Tags
September 2023
September 2023
- “Zero-click”
- “Toyota”
- “Storm-0558”
- “Rome Statute”
- “Police Service Northern Ireland (PSNI)”
- “International Criminal Court”
- “Common Vulnerability Scoring System (CVSS)”
- Spyware
- Pegasus (spyware)
- Online Safety Bill
- Okta
- NSO Group
- Nation-state
- Microsoft
- Mass-surveillance
- MageCart
- LastPass
- Identity
- End-to-end encryption (E2EE)
- Electoral Commission
- Cyber-norms
- Connected vehicles
- China
- Child Sexual Abuse Material (CSAM)
- Card skimming
- “Rail”
- “Qakbot”
- “Operation Duck Hunt”
- “Oktapus”
- “Metropolitan Police”
- Take down
- Russia
- Qbot
- Netgear
- National Cyber Security Centre (NCSC)
- National cyber
- Malwarebytes
- Malware
- Juniper
- Japan
- Federal Bureau of Investigation (FBI)
- Cybercrime
August 2023
August 2023
- “SPHERE23”
- “Risk”
- “Malicious extensions”
- “Excel”
- “Data scraping”
- “Cyber Security Sauna”
- “Budget”
- “Budgeting”
- Tesla
- Supply chain
- Ransomware
- Lapsus
- Ivanti
- Hacktivism
- “Wi-Fi”
- “SecureWorks”
- “Representative test data”
- “Mobile Device Management (MDM)”
- “FIDO2”
- “Drones”
- “Data loss”
- “Cyber budgets”
- “Chief Information Security Officer (CISO)”
- “Captcha”
- “Automation”
- Quantum Cryptography
- MOVEit
- Mobile Device Management
- Citrix
- ChatGPT
- Bots
- Artificial Intelligence (AI)
- Art
- Zoom
- Viasat
- Rapid7
- Privacy
- Police Service of Northern Ireland (PSNI)
- General Data Protection Regulation (GDPR)
- General Data Protection Regulation
- Freedom of Information (FOI)
- Election Interference
- Election
- Dark patterns
- Cyber Safety Review Board
- Cyber safety
- Barracuda Networks
- Side-channel attacks
- Side channel attacks (SCA)
- Side channel
- Progress Software
- Phishing
- MobileIron
- Google Play
- Espionage
- Dynamic code loading (DCL)
- Corrective control
- Cloudzy
- Cloud
- Capita
- California Privacy Protection Agency
- California Consumer Privacy Act
July 2023
July 2023
- TETRA
- Shadow IT
- Securities and Exchange Commission (SEC)
- National Health Service (NHS)
- Kids Online Safety Act
- Insecure Direct Object Reference (IDOR)
- Foreign Intelligence Surveillance Act (FISA)
- Clare O’Neil
- Cl0p
- Children’s Online Privacy Protection Rule (COPPA)
- Children and Teens Online Privacy Protection Act
- Breach disclosure
- Australia
- Security poverty line
- Security labels
- PwC
- JumpCloud
- EY
- Data brokers
- Data broker
- Adobe
- UEFI
- Safe Harbor
- Privacy Shield
- PoisonGPT
- Max Schrems
- Large Language Model (LLM)
- EU-US Data Privacy Framework
- Decoupling
- Data protection
- Balkanisation
- Regulation
- Port
- Operational Technology (OT)
- Operational Technology
- Logistics
- LockBit
- Link Rot
- File transfer
- Digital Identity
- Counter-Espionage
- Wagner
- Verizon Data Breach Investigations Report
- Verizon
- US Supreme Court
- Splinternet
- Solorigate
- SolarWinds
- Security and Exchange Commission (SEC)
- Password complexity
- Password
- Log4j
- Encrochat
- Cyberstalking
- Cyber Risk
- Clop
- Apple
June 2023
June 2023
- New York Department of Financial Services (NYDFS)
- Mirai
- Legal sector
- Anonymous Sudan
- Anonymous
- Thousand Talents Plan
- SIM Swapping
- Rewards for Justice
