Microsoft Patch Tuesday, December 2025 Edition

• Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. • This final Patch Tuesday of 2025 tackles one zero-day

Cybersecurity · December 9, 2025 (updated February 19, 2026) · 2 min · 241 words

Drones to Diplomas: How Russia's Largest Private University is Linked to a $25M Essay Mill

• A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian u

Cybersecurity · December 6, 2025 (updated February 24, 2026) · 2 min · 403 words

Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure

• Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure Actions for Operational Technology Owners and Operators to Take Today to Mitiga

Cybersecurity · December 5, 2025 (updated February 24, 2026) · 2 min · 273 words

SMS Phishers Pivot to Points, Taxes, Fake Retailers

• China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday s

Cybersecurity · December 4, 2025 (updated February 24, 2026) · 2 min · 383 words
A NICE Retrospective on Shaping Cybersecurity's Future

A NICE Retrospective on Shaping Cybersecurity's Future

• a NIST blog Rodney Petersen has served as the Director of NICE at the National Institute for Standards and Technology (NIST) for the past eleven years where his focus has been on

Beware of double agents: How AI can fortify - or fracture - your cybersecurity

Beware of double agents: How AI can fortify - or fracture - your cybersecurity

• AI is rapidly becoming the backbone of our world, promising unprecedented productivity and innovation. • But as organizations deploy AI agents to unlock new opportunities and dri

Big Tech · November 5, 2025 (updated February 24, 2026) · 2 min · 237 words
Preparing for Threats to Come: Cybersecurity Forecast 2026

Preparing for Threats to Come: Cybersecurity Forecast 2026

• Preparing for Threats to Come: Cybersecurity Forecast 2026 Blog and Content Manager Visibility and context on the threats that matter most. • Every November, we make it our missi

Threat Intelligence · November 4, 2025 (updated February 24, 2026) · 2 min · 218 words
Space is the new cybersecurity frontier: Here are the startups leading the race

Space is the new cybersecurity frontier: Here are the startups leading the race

• Space infrastructure is evolving from exclusive government and military operations into critical commercial applications - includingnavigation systems,satellite internet, andgeos

Sharpening the Focus on Product Requirements and Cybersecurity Risks: Updating Foundational Activities for IoT Product Manufacturers

Sharpening the Focus on Product Requirements and Cybersecurity Risks: Updating Foundational Activities for IoT Product Manufacturers

• a NIST blog Update: The comment period for your feedback on the second public draft of NIST IR 8259 has been extended through December 10, 2025. • Over the past few months, NIST

CISA Shares Lessons Learned from an Incident Response Engagement

• CISA Shares Lessons Learned from an Incident Response Engagement Advisory at a Glance Executive Summary | CISA began incident response efforts at a U.S. • federal civilian execut

Cybersecurity · September 22, 2025 (updated February 24, 2026) · 2 min · 285 words
NIST Awards More Than $3 Million to Support Cybersecurity Workforce Development Across 13 States

NIST Awards More Than $3 Million to Support Cybersecurity Workforce Development Across 13 States

• Official websites use .govA.govwebsite belongs to an official government organization in the United States. • Secure .gov websites use HTTPSAlock(LockA locked padlock) orhttps://

Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System

• Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System Executive summary People’s Republic of China (PRC) state-sponsored cybe

Cybersecurity · August 25, 2025 (updated February 24, 2026) · 2 min · 260 words
Powering AI-Driven Security with the Open Cybersecurity Schema Framework

Powering AI-Driven Security with the Open Cybersecurity Schema Framework

• AWS Open Source Blog Powering AI-Driven Security with the Open Cybersecurity Schema Framework As organizations continue to innovate and scale their operations, security teams fac

CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization

• CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization Summary The Cybersecurity and Infrast

Cybersecurity · July 29, 2025 (updated February 24, 2026) · 1 min · 206 words

#StopRansomware: Interlock

• #StopRansomware: Interlock Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Ransomware Activity Prevent initial access by implementing domai

Cybersecurity · July 21, 2025 (updated February 24, 2026) · 2 min · 239 words

Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider

• Ransomware actors target unpatched SimpleHelp RMM to breach utility billing software provider customers. • Vulnerability CVE-2024-57727, a path traversal flaw, exploited in Simpl

Cybersecurity · June 12, 2025 (updated February 24, 2026) · 1 min · 160 words
The Impact of Artificial Intelligence on the Cybersecurity Workforce

