The Infosec Archives 01.07.2022 - V5

The Infosec Archives 01.07.2022 - V5

Hey friends,

Welcome back to the Infosec Archives first edition of 2022!

Theme of the week?

Cybersecurity predictions! (and of course some more Log4j)

And now... Let's?dive in?as they say. ??


?--------------------

News:??

FTC to pursue companies that expose customer data due to not patching Log4j

Agency warns it will use its full legal authority against companies that fail to take reasonable steps against the Log4j vulnerability.

https://www.zdnet.com/article/ftc-to-pursue-companies-that-expose-customer-data-due-to-not-patching-log4j/

#2

I came across this article by Einat Meyron which summarizes nicely the top 10 cybersecurity trends and forecasts for 2022.

1.???Cyberattacks?will continue and even increase.

2.???They will become more?sophisticated, more?violent?and more?frequent.

3.???Specifically, Business Email Compromise (BEC) attacks will also become more precise and advanced, through social engineering that will help the malicious actors study the organization’s habits.

4.???The wind beneath the wings of cyberattacks will be?AI, which makes the task of identifying the attacks and their origin even more complicated.

5.???We’ll see many more combined ransomware?attacks.

6.???We’ll also see attacks whose first step is?data theft, in order to profit from selling.

7.???The abovementioned attacks will be affected by threats directed at the?company’s executives, about disclosure of personal and professional information.

8.???We’ll see many more?shutdowns of systems?and system backups, caused by Distributed Denial-of-Service (DDoS) attacks.

9.???As far as ransom attacks are concerned, the most dramatic element is the?supply chain. The complex process which involves many different interfaces might just be the window?through which threat actors attempt an attack.

10.?Cryptojacking?will exploit vulnerabilities which have not yet been patched or updated.

https://www.israeldefense.co.il/en/node/53171


--------------------

Career Advice: ??

Jerich Beason: Chief Information Security Officer | Board Advisor | Podcast Host?

I hope that in this year to come, you make mistakes. Because if you are making mistakes, then you are chasing dreams, trying new things, learning, living, pushing yourself, changing yourself, & changing your world.

It means you are doing things you've never done before, but more importantly, that means you're doing something. 99% failures are the result of never starting.

So that's my wish for everyone and my wish for myself. Make new mistakes. Make glorious, amazing mistakes. Make mistakes you’ve never made. Don't freeze, don't stop, don't worry that you won’t be good enough, whatever it is: that class you want to take, that career change you are contemplating, that business you want to start, that cert you want to go after, that love interest you want to ask out, or asking that person to be your mentor. You know exactly what that thing is for you. Whatever it is you're scared of doing, just do it!

Make your mistakes in 2022 and forever.

You will either find success, growth or maturation on the other side of those mistakes...maybe even all three.


--------------------

?Infosec Wisdom: ??

Jessica Boyer: Information Security Analyst

When is it okay to lie?

Security questions.

You know those annoying ones about what street you grew up on, what is your first pet name?

Most of these answers can come up in conversations, ether in person or online communication.

Lie, make something up, but don't put the truth down.

Also, don't forget what you made up....


?--------------------?

Mentorship/Education: ????

Heath Adams: CEO, TCM Security | Cyber Mentor | Hacker | YouTuber

12 HOURS of Free Ethical Hacking Training! We've released the entire first half of our best-selling Practical Ethical Hacking course for free on YouTube. Learn Linux, Python, and Hacking all with no strings attached.

Amazing field to break into and what better time than now? Come learn to hack as your New Year's resolution :)

https://www.youtube.com/watch?v=fNzpcB7ODxQ&feature=youtu.be&ab_channel=TheCyberMentor


?--------------------

Cybersecurity Heroes Podcast: ???

In order to get cyber insurance, companies have to fill out long questionnaires to show they’re taking important security steps.

With every passing year, these questionnaires get more complex, and companies have a harder time making sense of them. As a result, many don’t get the coverage they need.

One of the things the security community can do is identify the top priority actions that companies need to do to reduce impact, instead of leaving them feeling overwhelmed and under-protected.

Kirsten Bay, CEO of Cysurance, talked to us about the steps the cybersecurity industry can take to improve the process and what companies can do to make sure they’re getting the right policy for them.

