"Because of how Uber's PM ran our #bugbounty program, the moment the reporter reached out, I was able to respond effectively." Melanie Ensign @Wednesday on the value of collaboration in #securitycomms #cybersecurity #incidentresponse #CriticalPointWarStories

https://youtu.be/8Ltyei5e1UI

Bug Bounty, Incident Management - Melanie Ensign - They Called Her Christmas Day - w/ Kevin Riggle

YouTube

Vulnerability Patching Lag Exposes 91% of Organizations to Known Threats

The alarming truth is that 91% of organizations are leaving themselves exposed to known threats due to a vulnerability patching lag, with only 9% able to remediate high-severity flaws within a critical 24-hour window. This delay is not just a statistic - it's a recipe for disaster, with organizations thatโ€ฆ

https://osintsights.com/vulnerability-patching-lag-exposes-91-of-organizations-to-known-threats?utm_source=mastodon&utm_medium=social

#VulnerabilityManagement #PatchManagement #EmergingThreats #CyberHygiene #IncidentResponse

Vulnerability Patching Lag Exposes 91% of Organizations to Known Threats

Boost your security with timely vulnerability patching. Learn how 91% of organizations lag behind in remediation, exposing them to known threats - read now and protect your business.

OSINTSights

๐•๐š๐œ๐š๐ญ๐ฎ๐ซ๐ž โ€“ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐’๐ฉ๐ž๐œ๐ข๐š๐ฅ๐ข๐ฌ๐ญ ๐ข๐ง๐œ๐ข๐๐ž๐ง๐ญ ๐ซ๐ž๐ฌ๐ฉ๐จ๐ง๐ฌ๐ž & ๐ญ๐ž๐ฌ๐ญ๐ž๐ง

Sta jij stevig in je schoenen tijdens een cyberincident? En krijg je energie van incident response en het testen van security-maatregelen? In deze functie help je zorgorganisaties bij het detecteren, analyseren en herstellen van cyberincidenten.

โžก๏ธNieuwsgierig of direct solliciteren? Check de vacature en reageer: https://z-cert.nl/werken-bij/security-specialist-incident-response-testen

#vacature #cybersecurity #incidentresponse #werkenbijzcert

Ransomware groups now move from breach to exfiltration in hours โ€” not days.

The attack chain still has breakpoints. We cover where to break it. 

๐Ÿ‡ฌ๐Ÿ‡ง https://zurl.co/AeIfU
๐Ÿ‡ฉ๐Ÿ‡ช https://zurl.co/8FMQO

#CyberResilience #NIS2 #IncidentResponse #Cybersecurity

Whatโ€™s trending in cybersecurity today? Find out with the latest YouTube playlist weโ€™ve curated. ๐Ÿ‘€ https://www.youtube.com/playlist?list=PLXqx05yil_mcRdgaOdi1ED7Vc5pqT8bqy
#Malware #Phishing #IncidentResponse #CyberAwareness #AppSec
260603 rootshell.online

YouTube

๐Ÿšจ Ongoing ClickFix Campaign Alert ๐Ÿšจ

Threat actors are using fake browser/app update prompts to trick users into running malicious PowerShell scripts (Win+R โ†’ Ctrl+V).

Block & monitor these defanged IoCs:

๐Ÿ”น amalgama[.]lat
๐Ÿ”น bearman[.]bond
๐Ÿ”น burunduktracker[.]xyz
๐Ÿ”น cosmostars[.]shop
๐Ÿ”น lenders[.]digital
๐Ÿ”น megamegalodon[.]click
๐Ÿ”น merindashop[.]cyou
๐Ÿ”น mob[.]lanjut[.]in
๐Ÿ”น moll[.]lanjut[.]in

#ClickFix #ThreatIntel #CyberSecurity #InfoSec #Malware #IOC #DFIR #ThreatHunting #BlueTeam #SOC #CTI #DetectionEngineering #IncidentResponse #OSINT #PowerShell #WindowsSecurity

So, what's our collective #infosec take on how well #AI is working in #IR / #incidentresponse ?

On one hand, storytelling and contextualizing, acting decisively on poor data, and changing direction radically if someone has a good data point, is core to response management.

OTOH, I can think of no worse situation to lean on a word salad generator tuned to what has been popular buzzwords in the security media glossies the last decade(s).

"The reality is that #incidentresponse is not that different from product sprints," says Melanie Ensign @Wednesday. "A resilient organization should be able to ebb and flow and put together the right people at the right time." #cybersecurity #CriticalPointWarStories

https://youtu.be/8Ltyei5e1UI

Bug Bounty, Incident Management - Melanie Ensign - They Called Her Christmas Day - w/ Kevin Riggle

YouTube