- Perimiter
- IP Theft
- Fortinet
- Incident Response
- Edward Snowden
- Continual Improvement
- Conti
- Thames Valley Police
- Ring
- National Security Agency (NSA)
- National Security
- Kaspersky
- Digital Balkanisation
- Amazon
May 2023
May 2023
- Volt Typhoon
- Standard Contractual Clauses (SCCs)
- Micron
- Meta
- Insider Threat
- Guam
- Fingerprint
- European Data Protection Board (EDPB)
- Diplomacy
- Data Protection Commission (DPC)
- Critical national infrastructure
- BrutePrint
- Brute force
- Biometric
- TikTok
- Montana
- Data Protection and Digital Information (DPDI)
- App Store
- Turla
- Snake
- SecureBoot
- Micro-Star International (MSI)
- Federal Security Service (FSB)
- European Union (EU)
- European Union
- Advanced Persistent Threat (APT)
- Advanced
- Uber
- T-Mobile
- Surveillance
- NotPetya
- Merck
- Joseph Sullivan
- Fraud
- Cyber insurance
- ByteDance
- Act of War
April 2023
April 2023
- RSA Conference
- RSA
- Right to Repair
- Product Security and Telecommunications Infrastructure Act (2022)
- Internet of Things (IoT)
- Internet of Things
- Digital Services Act
- Digital regulation
- Denial-of-Service (DoS)
- Data-driven cyber (DDC)
- 3CX
- Maturity model
- Hacker-for-Hire
- Verification
- RaidForums
- Juice Jacking
- Industrial control systems
- Data Breach
- Cloud Security
- Operation Cookie Monster
- Open AI
- National Cyber Force (NCF)
- National Cyber Force
- Genesis Market
- DevOps
- Cyber-warfare
- Cyber war
March 2023
March 2023
- Veeam
- Tech Sovereignty
- Prompt injection
- GPS
- GoAnywhere
- Acropalypse
- Samsung
- Pig butchering
- Outlook
- National Protective Security Authority (NPSA)
- Business Email Compromise (BEC)
- Business Email Compromise
- Anker
- Secure Boot
- Misinformation
- Geolocation
- BlackLotus
- White House
- United States of America
- Shoulder surfing
- Sextortion
- PIN Surfing
- Mitre ATT&CK
- MITRE
- Liability
- Endpoint Protection
- Cyber strategy
- Bring Your Own Device (BYOD)
February 2023
February 2023
- US Department of Defense
- Signal
- Misconfiguration
- Concentration risk
- Competition
- Social engineering
- SMS
- Multi-factor Authentication (MFA)
- Multi-factor authentication
- Lancashire Police
- Industrial Control Systems (ICS)
- ICEFALL
- GoDaddy
- Disinformation
- Dashboards
- VMware
- TrickBot
- Training data
- Sanctions
- Romance scams
- Exclu
- ESXiArgs
- Enchrochat
- Consent
- Bing Chat
- An0m
- Threat modelling
- Threat model
- Simple Sabotage Field Manual
- Risk Analysis
- Rate limiting
- OpenAI
- NCC Group
- Middle management
- Lazarus Group
- Lazarus
- JD Sports
- GPT-2
- Compliance
- Application Programming Interface (API)
- Account registration
January 2023
January 2023
- Smart devices
- Seizure
- Outage
- Hive
- GoTo
- Disclosure
- Data breaches
- Cyber Resiliency Engineering Framework (CREF)
- Crypto-currency
- PayPal
- Password Manager
- Norton LifeLock
- Costa Rica
- VALL-E
- Stuxnet
- Session tokens
- Royal Mail
- Passwords
- Federal Aviation Administration (FAA)
- CircleCI
- Scraping
- Quantum computing
- Facial recognition
- Cryptography
- Cracking
- Trust
- Transparency
- Soverignty
- Infostealer
- Deglobalisation
December 2022
December 2022
- Worm
- EternalBlue
