Chris Krebs and Alex Stamos have started a cyber consulting firm

Former U.S. cybersecurity official Chris Krebs and former Facebook chief security officer Alex Stamos have founded a new cybersecurity consultancy firm, which already has its first client: SolarWinds. The two have been hired as consultants to help the Texas-based software maker recover from a devas

RedHat is acquiring container security company StackRox

RedHat today announced that it’s acquiring container security startup StackRox. The companies did not share the purchase price. RedHat, which is perhaps best known for its enterprise Linux products has been making the shift to the cloud in recent years. IBM purchased the company in 2018 for a

Decrypted: How bad was the US Capitol breach for cybersecurity?

It’s the image that’s been seen around the world. One of hundreds of pro-Trump supporters in the private office of House Speaker Nancy Pelosi after storming the Capitol and breaching security in protest of the certification of the election results for President-elect Joe Biden. Police w

FBI, NSA say ongoing hacks at US federal agencies ‘likely Russian in origin’

The U.S. government says hackers “likely Russian in origin” are responsible for breaching the networks of at least 10 U.S. federal agencies and several major tech companies, including FireEye and Microsoft. In a joint statement published Tuesday, the FBI, the NSA and Homeland Security&#

UK judge denies US request to extradite WikiLeaks’ founder, Julian Assange

A U.K. district court judge has refused to extradite WikiLeaks founder Julian Assange to the U.S. In a hearing at Westminster Magistrates’ Court this morning, Judge Vanessa Baraitser denied the extradition on grounds that Assange is a suicide risk and extradition to the U.S. prison system wou

T-Mobile says hackers accessed some customer call records in data breach

T-Mobile, the third-largest cell carrier in the U.S. after completing its recent $26 billion merger with Sprint, ended 2020 by announcing its second data breach of the year. The cell giant said in a notice buried on its website that it recently discovered unauthorized access to some customers’

One CMO’s journey with risk management and compliance

Marketers don't grow up daydreaming about risk management and compliance. Personally, I never gave governance, risk or compliance (GRC) a second thought outside of making sure my team completed required compliance or phishing training from time to time. So, when I was tasked with leading the Ge

After the FireEye and SolarWinds breaches, what's your failsafe?

"speakable-summary" dir="ltr">The security industry is reverberating with news of the FireEye breach and the announcement that the U.S. Treasury Department, DHS and potentially several other government agencies, were hacked due (in part, at least) to a supply chain attack on SolarWinds. These breach

Dozens of journalists’ iPhones hacked with NSO ‘zero-click’ spyware, says Citizen Lab

Citizen Lab researchers say they have found evidence that dozens of journalists had their iPhones silently compromised with spyware known to be used by nation-states. For more than the past year, London-based reporter Rania Dridi and at least 36 journalists, producers and executives working for the

We must end the era of adjunct surveillance

As consumers, most of us don't mind providing companies like Google, Facebook and Twitter with our personal data, as long as we get access to the services and solutions we want to use. However, many people don't realize that these companies function as data-collecting surveillance organizat

Just how bad is that hack that hit US government agencies?

It’s the nightmare scenario that has worried cybersecurity experts for years. Since at least March, hackers likely working for Russian intelligence have embedded themselves without detection inside the unclassified networks of several U.S. government agencies and hundreds of companies. Sen. R

2020 was a disaster, but the pandemic put security in the spotlight

Let’s preface this year’s predictions by acknowledging and admitting how hilariously wrong we were when this time last year we said that 2020 “showed promise.” In fairness (almost) nobody saw a pandemic coming. The pandemic is, and remains, a global disaster

Twitter fined ~$550K over a data breach in Ireland’s first major GDPR decision

Ireland’s Data Protection Commission (DPC) has issued Twitter with a fine of €450,000 (~$547,000) for failing to promptly declare and properly document a data breach under Europe’s General Data Protection Regulation (GDPR). The decision is noteworthy as it’s the first such cross

EU Council wants secure encryption and lawful data access

The Council of the European Union, the body which represents individual EU Member States’ governments, has adopted a resolution on encryption — calling for what they dub “security through encryption and security despite encryption”. “Competent authorities must be able