Federal Bureau of Investigation (#FBI) and Cybersecurity and Infrastructure Security Agency (#CISA) have put out a joint advisory on #ScatteredSpider - a #cybercriminal group that targets large companies and their contracted information technology (IT) help desks. Scattered Spider threat actors, per trusted third parties, have typically engaged in data theft for extortion and have also been known to utilize BlackCat/ALPHV ransomware alongside their usual TTPs. This advisory covers all #TTPs and provides recommendations for mitigation.

Anyone in #criticalinfrastructure who uses external IT services (#MSP) should review this advisory and create awareness with your users to #BOLO this advanced attack vector.

This crew are masters of #SocialEngineering so watch yourselves. #StayCyberSafe #BeCyberSecure

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a

"#Cybersecurity is no longer a fringe issue β€” it has a seat at the #boardroom table, and if #businesses can't fill that seat, they need to make sure the person sitting there is as well-informed as possible."

"Failing to prepare is preparing to fail." One of my mentors as a teen told me this over and over again until it stuck. It definitely contributes to my overactive #paranoia of any and all digital systems, as well as authority figures (that's a different conversation lol), which is why I prepare for whatever worst-case-scenario I can imagine and guide my family through the same in this #WildWest digital frontier. #StayCyberSafe and #BeCyberSecure
https://www.darkreading.com/vulnerabilities-threats/talking-security-strategy-cybersecurity-has-a-seat-at-the-boardroom-table?_mc=NL_DR_EDT_DR_weekly_20230518&cid=NL_DR_EDT_DR_weekly_20230518&sp_aid=116563&elq_cid=38046155&sp_eh=144c4ccfdc4bcabeefa4110f1ea26cecf2a866a1c04b99a946a3df0524ced34c&sp_eh=144c4ccfdc4bcabeefa4110f1ea26cecf2a866a1c04b99a946a3df0524ced34c&utm_source=eloqua&utm_medium=email&utm_campaign=DR_NL_Dark%20Reading%20Weekly_05.18.23&sp_cid=48613&utm_content=DR_NL_Dark%20Reading%20Weekly_05.18.23

Talking Security Strategy: Cybersecurity Has a Seat at the Boardroom Table

Pending new SEC rules reinforce how integral cybersecurity is to modern business operations, and will help close the gap between security teams and those making policy decisions.

Dark Reading