- Epic Games
- Children’s Online Privacy Protection Act (COPPA)
- Windows Hardware Developer Program
- Supply-chain attack
- RackSpace
- Offensive Cyber
- Internal API
- Inastrgam
- Digital signatures
- Commodities
- Amazon Web Services (AWS)
- Passkeys
- Mercury IT
- Medibank
- Homomorphic Encryption
- Air Gap
- Reuglation
- Network and Information Systems (NIS)
- Managed Security Service Provider (MSSP)
- Managed Detection and Response (MDR)
- Eufy
November 2022
November 2022
October 2022
October 2022
- UK Informtion Commissioner
- Twilio
- See Tickets
- Raspberry Robin
- Performance measurement
- Liz Truss
- Interserve Group
- Federal Trade Commission (FTC)
- Cyber-espionage
- Boardroom
- Board
- Authenticaiton
- Accountability
- 0ktapus
- Optus
- Federal Office for Information Security (BSI)
- Clearview AI
- Action Fraud
- Workplace Surveillance
- Thermal imaging
- LockBit 3.0
- Authentication
- ProxyNotShell
- NetWalker
- Microsoft Exchange
- Data Access Agreement (DAA)
- Bring Your Own Driver
- BlackByte
- Binance
- United Nations
- Ukraine
- Internet governance
- International Telecommunicaions Union (ITU)
- Finland
- eBay
September 2022
September 2022
- Rockstar Games
- Revolut
- Personal Data Protection Bill (Indonesia)
- Kiwi Farms
- Guacamaya
- Grand Theft Auto
- Deepfakes
- Spell-jacking
- Privileged Access Management (PAM)
- Intercontinental Hotels Group (IHG)
- Human Trafficking
- Iran
- Data Protection and Digital Information Bill
- Bug bounty
- Attribution
- Albania
- Systemic risk
- One-time passwords
- Kochava
- Belarusian Cyber Partisans
- Belarus
August 2022
August 2022
- UK Conservative Party
- Lloyd’s of Londond
- wiper
- Thames Water
- South Staffordshire PLC
- Seabogium
- Reconnaisance
- RECON
- Mailchimp
- Janet Jackson
- DigitalOcean
- Yanluowang
- Tornado Cash
- Starlink
- SpaceX
- Personal accounts
- NHS 111
- Cryptocurrency
- Cloudflare
- Cisco
- Advanced Computer Software Group
- Traffic Light Protocol
- SunBurst
- Sovereign internet
- Reading list
- Election security
July 2022
July 2022
- Southern Co-Op
- protestware
- Opportunity cost
- Microsoft Defender
- Facewatch
- Electric Vehicles (EVs)
- Biometrics
- Actoin bias
- Risk aggregation
- Oracle
- FaceID
- Encryption
- Data exfiltration
- Data centre
- Cloud misconfiguration
- Climate change
- Backdoors
- Alibaba
- Whistleblower
- Ring doorbell
- Office of Personnel Management (OPM)
- Log4Shell
- False Claims Act
- Cyber Safety Review Board (CSRB)
- State surveillance
- Software supply chain
- Shanghai National Police (SHGA)
- Gonjeshke Darande (Predatory Sparrow)
- Attack surface
- Safety
- Kinetic cyber
- Cyber-attack
- BellTroX
June 2022
June 2022
- Targeted advertising
- Reproductive rights
- Infosecurity Europe
- Infosec2022
- Formula 1
- Environmental, Social and Governance (ESG)
- Cyber Warefare
- Cyber Incident Phoneline
- Process
- People, Process, Technology
- Interpol
- Health and Location Data Protection Act
- GDPR
- Zero-day
- Telecommunications
- Mandiant
- Known Exploited Vulnerabilities (KEV)
- Follina
- Computer Fraud and Abuse Act (CFAA)
- Website defacement
- Privacy legislation
- Manfuacturing
- Digital Shadows
- Confluence
- Atlassian
May 2022
