4.7K Followers
983 Following
14.8K Posts
Metacurity.com (https://metacurity.com) is the one-stop destination for leading infosec news and cybersecurity developments. Run by infosec writer and columnist Cynthia Brumfield, Metacurity draws from thousands of sources every day to deliver aggregated summaries of the latest infosec developments. If anyone wants to get in touch with me, on or off the record, you can reach me at cynthia [at] digitalcrazytown.com or on Signal via Cynthia.507. Sign up for our free daily emails at https://www.metacurity.com. Searchable
Metacurityhttps://metacurity.com
Blueskyhttps://bsky.app/profile/msbrumfield.bsky.social
Columnshttps://www.csoonline.com/author/Cynthia-Brumfield/
Bookhttps://www.amazon.com/Cybersecurity-Risk-Management-Mastering-Fundamentals/dp/1119816289
Coursehttps://www.oreilly.com/live-events/cybersecurity-risk-management-with-the-nist-20-framework/0636920081497/
Cynthia's Personal Ramblingshttps://bsky.app/profile/msbrumfield.bsky.social
HHS unveiled a tool to help health care facilities assess their cybersecurity risks, yet forgot to renew its encryption certificate or something on its site that unveiled the tool.
https://cyberscoop.com/hhs-aspr-cybersecurity-risc-toolkit-update/

Metacurity is the only independent daily cybersecurity newsletter that is written outside the usual cyber press echosphere and is a refreshing alternative to vendor-driven content and PR-flavored threat intelligence.

Every day, Metacurity publishes critical infosec developments that CISOs, security engineers, IT decision-makers, and infosec practitioners should know, scanned from thousands of sources and expertly summarized.

I've never asked on social media before, but if you find value in it, please consider supporting. My goal is 10 new annual subscribers this month to put Metacurity on a solid footing🙏
https://www.metacurity.com/

Statement from Adam Meyers, Head of Counter Adversary Operations, CrowdStrike

No large-scale cyber campaigns from Iran have been observed thus far.

From the leaked DHS contractor database: There’s a company here getting $70m from ICE called Cyber Apex Solutions that uses Hotmail.

https://micahflee.github.io/ice-contracts/

Google issued a report this morning documenting the degree to which defense firms and telecoms are targeted by Russian threat actors, particularly one cluster called UNC5976.

https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-base/

As far as breach emails are concerned, this one is good. It uses the word "sucks."
This stinks - @JosephMenn got caught up in the massacre of the Washington Post today.

Bad timing for an email to hit my inbox

Booz Allen Automates Malware Analysis with Al Agents

Cool badge at DistrictCon

So, it's really going to happen. My next book to be published by Wiley is slated for release in April.

I have analyzed some high-profile cyber incidents and mapped them to the outcomes in the NIST 2.0 Framework.

The goal is to give real-world relevance to what can sometimes be dry but absolutely necessary cybersecurity fundamentals that all defenders should take to heart.

Even more exciting is that Wiley will be offering corporate and government purchasers some interesting options for their employees, customers, and clients. Stay tuned! Lots more to come.