-
Security researcher Mikko Kenttälä discovered a zero-click vulnerability in macOS Calendar that allows an attacker to add or delete arbitrary files within the Calendar sandbox environment.
-
By exploiting the vulnerability during a macOS version upgrade process, an attacker can gain remote code execution (RCE) capabilities without any user interaction by injecting malicious files via calendar invites.
-
The exploit chain abuses the Photos app configuration to gain access to the user's sensitive iCloud Photos data, bypassing TCC protections, and demonstrating the potential impact of the vulnerabilities.
-
I have written a guide to help cybersecurity leaders decide between in-house, hybrid, or outsourced Security Operations Center (SOC) models, covering 7 major steps.
-
Key steps include conducting a risk assessment to understand the environment, threats and potential business impact, defining security goals around monitoring, compliance, response time and user training, and evaluating costs of different SOC models.
-
In this guide I also recommend assessing the skills required for an effective SOC, including cyber threat analysis, incident response, threat hunting, network and cloud security, security engineering, automation and scripting abilities.
-
SANS Institute whitepaper "Building Security from the Ground up with Secure by Design" explores how to integrate Secure by Design (SbD) principles into product development to mitigate vulnerabilities early and recognize security as a core business requirement.
-
Key considerations include integrating SbD into the software development lifecycle (SDLC), supporting SbD with automation, reinforcing defense-in-depth, applying SbD to artificial intelligence (AI), identifying threats early with threat modeling, using SbD to simplify compliance, and establishing a culture of security.
-
The whitepaper provides five action items to help organizations get started on the journey to SbD, which is an iterative process that aims to reduce the cybersecurity burden by developing foundationally secure products from the ground up.
-
Julie Ragland, former CIO of Navistar, says boards often fall into the trap of thinking cybersecurity is a purely technical issue, focusing too much on tools and protections while missing key areas of responsibility.
-
Ragland emphasizes that boards need to understand their role in investment prioritization and incident response behaviors, which are not technical but critical for effective cybersecurity governance.
-
To educate boards, CIOs should provide external assessments of cyber recovery plans, penetration testing results, and focus on business risks and how IT contributes to protecting the organization, rather than giving technical presentations.
Stay Ahead in Cybersecurity!
Get the week's top cybersecurity news and insights in 8 minutes or less
I will never spam or sell your information.
-
Tanya Janca, an AppSec program director, says many companies still require college degrees for entry-level positions, despite calls for skills-based hiring from the National Cyber Director.
-
Entry-level AppSec job postings often list impossible requirements like CISSP certification, which requires five years of security experience, creating misaligned expectations.
-
Companies struggle to accurately define AppSec roles, covering areas from tools and architecture to monitoring and incident response, leading to hiring freezes until they determine their focus.
-
Cliff Stoll's "The Cuckoo's Egg" is widely considered essential reading for cybersecurity professionals, according to Reddit users.
-
Other highly recommended books include "Security Engineering" by Ross Anderson, "How to Measure Anything" by Douglas W. Hubbard, and "This Is How They Tell Me the World Ends" by Nicole Perlroth, which delves into the history of zero-days.
-
Books by Kevin Mitnick, such as "The Art of Invisibility", "The Art of Deception", and "Ghost in the Wires", are also popular suggestions, with Mitnick being referred to as "The OG" of cybersecurity.
-
Cisco, the U.S. tech giant, has announced its second layoff of 2024, letting go of approximately 5,600 employees, or 7% of its workforce.
-
The company refused to disclose who was affected by the layoffs until September 16, creating a "toxic environment" according to one employee, and the layoffs also impacted the Talos Security unit.
-
Despite Cisco citing 2024 as its "second strongest year on record" with nearly $54 billion in annual revenue, and CEO Chuck Robbins earning close to $32 million in 2023, the company stated that the layoffs would allow for investment in "key growth opportunities" and drive "efficiencies."
-
LinkedIn has opted accounts into training generative AI models without asking, according to reports from 404Media and TechCrunch, before updating its privacy policy.
-
The updated policy states that LinkedIn may use personal data to improve, develop, and provide products and services, develop and train AI models, and gain insights with the help of AI, automated systems, and inferences.