May 2022
April 2022
April 2022
March 2022
March 2022
- Risk concentration
- Resilience
- Key Risk Indicators
- Key Performance Indicators
- IC3
- Capabilities
- Ukraine IT Army
- Satellite communications (satcom)
- Online Safety Bill (UK)
- Online Safety Bill (UK legislation)
- Initial Access Broker (IAB)
- General Data Protection Regulations (GDPR)
- Exotic Lilly
- Information warfare
- Distributed Denial of Service (DDoS)
- Cyber-crime
- Conti Ransomware
- Conti (ransomware gang)
- APT41
- AON
February 2022
February 2022
January 2022
January 2022
- UK Government
- Let’s Encrypt
- Hacktivist
- Cyber Essentials
- Balrusian Railways
- Trustworthy Computing
- No Place To Hide
- Information Commissioner’s Office (ICO)
- Home Office (UK)
- Crypto.com
- Crypto-wars
- Sodinokibi
- Security Programme
- Security Obstructionism (SecObs)
- Risk identification
- Digital Transformation
- Democratic People’s Republic of Korea (DPRK)
- UK Information Commissioner
- Positive Security
- NortonLifeLock
- Google Docs
- Crypto-mining
- Predicitions
December 2021
December 2021
November 2021
November 2021
- Tardigrade
- Nigeria
- Diversity
- Biomanfuacturing
- Rowhammer
- Private Key Infrastructure (PKI)
- National Security and Investment Act 2021
- Monzo
- Emotet
- Vulnerability disclosure
- Offensive security tools
- National Transport Safety Board (NTSB)
- Federal Bureuax of Investigation (FBI)
- Ethics
- Cyber defence
- Client-Side Scanning (CSS)
- Unicode
- Trojan Source
- Personal Information Privacy Law (PIPL)
October 2021
October 2021
September 2021
September 2021
- United Arab Emirates (UAE)
- Release the hounds
- Kaseya
- Dimitri Alperovitch
- Defend Forward
- BlackMatter
- Profession
- Passwordless
- OWASP Top 10
- Open Web Application Security Project (OWASP)
- Open Infrastructure Manager (OMI)
- OMIGOD
- Wireless charging
- User behaviour
- Proton Mail
- Encryption backdoors
- Proxyware
- Google Firebase
August 2021
August 2021
- Surveillance state
- Secure by design
- Data protection regulation
- Cosmos DB
- Securities Exchange Commission (SEC)
- Pearson
- Moral outrage
- Investor relations
- Machine learning (ML)
- Machine learning
- iCloud Photos
- iCloud
- Doxxing
- Cyber Runway
- Code poisoning
- Chiled sexual abuse
- Trusted Platform Module (TPM)
- Cyber offense
- Biometric authentication
- Spoofing
- PrintNightmare
- President Biden
- AIS
July 2021
July 2021
- Risk management
- Hafnium
- Data Sovereignty
- APT 40
- APT 31
- Windows Print Spooler
- Online anonymity
- Leaks
- Information Comissioner’s Office (ICO)
- Great Firewall of China
- Great Firewall
- CCTV
- Random Number Generators
- Kaspersky Password Manager (KPM)
- John Deere
- CVE-2021-34527
- Taskforce on Innovation, Growth and Regulatory Reform (TIGRR)
June 2021
June 2021
May 2021
May 2021
- U.S. Military
- U.K. National Cyber Force (NCF)
- Privacy defaults
- Operation Venetic
- Nuclear weapons
- NHS Digital
- Email security
- Cybercrime economics
- Amazon Sidewalk
- Technology detection dogs
- Health Services Executive (HSE)
- Colonial Pipelines
- Axa
- Asia
- West Midlands Trains
- Security engagement
- Security awareness
- Public exploits
- Phishing simulation
- Information Security Maturity Report