The Impact of Artificial Intelligence on the Cybersecurity Workforce

• NICE Framework updated in 2020 to integrate emerging tech, especially AI, into cybersecurity workforce planning. • Stakeholder dialogues span federal agencies, industry, academia

Cybersecurity and AI: Integrating and Building on Existing NIST Guidelines

Cybersecurity and AI: Integrating and Building on Existing NIST Guidelines

• NIST held Cybersecurity & AI Profile Workshop to gather feedback on CSF and AI RMF profiles. • Profiles aim to guide adoption of AI in cybersecurity and defend against AI-enabled

Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations

• FBI & CISA issue joint advisory on LummaC2 infostealer targeting critical infrastructure. • Malware infiltrates networks, exfiltrates sensitive data via spearphishing links and a

Cybersecurity · May 20, 2025 (updated February 24, 2026) · 1 min · 150 words
Impact of AI on cyber threat from now to 2027

Impact of AI on cyber threat from now to 2027

• AI is accelerating threat sophistication, enabling attackers to craft more convincing phishing campaigns. • Machine‑learning models are used to generate polymorphic malware that

Five Years Later: Evolving IoT Cybersecurity Guidelines

Five Years Later: Evolving IoT Cybersecurity Guidelines

• NIST’s 2020 IoT Cybersecurity Improvement Act mandated five‑year guideline reviews. • IR 8259 set foundational cybersecurity activities for IoT manufacturers. • IR 8259A/B expand

Russian GRU Targeting Western Logistics Entities and Technology Companies

• Russian GRU’s 85th GTsSS unit 26165 targets Western logistics and tech firms. • Campaign focuses on coordination, transport, delivery of foreign aid to Ukraine. • Uses known TTPs

Cybersecurity · May 12, 2025 (updated February 24, 2026) · 1 min · 155 words
Small Businesses Create Big Impact: NIST Celebrates 2025 National Small Business Week

Small Businesses Create Big Impact: NIST Celebrates 2025 National Small Business Week

• NIST celebrates National Small Business Week, spotlighting SMBs’ vital role in U.S. economy and cybersecurity. • 34.8 million SMBs, 99% of U.S. businesses, 81.7% having no paid e

Journey to Zero Trust Access

• Yelp transitioned to fully remote, requiring secure, consistent access for a globally distributed workforce. • Existing VPN (Ivanti Pulse Secure) was unreliable, prompting a sear

Engineering Blogs · April 15, 2025 (updated February 24, 2026) · 1 min · 189 words

Fast Flux: A National Security Threat

• Fast flux hides malicious server locations by rapidly changing DNS records. • Enables cybercriminals and nation-state actors to evade detection and maintain C2. • Resilient, high

Cybersecurity · April 1, 2025 (updated February 24, 2026) · 1 min · 156 words
Vendor Security Assessment

Vendor Security Assessment

• Identify vendor security posture through comprehensive risk assessment. • Evaluate compliance with industry standards and regulatory requirements. • Assess data protection, acces

Threat report on application stores

Threat report on application stores

• Malware increasingly hides in legitimate app store listings, exploiting user trust for widespread infection. • Supply‑chain attacks target third‑party libraries, enabling attacke

The threat from commercial cyber proliferation

The threat from commercial cyber proliferation

• Commercial software proliferation expands attack surface, increasing vulnerability exposure across enterprises. • Open-source components in commercial stacks introduce hidden bac

The near-term impact of AI on the cyber threat

The near-term impact of AI on the cyber threat

• AI accelerates threat detection, enabling faster identification of malicious activity. • Adversarial AI allows attackers to craft evasive malware that bypasses traditional defens

The cyber threat to Universities

The cyber threat to Universities

• Universities face rising ransomware attacks targeting research data and student records. • Phishing campaigns exploit faculty credentials to gain network access. • Supply‑chain v

The Cyber Threat to UK Business

The Cyber Threat to UK Business

• Ransomware remains the top threat, targeting critical UK business data. • Phishing campaigns exploit remote working, increasing credential theft. • Supply‑chain attacks grow, com

The cyber threat to sports organisations

The cyber threat to sports organisations

• Sports organisations increasingly targeted by ransomware, phishing, and credential‑stealing attacks. • High‑profile events like the Olympics and World Cup attract sophisticated t

Summary of the NCSC analysis of May 2020 US sanction

Summary of the NCSC analysis of May 2020 US sanction

• US sanctions in May 2020 targeted Russian cyber actors and infrastructure. • NCSC identified increased threat actor activity following sanction announcements. • Sanctions disrupt

