mentoring, promoting or developing staff could hamper efforts to build the cybersecurity workforce and to diversify the individuals who make up this group.

Unconscious Bias Series - Part 1(ISC)² has partnered with Cyversity, an organization whose mission is to achieve consistent representation of women and underrepresented minorities in the cybersecurity profession, to offer a series of free webinars addressing unconscious bias.

The first webinar in this series – Understanding Unconscious Bias – will take place on June 29 at 1:00 p.m. ET on the (ISC)² Security Briefings webinar channel. Registration is open now and (ISC)² members will earn 1 CPE credit for attending (either live or watching on-demand).

The cybersecurity workforce gap, estimated at 2.7 million globally, is a challenge facing organizations and professionals alike around the world. In 2021, (ISC)² launched its Diversity, Equity and Inclusion initiative committing to redefine the image of the cybersecurity professional and the profession to accurately reflect and value the diversity of the world it protects.

Lead by Suri Surinder, CEO & DEI Leader, CTR Factor, the three webinars will offer participants an engaging mix of insights, exercises, illustrations, activities and more to enable understanding of their biases. The second webinar will be on September 21 and will focus on Identifying Bias while the third webinar in the series will be on October 29 and will guide participants on Managing Bias. Participants of this series will leave with specific strategies and tactics that they can deploy in their day-to-day work as they learn the definition, domains and impact of bias.

Cyversity and (ISC)² are working together to draw more individuals to the cybersecurity workforce who are underrepresented in the field. To meet the forces threatening our governments, corporations and communities, the profession must develop a diverse community of cyber professionals who have the skills, knowledge and abilities to offset those threats. Diversity of thought, experiences and background only make us stronger.

The post Unconscious Bias: How to Understand, Identify and Manage It appeared first on Cybersecurity Insiders.


July 02, 2022 at 09:09AM

Hexnode Unveils Its Third Annual User Conference: HexCon22

SAN FRANCISCO–(BUSINESS WIRE)–Hexnode, the enterprise security solution of Mitsogo, is gearing up to launch its third annual virtual user conference, HexCon22. The three-day event, scheduled to commence on September 21 until 23 will be an open event featuring about 100 speakers from various verticals, endpoint management, cybersecurity and more.

The event will start off with a keynote message from Apu Pavithran, Founder and CEO of Hexnode. He will be joined by Rachana Vijayan (CMO and Director of Sales, Marketing and Partnership), Sahad M (CTO), and Bijo Paulose John (COO). The event will also be graced by other notable speakers including Joe Tidy (BBC News Cyber reporter), Burton Kelso (Chief Technology Expert, Integral), Brian Contos (Chief Security Officer, Phosphorous Cybersecurity Inc.), and many other CEOs, CISOs, and industry experts across the globe.

HexCon21 was a huge success and had garnered a lot of attention. This year, HexCon22, a conference revolving around enterprise security, is a must-attend event for every IT enthusiast. The event will witness experts from the field of enterprise mobility management, endpoint security, cybersecurity, IoT and areas related to remote work, hybrid work, building a healthy workplace, etc. The conference will also set the stage for new feature releases and product announcements, serving as a fairground for Hexnode customers and partners to analyse ‘everything Hexnode.’

“Our aim is to bring together the best in the industry experts and hear out their perspectives on the evolving technological trends. Every tech aficionado will find something to pique their interest. Building awareness, imparting knowledge and keeping up with the times is the whole essence of HexCon22,” says Apu Pavithran, Founder and CEO at Hexnode.

This year’s HexCon22 will be all about learning, networking and building professional camaraderie and will unveil an expanded security roadmap for businesses. Mark your calendars, register today and confirm your presence.

About Hexnode

Hexnode, an award-winning cloud-based Unified Endpoint Management (UEM) solution, was developed with the mission of helping enterprises manage their device fleet. Recognizing the value of corporate data and witnessing the emergence of BYODs, COPEs, and COBOs, Hexnode has been in an endeavor of introducing intelligent technologies to safeguard devices against threats and thefts. It offers full mobility management software compatible with all major platforms, including Android, Windows, iOS, macOS, Fire OS, and Apple TVs. Hexnode, known for its enthusiastic support crew, offers a free trial for those interested in giving it a try.

About Mitsogo Inc.

Mitsogo Inc. has established itself as one of the leading vendors of endpoint management and security solutions throughout the years. Mitsogo Inc., the company behind the award-winning Hexnode Unified Endpoint Management software, has been supporting businesses in securing their corporate endpoints since around a decade now. Mitsogo’s device management expertise to boost business productivity and compliance has been leveraged by companies of all sizes, from SMBs to Fortune 500s. Mitsogo’s products are designed to adapt to the most complicated business contexts.

The post Hexnode Unveils Its Third Annual User Conference: HexCon22 appeared first on Cybersecurity Insiders.


