CISA orders federal agencies to secure Microsoft cloud systems after ‘recent’ intrusions
For a while, it was just a recommendation. Now it’s mandatory. Federal civilian agencies were ordered to secure their Microsoft cloud systems after several recent cyber incidents. The Cybersecurity and Infrastructure Security Agency (CISA) issued a binding directive on Tuesday giving federal agencies a series of deadlines to identify cloud systems, implement assessment tools and abide by […]
SEC Charges Flagstar for Misleading Investors About Cyber Breach
ADMINISTRATIVE PROCEEDINGFile No. 3-22360 December 16, 2024 – The Securities and Exchange Commission today filed settled charges against Flagstar Bancorp, Inc. (now known as “Flagstar Financial, Inc.”), for making materially misleading statements regarding a cybersecurity attack on Flagstar’s network in late 2021 (the “Citrix Breach”). The SEC’s order finds that Flagstar negligently made materially misleading statements […]
Deloitte Sued Over Breach of Rhode Island Government Benefits Recipient Data
Deloitte has been getting its name in the news this month, but not in a good way. First, a ransomware group named “Brain Cipher” claimed to have attacked Deloitte UK. Deloitte responded to their claims by denying that their network was breached and stating that the breach involved a single client’s system that is not […]
Wanted Russian Hacker Linked to Hive and LockBit Ransomware Arrested
The Hacker News reports that a notorious Russian cybercriminal wanted in the U.S. in connection with LockBit and Hive ransomware operations has been arrested: According to a news report from Russian media outlet RIA Novosti, Mikhail Pavlovich Matveev has been accused of developing a malicious program designed to encrypt files and seek ransom in return for a […]
Is The FinCEN Laying The Foundation For The G.O.A.T. Data Breach?
A recent article by Allen Matkins Leck Gamble Mallory & Natsis LLP begins: On May 29, 1453 the walls of Constantinople had stood unbreached for more than a thousand years. Yet on that day, the army of Sultan Mehmed II was able to force entry into the city through the Gate of St. Romanus. The Byzantine Emperor Constantine […]
NYDFS Issues Industry Guidance on Risks Arising from Artificial Intelligence
It seems like everything is “AI” these days, but there’s also an increasing awareness of the flaws or risks in using AI for some purposes, including AI making up things that just aren’t true (called “hallucinations”). But there are also cybersecurity risks. From Covington and Burling: On October 16, 2024, the New York Department of […]
Should regulators do more naming and shaming?
The U.K. Information Commissioner’s Office did an interesting two-year trial and the results suggest that publicly reprimanding public sector entities over breaches and data leaks is an effective strategy — even without any monetary penalties. Infosecurity Magazine reports: The publication of reprimands following data leaks has been cited as an “effective” deterrent for public authorities. […]