Task #154616
open(IN)SECURE Newsletter - January 15, 2025
0%
Description
A smorgasbord of knowledge and news -
View this email in your browser (https://mailchi.mp/helpnetsecurity.net/insecure-newsletter-2761484?e=b0f1ce63ac)
- (IN)SECURE Newsletter January 15, 2025
------------------------------------------------------------
A smorgasbord of knowledge and news
What’s new?
CISA has issued (https://www.helpnetsecurity.com/2024/12/19/cisa-bod-25-01-directive-secure-microsoft-cloud-environments/) a binding operational directive (BOD 25-01) requiring federal civilian agencies to secure their (Microsoft) cloud environments.
The White House has announced (https://www.helpnetsecurity.com/2025/01/08/the-u-s-cyber-trust-mark-label-launch/) the launch of the U.S. Cyber Trust Mark, a voluntary cybersecurity labeling program for consumer-grade internet-connected devices.
A ransomware gang dubbed Codefinger is encrypting data stored in target organizations’ AWS S3 buckets (https://www.helpnetsecurity.com/2025/01/13/codefinger-encrypting-aws-s3-data-without-ransomware-sse-c/) with AWS’s server-side encryption option with customer-provided keys (SSE-C), and asking for money to hand over the key they used.
$2.2 billion worth of cryptocurrency was stolen (https://www.helpnetsecurity.com/2024/12/19/cryptocurrency-hackers-stole-2-2-billion-from-platforms-in-2024/) from various platforms in 2024, Chainalysis’ 2025 Crypto Crime Report has revealed.
Some cybersecurity predictions for 2025:
As we look ahead to cybersecurity developments (https://www.helpnetsecurity.com/2025/01/09/2025-cybersecurity-community/) in 2025, there’s bad news and good—expect to see new challenging attacks and the cybersecurity community increasingly working together to counter threats that are beyond the scope of individual organizations.
In 2025, seven trends (https://www.helpnetsecurity.com/2024/12/27/data-ai-2025-trends/) will shape the future of data and AI, offering advantages for those who see these changes not as challenges but as opportunities to innovate and excel.
In the Internet of Things (IoT) sector, 2025 is shaping up to be a politically charged year (https://www.helpnetsecurity.com/2024/12/24/iot-2025-security/) .Webinar: Amplifying SIEM with AI-driven NDR for IT/OT Convergence (https://helpnet.link/928)
Join cybersecurity leader Erwin Eimers from Sumitomo Chemicals Americas on Thursday, January 23rd at 10 AM PT, to explore how AI-driven Network Detection and Response (NDR) enhances SIEM capabilities, bridging critical visibility gaps in converged IT/OT environments. Don’t miss this chance to transform your security operations - Register now! (https://helpnet.link/928)
Ideas to consider, practices to implement
- GitHub CISO on security strategy and collaborating with the open-source community (https://www.helpnetsecurity.com/2025/01/13/alexis-wales-github-ciso-security-strategy/)
- Time for a change: Elevating developers’ security skills (https://www.helpnetsecurity.com/2025/01/13/developers-cybersecurity-skills/)
- eBay CISO on managing long-term cybersecurity planning and ROI (https://www.helpnetsecurity.com/2025/01/07/sean-embry-ebay-enterprise-cybersecurity-planning/)
- Preventing the next ransomware attack with help from AI (https://www.helpnetsecurity.com/2025/01/10/darren-williams-blackfog-ransomware-awareness-training/)
- GitLab CISO on proactive monitoring and metrics for DevSecOps success (https://www.helpnetsecurity.com/2025/01/09/josh-lemos-gitlab-devsecops-success/)
- Balancing proprietary and open-source tools in cyber threat research (https://www.helpnetsecurity.com/2025/01/06/thomas-roccia-microsoft-threat-research/)
- Making the most of cryptography, now and in the future (https://www.helpnetsecurity.com/2025/01/07/cryptography-risks/)
- Overwhelmed by fraud? Here’s how financial pros fight back (https://www.helpnetsecurity.com/2024/12/27/patrick-harding-ping-identity-financial-fraud-future/)
- Why an “all gas, no brakes” approach for AI use won’t work (https://www.helpnetsecurity.com/2025/01/08/ai-gas-brakes-mindsets/)
- How CISOs can make smarter risk decisions (https://www.helpnetsecurity.com/2024/12/24/gavin-reid-human-security-ciso-cybersecurity-threats/)
- How companies can fight ransomware impersonations (https://www.helpnetsecurity.com/2024/12/23/cybersecurity-measures-ransomware-impersonations-video/) (Video)
Subscribe to get regular updates from Help Net Security. Choose between our daily and weekly newsletters, or you can also opt for specialized newsletters:
- Breaking news – sent for major events
- Cybersecurity jobs – sent weekly
- Open-source cybersecurity tools – sent monthly
- Chainsaw (https://www.helpnetsecurity.com/2025/01/13/chainsaw-open-source-tool-hunting-through-windows-forensic-artefacts/) - A tool for hunting through Windows forensic artefacts
- Sara (https://www.helpnetsecurity.com/2025/01/09/sara-open-source-routeros-security-inspector/) - A RouterOS security inspector
- Cyberbro (https://www.helpnetsecurity.com/2025/01/07/cyberbro-open-source-extract-iocs-check-reputation/) - A tool that extracts IoCs and checks their reputation
- Kata Containers (https://www.helpnetsecurity.com/2025/01/02/kata-containers-open-source-container-runtime-vms/) - A container runtime, building lightweight VMs
- reconFTW (https://www.helpnetsecurity.com/2024/12/30/reconftw-open-source-reconnaissance-automation/) - A tool that simplifies and automates the reconnaissance process
- Evilginx (https://www.helpnetsecurity.com/2024/12/23/evilginx-open-source-man-in-the-middle-attack-framework/) - A man-in-the-middle attack framework
https://www.helpnetsecurity.com
https://twitter.com/helpnetsecurity
https://www.linkedin.com/company/2146685/admin/
============================================================
Copyright © 2025 Help Net Security (Astus d.o.o.), All rights reserved.
You are receiving (IN)SECURE Newsletter because you opted in at our web site located on https://www.helpnetsecurity.com.
Note: Sometimes we send promotional maildrops to our list. We never share your details with anyone! We really send a limited number of maildrops per year, so we hope you won't unsbscribe because of them. Thanks in advance!
Our mailing address is:
Help Net Security (Astus d.o.o.)
Kastav
Kastav 51215
Croatia
Want to change how you receive these emails?
You can * update your preferences (https://helpnetsecurity.us2.list-manage.com/profile?u=f76e9593a7d90f4024574218d&id=28abe5d9ef&e=b0f1ce63ac&c=4a740830f4)
or * unsubscribe from this list (https://helpnetsecurity.us2.list-manage.com/unsubscribe?u=f76e9593a7d90f4024574218d&id=28abe5d9ef&t=b&e=b0f1ce63ac&c=4a740830f4)
.
No data to display
Also available in: Atom PDF Tracking page