July 02, 2022 at 09:08AM

EY Announces Robert M. Lee of Dragos Inc. as an Entrepreneur of the Year® 2022 Mid-Atlantic Winner

HANOVER, Md.–(BUSINESS WIRE)–Ernst & Young LLP (EY US) today announced that Robert M. Lee, CEO and Co-Founder of Dragos Inc., the global leader in cybersecurity for industrial controls systems (ICS)/operational technology (OT) environments, was named an Entrepreneur of the Year® 2022 Mid-Atlantic winner. Entrepreneur of the Year is one of the preeminent competitive business awards for entrepreneurs and leaders of high-growth companies who think big to succeed. An independent panel of judges selected Lee based on his entrepreneurial spirit, purpose, growth, and impact, among other core contributions and attributes.

“This award really goes out to the entire industrial cybersecurity community and is a reflection of the hard work and progress made to protect critical infrastructure around the world from cyberattacks,” said Robert M. Lee, CEO and Co-Founder, Dragos. “The path to securing the industrial operations that people rely on requires us to educate and empower each other to all be successful.”

Winners were evaluated based on their demonstration of long-term value through entrepreneurial spirit, purpose, growth and impact, among other core contributions and attributes. Since its launch, the program has expanded to recognize business leaders in more than 145 cities in over 60 countries throughout the world who are building a more equitable, sustainable and prosperous world for all.

Lee is a recognized pioneer in the industrial cybersecurity community. He serves on the Department of Energy’s Electricity Advisory Committee, and is Vice Chair of DOE’s Grid Resilience for National Security Subcommittee. He is also a member of the World Economic Forum’s subcommittees on Cyber Resilience for the Oil & Gas and Electricity communities, and serves on the board of the National Cryptologic Foundation.

A business leader and technical practitioner, Lee helped lead the investigation into the 2015 attack on Ukraine’s power grid, and has been involved in the most significant cyberattacks on industrial infrastructure around the globe, including the investigation and analysis of the 2016 attack on Ukraine’s electric system, the 2017 TRISIS attack on a Saudi Arabian petrochemical facility, and the 2021 Colonial Pipeline ransomware attack. Lee’s work has been featured in the book Sandworm, on 60 Minutes, and most recently, he was invited to present at the World Economic Forum Annual Meeting in Davos.

Entrepreneur of the Year Award winners become lifetime members of an esteemed community of multi-industry award winners, granting them unlimited access to the experience, insight and wisdom of fellow alumni across over 60 countries, in addition to extensive support from EY resources and other members of the entrepreneurial community.

Ernst & Young LLP is a client-serving member firm of Ernst & Young Global Limited operating in the US.

About Dragos, Inc.

Dragos has a global mission: to safeguard civilization from those trying to disrupt the industrial infrastructure we depend on every day. The practitioners who founded Dragos were drawn to this mission through decades of government and private sector experience.

Dragos codifies the knowledge of our cybersecurity experts into an integrated software platform that provides customers critical visibility into ICS and OT networks so that threats are identified and can be addressed before they become significant events. Our solutions protect organizations across a range of industries, including power and water utilities, energy, and manufacturing, and are optimized for emerging applications like the Industrial Internet of Things (IIOT).

The post EY Announces Robert M. Lee of Dragos Inc. as an Entrepreneur of the Year® 2022 Mid-Atlantic Winner appeared first on Cybersecurity Insiders.


July 01, 2022 at 09:08PM

Teenagers are being encouraged to spread ransomware

Ransomware-as-a-service gang is on the prowl of teenagers who can act as distributors for malware. As law enforcement is tightening the noose around black hat hackers in all ways, ransomware spreading groups are now focusing more on luring teenagers into their business distribution stream.

According to a study made by security software firm Avast, cybercriminals are openly advertising their malware-building tools and distribution schemes on online communities and gaming platforms.

Their modus operandi for attracting teenagers is simple. Lurk on messaging (mainly telegram), gaming, music, and movie streaming platforms and somehow entice the children to join their distribution gangs.

Their attraction scheme is simple: offer their teenage members’ money when in need and then ask them to distribute ransomware, information stealers, and crypto miners.

By doing so, they can achieve two things- get virtual control of the teenager’s computing device that can be used for future malicious activities. Two is to simply gain new members in the team so that the focus of the law enforcement officers remains on the hackers and the budding team of hackers can do the work.

For this reason, Avast researchers are urging parents to monitor their children’s activities and be open to money matters as much as possible. The security firm is also requesting parents to spend time with their kids to inquire about what ‘Stuff’ is happening in their lives and is there anything that they can share with them.

Parents of teenage kids are also being asked to educate their children about the dangers lurking on the internet and how easily anyone can make them prey to scams.

And instead of restricting their actions, it is better if they make their children responsible citizens of the future.

According to a report released by UK’s National Crime Agency (NCA) school-going kids as young as nine are taking part in campaigns related to DDoS and ransomware attacks. And the year 2019-2020 witnessed a 107% increase in crimes conducted by students.

Was this a COVID-19 inducted lockdown effect?

 

The post Teenagers are being encouraged to spread ransomware appeared first on Cybersecurity Insiders.


July 01, 2022 at 08:58PM