-
Users can opt out of having their data used for generative AI training by turning off the "Data for Generative AI Improvement" toggle in their account settings, but this does not affect training that has already taken place or other machine learning tools used for personalization and moderation.
-
Nico Waisman, Head of Security at XBOW, discusses the challenges CISOs face in evaluating security products amidst inflated claims and hype, especially in the AI domain.
-
XBOW engaged pentesting companies to develop 104 novel benchmarks that closely replicate various classes of real-life vulnerabilities, such as SQL Injections, IDOR, and SSRF, ensuring the AI system generates new ideas instead of regurgitating memorized examples.
-
The benchmarks, designed for testing both offensive tools and human experts, revealed that XBOW achieved an impressive 85% success rate, equivalent to an experienced pentester's performance within a week, and are now being made public for others to utilize and build upon while respecting the included canary string.
-
AWS announced a serverless solution for querying security data in Amazon Security Lake using natural language with Amazon Q in QuickSight, enabling use cases like generating visualizations and querying vulnerability data.
-
Security Lake centralizes security data from AWS, SaaS, on-premises, and cloud sources into a data lake stored in your AWS account, converting it to Apache Parquet format and the Open Cybersecurity Schema Framework (OCSF).
-
The solution architecture uses Security Lake for ingestion, Athena views for defining interesting fields, QuickSight datasets for analysis, and Amazon Q topics for natural language querying, requiring specific prerequisites and IAM permissions.
-
Sedric AI, a New York-based regtech, has raised $18.5 million in a Series A funding round led by Foundation Capital, with participation from existing investors StageOne Ventures and The Garage, and new investor Amex Ventures.
-
The Sedric platform uses large language models (LLMs) to help financial institutions manage regulatory compliance, risk, and communication monitoring across multiple channels and customer touchpoints.
-
With a total of $22 million in funding, Sedric plans to develop its AI lab in Tel Aviv and expand its global go-to-market teams, having seen a fivefold increase in revenue over the last 12 months.
-
According to a report by Dell'Oro Group, the Secure Access Service Edge (SASE) market growth has slowed down in the June quarter, climbing 9.7% to $2.3 billion compared to a 37% jump in the year-earlier period.
-
Despite the slowdown due to economic uncertainty, Dell'Oro analyst Mauricio Sanchez anticipates a rebound in the coming year as enterprises shift focus to long-term investments in cloud-based security and networking solutions, with single-vendor SASE solutions emerging as a clear winner.
-
The SASE market, which combines Security Service Edge (SSE) and SD-WAN technologies, has major players including Zscaler, Palo Alto Networks, Cisco Systems, Broadcom, Fortinet, and Netskope, with their stocks being impacted by the market slowdown.
-
CrowdStrike, in partnership with Amazon Web Services (AWS) and NVIDIA, announced the launch of their second annual Cybersecurity Startup Accelerator program to support disruptive startups in the U.S. and EMEA with mentorship, technical expertise, funding, and go-to-market opportunities.
-
Selected startups will participate in a free eight-week program offering mentorship from industry experts, access to global cybersecurity investors, up to $25,000 in AWS Activate credits, and the opportunity to present at an in-person Demo Day during the RSA Conference in April 2025.
-
The program aims to cultivate the next generation of cloud security companies by leveraging the expertise of market-leading cybersecurity (CrowdStrike), cloud (AWS), and AI (NVIDIA) providers, with potential funding from the CrowdStrike Falcon Fund for winning presentations.
High-performance remote packet capture and collection tool used for forensic analysis in cloud workloads.
CredStash is a tool used for managing and securely storing credentials, requiring installation of dependencies and setup of a key in AWS KMS, with specific Linux installation instructions available.
AirIAM is an AWS IAM to least privilege Terraform execution framework that compiles AWS IAM usage and leverages that data to create a least-privilege IAM Terraform that replaces the exiting IAM management method.
🔔 Want to stay ahead in cybersecurity?
Get the latest developments, security tools, market updates and resources delivered to your inbox every week.
I will never spam or sell your information.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz