As predicted Log4j is going to be a problem for a long time

The Cyber Safety Review Board is operated by The Department of Homeland Security and in it’s inaugural report the Log4j vulnerability, spread and exploitation is discussed: CSRB Report on Log4j – Public Report – July 11 2022_508 Compliant (cisa.gov) It makes interesting reading. I wonder just how many developers do …

A few of the ransomware stories in the media at the moment – to give you some idea of the scale of the cyber security risk you have to plan for. Do you need training?

ransomware

I have gathered here just a selection of the ransomware stories that have made the headlines – for these there are many more that go unreported in the media or even outside the organisation. ‘Lives are at stake’: hacking of US hospitals highlights deadly risk of ransomware | Hacking | …

I have told everyone to use MFA so I do not need to think about more cyber security! UPDATED 14 July 2022

MFA multi-factor authentication diagram

This post was original published on 27 June 2022 Update 14 July 2022 Here is an article from the Microsoft Threat Intelligence Center (MSTIC) and the Microsoft 365 Defender Research Team outlining how the big phishing campaigns backed by experienced and skilled hackers can bypass the security of multi-factor authentication: …