SolarWinds CISO says security execs are ‘nervous’ about individual liability for data breaches 

Tim Brown didn’t call for indemnification laws, but suggested that CISOs dealing with legal implications for cyberattacks is stressful and a distraction from their core work.

The post SolarWinds CISO says security execs are ‘nervous’ about individual liability for data breaches  appeared first on CyberScoop.

Continue reading SolarWinds CISO says security execs are ‘nervous’ about individual liability for data breaches 

A major cybersecurity law is expiring soon — and advocates are prepping to push Congress for renewal 

The 2015 Cybersecurity Information Sharing Act provides vital legal protections for cyber threat sharing initiatives, they say.

The post A major cybersecurity law is expiring soon — and advocates are prepping to push Congress for renewal  appeared first on CyberScoop.

Continue reading A major cybersecurity law is expiring soon — and advocates are prepping to push Congress for renewal 

Security and privacy concerns challenge public sector’s efforts to modernize

For most public sector organizations, digital transformation is a work in progress, with the complexity of integrating new systems and privacy and security concerns remaining key barriers, according to a report by SolarWinds. Only 6% of respondents rep… Continue reading Security and privacy concerns challenge public sector’s efforts to modernize

SolarWinds Taken Private in $4.4 Billion Turn/River Capital Acquisition

SolarWinds will become a privately held company following its acquisition by Turn/River Capital for $4.4 billion in cash. 
The post SolarWinds Taken Private in $4.4 Billion Turn/River Capital Acquisition appeared first on SecurityWeek.
Continue reading SolarWinds Taken Private in $4.4 Billion Turn/River Capital Acquisition

Biden administration nears completion of second cybersecurity executive order with plethora of agenda items

Federal agencies would have to address everything from AI to cloud security to access management, sources told CyberScoop.

The post Biden administration nears completion of second cybersecurity executive order with plethora of agenda items appeared first on CyberScoop.

Continue reading Biden administration nears completion of second cybersecurity executive order with plethora of agenda items

SEC fines tech companies for misleading SolarWinds disclosures

The Securities and Exchange Commission charged four current and former public companies – Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited – with making materially misleading disclosures regarding cybersec… Continue reading SEC fines tech companies for misleading SolarWinds disclosures

Smashing Security podcast #390: When security firms get hacked, and your new North Korean remote worker

The SolarWinds have returned to haunt four cybersecurity companies who tried to hide their breaches and ended up with their trousers around their ankles, and North Korea succeeds in getting one of its IT workers hired… but what’s their plan?

All t… Continue reading Smashing Security podcast #390: When security firms get hacked, and your new North Korean remote worker

SEC hits four companies with fines for misleading disclosures around SolarWinds hack

Unisys, Avaya, Check Point and Mimecast will pay fines to settle charges that they downplayed in SEC filings the extent of the compromise.

The post SEC hits four companies with fines for misleading disclosures around SolarWinds hack appeared first on CyberScoop.

Continue reading SEC hits four companies with fines for misleading disclosures around SolarWinds hack

ISC2 Security Congress 2024: The Landscape of Nation-State Cyber Attacks

CISA advisor Nicole Perlroth closed out ISC2 Security Congress’ keynotes with a wake-up call for security teams to watch for nation-state-sponsored attacks. Continue reading ISC2 Security Congress 2024: The Landscape of Nation-State Cyber Attacks

PoC for critical SolarWinds Web Help Desk vulnerability released (CVE-2024-28987)

Details about and proof-of-concept (PoC) exploit code for CVE-2024-28987, a recently patched SolarWinds Web Help Desk (WHD) vulnerability that could be exploited by unauthenticated attackers to remotely read and modify all help desk ticket details, are… Continue reading PoC for critical SolarWinds Web Help Desk vulnerability released (CVE-2024-28987)