Featured
October is Cybersecurity Awareness Month: Why Cyber Basics Still Matter

As October kicks off, we are reminded of the importance of Cybersecurity Awareness Month and Cybersecurity Career Awareness Week. These initiatives serve not just to raise awareness but to equip everyone—from individuals to organizations—with the tools and knowledge to protect against the growing wave of cyber threats. Between strong passwords, 6-digit PINs, and fingerprints scanned […]

Read more
Featured
Reflecting on National Cybersecurity Awareness Month 2023: A Call for Continued Vigilance

October is recognized as Cyber Security Awareness Month and as we come to the end of the month, so does National Cybersecurity Awareness Month (NCSAM) 2023. This annual observance, dedicated to promoting cybersecurity awareness, provides a valuable opportunity to reflect on the critical issues surrounding digital safety, the history of NCSAM, and the imperative of […]

Read more
General Security
Top 5 Open Source Vulnerability Security Scanning Tools

Nmap: Nmap is a powerful open source network exploration and security auditing tool that can help identify vulnerabilities in a system. It is widely used for port scanning, version detection, and network mapping. Nmap can also be used for vulnerability scanning by detecting known vulnerabilities in software and services running on a system. OpenVAS: OpenVAS […]

Read more
Featured
The Benefits of Sock Puppets in Open-Source Intelligence (OSINT)

A Sock Puppet is fake persona, or an alternative online identity used to collect and investigate open-source information on a target.

Read more
Featured
The Open-Source Intelligence (OSINT) Cycle

Open-source intelligence, or OSINT, refers to the process of collecting information from public and legal data sources to serve a specific function. Some open sources components might include social media, videos, blogs, news, and the web (surface, Deep and Dark Web). 

Read more
General Security
U.S. Can Expect to see more Ransomware Attacks


In the cybersecurity space, there are many things we do not all agree on, but one thing I have noticed in the past year is that we all agree that the U.S. can expect to see more ransomware attacks as the nation recover from recent attacks which included the District of Columbia Police Department, The Colonial Pipeline and now the JBS meat plant. These will continue to increase, especially in the state, local environment, as well as in the critical infrastructure and manufacturing space.
There are two main reasons for this trend:
1. Organizations are not implementing the basic security controls thus allowing attackers to take advantage of easy attack vectors. A major of the critical infrastructure in the U.S. are operated by private organizations with very little IT and security regulations.

2. Many organizations are frequently deciding to pay the ransom after they have been attacked. Security researchers and law enforcement often recommend organizations not to pay the ransoms, but when stakeholders and the media are applying pressure, organizational leader must do what is best for the organization. This validates the ransomware industry and their frequency and tactics become more sophisticated.

This recent attack seems to have a Russian’s group fingerprint associated to it just like the pipeline event. Many security researchers, law enforcement officials and politicians are recommending in conjunction to increasing regulations on U.S. based organizations, the U.S. must also impose sanctions against countries that allow these types of activities to occur inside their borders.

Read more
General Security
Bad Ending for Washington, D.C.'s Metropolitan Police Department (MPD) after a Ransomware Attack

A group of ransomware hackers known as “Babuk” leaked internal police files from the Washington, D.C. Metropolitan Police Department (MPD).  The information was stolen in late April. 

Read more
General Security
Colonial Pipeline Ransomware Attack

One of the nation's largest fuel pipelines has been forced to shut down after being affected by a ransomware cyberattack.  Ransomware is a form of malware that encrypts a victim's files. The attacker then demands a ransom from the victim to restore access to the data upon payment. 

Read more
General Security
Ransomware attack leads to shutdown of major U.S. pipeline system

By: David E. Sanger A cyberattack forced the shutdown of one of the largest pipelines in the United States, in what appeared to be a significant attempt to disrupt vulnerable energy infrastructure. The pipeline carries refined gasoline and jet fuel up the East Coast from Texas to New York. The operator of the system, Colonial Pipeline, […]

Read more
General Security
The Cybersecurity Job Gap and How Getting Women in STEM can Help [Video]

As previously stated, Researchers at Cybersecurity Ventures detailed in a 2019 post there would be 3.5 million unfilled cybersecurity positions globally in 2021, but with the addition of 700,000 additional skilled practitioners according to a Cybersecurity Workforce Study that entered the field this year, the projected number has dropped to approximately 3,21 million.

Read more