Incident Response Ransomware Security

FBI Cyber Strategy goes from defense to disruption

The FBI’s new cyber strategy shifts the focus toward actively disrupting adversaries, dismantling infrastructure, seizing funds and imposing real costs on attackers. Four pillars drive the strategy: disrupt cyber adversaries, support victims, strengthen partnerships, and enhance the FBI’s own cyber capabilities. Rapid intelligence sharing and closer public-private cooperation should help organizations detect attacks earlier, contain […]

Cybersecurity Identity & Access Management MFA Phishing Social engineering

Oauth phishing bypasses passwords and MFA

The FBI warns of highly targeted OAuth consent phishing attacks aimed at prominent figures, their families, and acquaintances. Attackers impersonate government officials, media personnel, or known contacts, luring victims with fake file shares or meeting invitations. Granting permission to a malicious OAuth application gives attackers long-term access to emails, files, and other sensitive account data. […]

Cybersecurity

FBI urges prioritizing security in software suppliers

The FBI, along with CISA, advises businesses and organizations to choose software suppliers that prioritize security from the development phase. This approach aims to create a safer software landscape. To assist organizations, the FBI and CISA have released the ‘Secure by Demand Guide’. This document outlines how to evaluate software suppliers’ security practices during procurement. […]