Welcoming Our New Overlords
Our Take
We’re fans of this new buzzword: “Shadow AI.” Generative AI is getting integrated into every SaaS tool out there: customer support, content creation, graphic design, software development, etc. etc. … So how in the world do you balance the obvious productivity benefits with keeping your employees from dumping sensitive details – you know, PII, infrastructure info, proprietary code – into gosh-knows-who’s pool of data?
No answers at this point, only questions. Maybe Biden’s executive order will help … eventually.
What Lurks in the Dark: Taking Aim at Shadow AI
https://www.darkreading.com/vulnerabilities-threats/what-lurks-in-the-dark-taking-aim-at-shadow-ai
Biden issues sweeping executive order on AI
https://thehill.com/homenews/administration/4282336-biden-issues-sweeping-executive-order-on-ai/
This is our CINS Army Brief for October 2023, curating the most interesting cyber news from the previous month. Learn more and subscribe here.
- 2023 is already the worst year for hacks—and we’re not out yet
https://www.fastcompany.com/90966633/2023-breaking-records-hacks-cyberattacks - September saw a record 153% increase of ransomware attacks, says NCC Group
https://www.zdnet.com/article/september-saw-a-record-153-increase-of-ransomware-attacks-says-ncc-group - Ransomware Infection Times Fall From 5 Days to 5 Hours
https://www.pcmag.com/news/ransomware-infection-times-fall-from-5-days-to-5-hours - What Would a Government Shutdown Mean for Cybersecurity?
https://www.darkreading.com/vulnerabilities-threats/what-would-government-shutdown-mean-for-cybersecurity - High-profile summer attacks linked to same aggressive ransomware group
https://www.cybersecuritydive.com/news/high-profile-attacks-oktapus-ransomware/697998 - Why companies must prepare for future AI regulation
https://www.ciodive.com/news/global-AI-regulation-enterprise-response/697520 - Cybersecurity Awareness Doesn’t Cut It; It’s Time to Focus on Behavior
https://www.darkreading.com/vulnerabilities-threats/cybersecurity-awareness-doesnt-cut-it-focus-on-behavior - Cybersecurity Is Not Working: Time To Try Something Else
https://www.forbes.com/sites/forbesbusinesscouncil/2023/10/26/cybersecurity-is-not-working-time-to-try-something-else/?sh=a8d390f521fa - “You Can’t Be Siloed”: How Collaboration Among Stakeholders Can Help Better Manage Insider Threats
https://healthsystemcio.com/2023/10/23/you-cant-be-siloed-how-collaboration-among-stakeholders-can-help-better-manage-insider-threats - Hurricane Season And Cybersecurity Have More In Common Than You Think
https://www.forbes.com/sites/forbesbusinesscouncil/2023/10/25/hurricane-season-and-cybersecurity-have-more-in-common-than-you-think/?sh=37fe9a4d21f2 - Privacy vs convenience – which comes out ahead?
https://www.techradar.com/pro/privacy-vs-convenience-which-comes-out-ahead - ‘Log in with…’ Feature Allows Full Online Account Takeover for Millions
https://www.darkreading.com/remote-workforce/oauth-log-in-full-account-takeover-millions - Many SMBs wouldn’t trust employees with confidential information
https://www.techradar.com/pro/security/many-smbs-wouldnt-trust-employees-with-confidential-information - Many cyber bosses just aren’t confident in their company’s defenses
https://www.techradar.com/pro/many-cyber-bosses-just-arent-confident-in-their-companys-defenses - Will CISOs Become Personally Liable for Breach Response?
https://www.govinfosecurity.com/will-cisos-become-personally-liable-for-breach-response-a-23287 - Largest-ever DDoS leverages zero-day vulnerability
https://cyberscoop.com/largest-ddos-cloudflare-amazon-google - Data Thieves Test-Drive Unique Certificate Abuse Tactic
https://www.darkreading.com/endpoint/data-thieves-unique-certificate-abuse - Cybersecurity Trends to Watch in the US in the Next 5 Years
https://www.tripwire.com/state-of-security/cybersecurity-trends-watch - Medical Device Security Is A Top Challenge For Healthcare CIO
https://www.forbes.com/sites/davidchou/2023/10/04/medical-device-security-is-a-top-challenge-for-healthcare-cio/?sh=6e98678c55ca - Make these 5 changes to avoid becoming the next cybersecurity headline
https://techcrunch.com/2023/10/04/make-these-5-changes-to-avoid-becoming-the-next-cybersecurity-headline - Ransomware Crisis, Recession Fears Leave CISOs in Tough Spot
https://www.darkreading.com/vulnerabilities-threats/ransomware-crisis-recession-fears-leave-cisos-in-tough-spot - Company cyber budgets jump 70% in four years: Moody’s
https://www.businessinsurance.com/article/20230929/NEWS06/912360168/Company-cyber-budgets-jump-70-in-four-years-Moody%E2%80%99s-