Summary of NCSC's security analysis for the UK telecoms sector

Summary of NCSC's security analysis for the UK telecoms sector

• UK telecoms face rising cyber threats, including ransomware targeting network infrastructure. • NCSC highlights supply chain risks from overseas vendors in 5G equipment. • Vulner

Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking

Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking

• BGP is critical for inter-ISP routing, requiring strict policy enforcement to prevent leaks and hijacks. • Implement prefix filtering and route origin validation to ensure only l

Organisational use of Enterprise Connected Devices

Organisational use of Enterprise Connected Devices

• Enterprise connected devices expand attack surface, enabling lateral movement across corporate networks. • Insider threats amplified as employees use personal devices for work, b

Joint report on publicly available hacking tools

Joint report on publicly available hacking tools

• Joint report reveals surge in publicly available hacking toolkits targeting critical infrastructure. • Analysts highlight increased ease of access via dark web marketplaces and o

Incident trends report (October 2018 - April 2019)

Incident trends report (October 2018 - April 2019)

• Over 1,200 cyber incidents reported across 30 countries, highlighting rising ransomware activity. • Ransomware attacks surged 35%, with CryptoLocker variants targeting healthcare

Decrypting diversity: Diversity and inclusion in cyber security report 2021

Decrypting diversity: Diversity and inclusion in cyber security report 2021

• Cybersecurity workforce remains 70% male, with women under 20% in technical roles. • Minority representation below 15%, limiting diverse threat perspective. • 2021 report links d

#StopRansomware: Medusa Ransomware

• Patch OS, software, firmware promptly to close known vulnerabilities across all systems. • Segment networks to limit lateral movement from infected devices and protect critical a

Cybersecurity · March 11, 2025 (updated February 24, 2026) · 1 min · 173 words
Celebrating 1 Year of CSF 2.0

Celebrating 1 Year of CSF 2.0

• One year since NIST released Cybersecurity Framework 2.0, boosting enterprise security readiness. • New 2025 resources offer tailored pathways for diverse audiences to implement

NIST's International Cybersecurity and Privacy Engagement Update - New Translations

NIST's International Cybersecurity and Privacy Engagement Update - New Translations

• NIST released 10+ new cybersecurity translations across six languages for global stakeholders. • International partners engaged through travel, sharing key NIST projects worldwid

Kicking-Off with a December 4th Workshop, NIST is Revisiting and Revising Foundational Cybersecurity Activities for IoT Device Manufacturers, NIST IR 8259!

Kicking-Off with a December 4th Workshop, NIST is Revisiting and Revising Foundational Cybersecurity Activities for IoT Device Manufacturers, NIST IR 8259!

• NIST’s 2020 IR 8259 outlines foundational cybersecurity activities for IoT device manufacturers. • The guide has 40,000+ downloads and is available in English, Spanish, and Portu

Unlocking Cybersecurity Talent: The Power of Apprenticeships

Unlocking Cybersecurity Talent: The Power of Apprenticeships

• Cybersecurity demand surges, yet no standardized entry path for professionals. • Registered apprenticeships offer paid, on‑the‑job training with real‑world experience. • Apprenti

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

• Verifiable digital credentials turn physical IDs into cryptographically verifiable digital tokens stored on smartphones. • Common buzzwords include ‘digital wallet,’ ‘mobile driv

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

• NIST launches Staff Stories Spotlight series during Cybersecurity Awareness Month to highlight diverse staff backgrounds. • Theme ‘Secure our World’ emphasizes global collaborati

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

• NIST launches Staff Stories Spotlight series for Cybersecurity Awareness Month, featuring Q&A with staff. • Theme ‘Secure our World’ underscores collective duty to protect digita

Integrate Elastic AI Assistant for Security via API to advance SOC workflows

Integrate Elastic AI Assistant for Security via API to advance SOC workflows

• Elastic AI Assistant for Security now offers chat and management APIs in Elastic Security 8.15. • APIs enable automated threat identification and data enrichment directly within

Building a next-gen SOC at Pinewood, a leading MSSP, underpinned by Elastic SIEM

Building a next-gen SOC at Pinewood, a leading MSSP, underpinned by Elastic SIEM

• Pinewood, a leading MSSP, deployed Elastic SIEM to centralize threat detection across finance, healthcare, retail, and government clients. • The platform aggregates logs, network

What you need to know about Process Ghosting, a new executable image tampering attack

What you need to know about Process Ghosting, a new executable image tampering attack

• Process Ghosting exploits the delay between process creation and thread notification, enabling pre‑scan tampering. • Attack writes malware to disk, deletes it, yet execution cont