Catch all the links to the episode below or search for #CyberSecurityHeroes in your favorite podcast player.

Apple:??

https://podcasts.apple.com/us/podcast/how-to-improve-the-cyber-insurance-process/id1559807252?i=1000546973590

Spotify:?

https://open.spotify.com/episode/1Ugn2xnIXTYeRr8dMNdL1p


p.s

If you enjoy the show, follow/subscribe and we would love a rating or a review on Apple so more people like you can find it!


--------------------

Meme of The Week ??

No alt text provided for this image

?

--------------------

That's a wrap for this week's Infosec Archives, see you again next week. ??

Brendon

Ger van Hees GAICD

?? AI Governance Advisor ?? Non Executive Director ?? Reduce Cyber Risk ?? Protect Privacy ?? Peace of Mind

2 年

Hi ??Brendon, I like the newsletter. Thanks for publishing. If I may add to the "When is it OK to lie" section: I always suggest to my students to use a password manager to generate long strings random characters (passwords) and use those to answer the security questions instead of the real answers. Then store those generated strings in the password manager under the comments section in the password entry for the website that they are answering these questions for. Obviously I assume they are using a password manager to store the username/password for the website in the first place! :-)

Einat Meyron????

Cyber Resilience ★ Reduce the impact of cyber attack & business cyber risks. Upgrade cyber security culture ★ Advocate for CISOs ★ Speaker ★ Powerlifting??? ★ ??

2 年

OMG ?? I'm so honored. So glad you liked it. Thank you ??

Jerich Beason

Chief Information Security Officer | Board Advisor | Podcast Host | Forbes Tech Council | Keynote Speaker | Instructor

2 年

Pretty cool getting a place on your list...cheers to 2022!

要查看或添加评论,请登录

?? Brendon Rod ??的更多文章

  • The Infosec Archives 04.22.22 V20

    The Infosec Archives 04.22.22 V20

    Hey friends, Welcome back to the Infosec Archives volume 20 ?????? Thank you again to all the contributors that make…

    12 条评论
  • Happy 1st Birthday Cyber Security Heroes ????????♂???

    Happy 1st Birthday Cyber Security Heroes ????????♂???

    Welcome to part 1 of our "Best of" Montage of Cybersecurity Heroes Podcast 2021. We hope you enjoy and thank you again…

    4 条评论
  • The Infosec Archives 04.15.22 V19

    The Infosec Archives 04.15.22 V19

    Hey friends, Welcome back to the Infosec Archives volume 19 ?????? We have some catching up to do! A lot happens in 2…

    2 条评论
  • The Infosec Archives 04.01.22 V18

    The Infosec Archives 04.01.22 V18

    Hey friends, Welcome back to the Infosec Archives volume 18 ?????? Can you believe it's already April?? One quarter…

    5 条评论
  • The Infosec Archives 03.25.22 V17

    The Infosec Archives 03.25.22 V17

    Hey friends, Welcome back to the Infosec Archives volume 17 ?????? A lot to unpack this week ??, hint hint..

    5 条评论
  • The Infosec Archives 03.18.22 V16

    The Infosec Archives 03.18.22 V16

    Hey friends, Welcome back to the Infosec Archives volume 16 ?????? Thank you again to all the contributors that make…

    10 条评论
  • The Infosec Archives 03.11.22 V15

    The Infosec Archives 03.11.22 V15

    Hey friends, Welcome back to the Infosec Archives volume 15 ?? Last week i was at the hairdresser. While she was…

  • The Infosec Archives 03.04.22 V14

    The Infosec Archives 03.04.22 V14

    Hey friends, Welcome back to the Infosec Archives volume 14 ?????? For all the criticisms of social media, now is the…

    13 条评论
  • The Infosec Archives 02.25.22 V13

    The Infosec Archives 02.25.22 V13

    Hey friends, Welcome back to the Infosec Archives volume 13 ?? Before we get started, I just want to say my thoughts go…

    8 条评论
  • The Infosec Archives 02.18.22 V12

    The Infosec Archives 02.18.22 V12

    Hey friends, Welcome back to the Infosec Archives volume 12 ?? While love is still hopefully in the air ??, no better…

    6 条评论

社区洞察

其他会员也浏览了