Cybersecurity

Mitre ATT&CK News

Explore the latest news articles and reports about the Mitre Attack Framework, a curated knowledge base that helps network defenders learn exactly how networks are attacked. Discover everything about it and its place in the world of cybersecurity.

Top news of the week: 06.01.2022.

#cybersecurity
#google
#threatintel
#log4j
#msftsecurity
#cloudsecurity
#siemplify
#exploit
#acquisition
#ITsecurity

Mitre Attack

@PatrickCMiller shared
On Jan 6, 2022
Attackers Exploit Log4j Flaws in Hands-on-Keyboard Attacks to Drop Reverse Shells https://t.co/mZeyz5NPrq
Open
Attackers Exploit Log4j Flaws in Hands-on-Keyboard Attacks to Drop Reverse Shells

Attackers Exploit Log4j Flaws in Hands-on-Keyboard Attacks to Drop Reverse Shells

Microsoft says vulnerabilities present a "real and present" danger, citing high volume of scanning and attack activity targeting the widely used Apache logging framework.

@CSOonline shared
On Jan 6, 2022
A framework to vet security processes for human execution https://t.co/49hHdVFsxk
Open
A framework to vet security processes for human execution

A framework to vet security processes for human execution

Make sure you take human interaction and communication into account when developing your security processes. Here's a simple framework that can help.

@PatrickCMiller shared
On Jan 4, 2022
Cybersecurity M&A Roundup: 35 Deals Announced in December 2021 https://t.co/sIA798RrMB
Open
Cybersecurity M&A Roundup: 35 Deals Announced in December 2021

Cybersecurity M&A Roundup: 35 Deals Announced in December 2021

SecurityWeek’s cybersecurity M&A roundup for December 2021 lists 35 deals, including ones that involved hundreds of millions or billions of dollars.

@jaysonstreet shared
On Jan 3, 2022
RT @scythe_io: Shoutout to our own @Natha_Sect for getting her blog posted by @CybersecurityNp! 🦄🦄 https://t.co/MNpJO9NmCf
Open
Simplifying the MITRE ATT&CK Framework

Simplifying the MITRE ATT&CK Framework

This blog was originally published on 11/3/21 on Scythe's blog site. Author Nathali Cano Introduction Before we get into the nitty gritty of things, I’d like to briefly talk about the big ...

@ItsReallyNick shared
On Jan 5, 2022
RT @DeltaTangoTwo: Great blog by the team on finding the bad guys by using the power of KQL #msftsecurity https://t.co/FjLGQU2jul
Open
Leveraging the Power of KQL in Incident Response

Leveraging the Power of KQL in Incident Response

When your organization is faced with investigating a security incident, whether that’s something as simple as a phishing campaign or more complex like a determined human adversary, time is ...

@DarkReading shared
On Jan 4, 2022
Google Buys Siemplify to Get Ahead in Cloud Security https://t.co/XKZuJg2UnG by @roblemos #google #siemplify #acquisition #cloudsecurity
Open
Google Buys Siemplify to Get Ahead in Cloud Security

Google Buys Siemplify to Get Ahead in Cloud Security

Google says the deal will bring security orchestration, automation, and response to its Google Cloud security portfolio and expand its Chronicle platform.

@DarkReading shared
On Jan 4, 2022
Vinnie Liu Has a Mission: Keeping People Safe Online and Offline https://t.co/fcDA7dXSgc by @CarloMassimo6 #cybersecurity #ITsecurity #securitypro #NSA
Open
Vinnie Liu Has a Mission: Keeping People Safe Online and Offline

Vinnie Liu Has a Mission: Keeping People Safe Online and Offline

Security Pro File: The years at the National Security Agency shaped Vinnie Liu's views on security. "We're missionaries, not mercenaries," he says.

@DarkReading shared
On Jan 4, 2022
CISOs Plan What to Buy With Funds From the Infrastructure Bill https://t.co/4mLzoZSbE2 by @AFiscutean #CISO #infrastructure #cybersecurity
Open
CISOs Plan What to Buy With Funds From the Infrastructure Bill

CISOs Plan What to Buy With Funds From the Infrastructure Bill

CISOs welcome the cybersecurity funding allocated under the Infrastructure Investment and Jobs Act, but say it’s not perfect because it doesn't address a key issue: people.