- DBIR 2021
- CyberUK
- ClubCISO
- 10 Steps to Cyber Security
- Royal United Services Institute (RUSI)
- Moriya
- Energy networks
- Energy
- Cyber power
- Critical infrastructure
- Command and Control (C2)
- BAE Systems
- SS7
- Smishing
- Reputation
- Physical threat
- Operational resiliance
- Metropolitan Police Department (Washington DC)
- Law enforcement takedown
- Confidential informant
- Canada
- Boris Johnson
- Beavers
- Babuk
April 2021
April 2021
March 2021
March 2021
February 2021
February 2021
- Solorwinds
- Initial Access Brokers (IABs)
- Bad IR
- Accellion
- SIEM
- Security vs Usability
- GRU
- Exaramel
- European Commission
- EU-UK Data protection adequacy
- Citibank
- Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI)
- The Long Hack
- The Big Hack
- TeamViewer
- Supermicro
- Package managers
- Isis
- Dependency confusion
- Bloomberg
- Trustwave
- SpamCop
- Interoperability
- Cleaview AI
- Cisco Talos
January 2021
January 2021
December 2020
December 2020
November 2020
November 2020
- Vishing
- UK National Cyber Force (NCF)
- UK National Cyber Force
- Sopra Steria
- Public health
- Measurement
- Home Depot
- Cyber public health
- USSOCCOM
- Speculative Execution
- Regional Comprehensive Economic Partnership (RCEP)
- Microsoft Pluton
- Meltdown
- Location tracking
- Association of South-East Asian Nations (ASEAN)
- Tim Berners-Lee
- TicketMaster
- Password Strength
- Nutrition labels
- Inrupt
- Cyber skills gap
- Voice over IP (VOIP)
- United States of America (USA)
- UK Information Commissioner’s Office (ICO)
- Regulatory penalty
- Redaction
- Marriott International
- Marriott
- Huawei
- Clean Network Program
- 5G
October 2020
October 2020
- McDonald’s
- Donald Trump
- Charities
- Application Programing Interfaces (API)
- Persistent engagement
- CyberFirst
- Coronairus (COVID-19)
- Contact Tracing
- British Airways (BA)
- British Airways
- NHS Test & Trace
- Integrity
- Detection
- Cell-mate
- US Treasury
- Huawei Cyber Security Evaluation Centre (HCSEC)
- Grindr
- EvilCorp
- Consumer security labels
September 2020
September 2020
- YOLOsec
- Value generation
- Security value
- Security strategy
- Pseudo-national threat
- Nationalism
- FOMOsec
- Commodity controls
- Windows Server
- NetLogon
- Experian
- National cyber capability
- Global Initiative on Data Security
- EU-US Personal data transfers
- Data Protection Commission (Ireland)
- Vulnerability Disclosure Policy (VDP)
- Security spending
- Security Spend
- Secure Cyber Risk Aggregation and Measurement (SCRAM)
- Quantification
- Personal liability
- Massachusetts Institute of Technology (MIT)
- Hiscox
- Gartner
- Fiduciary responsibility
- Cybersecurity and Infrastructure Agency (CISA)
- Cyber Readiness Report
- CEO liability
August 2020
August 2020
- Webex
- Security budgeting
- NZX (New Zealand Stock Exchange)
- JML (Joiners-Movers-Leavers)
- FBI (Federal Bureaux of Investigation)
- DDOS (Distributed Denial of Service)
- Threat Intelligence
- Mailto
- fraudulent data request
- Cover-up
- CISO
- ReVoLTE
- Prediction
- Ofqual
- MITRE Shield
- Estimation
- Automated decision-making
- Accuracy
- 4G LTE
- 2020 Exam Results
- Satellite Internet
- Market manipulation
- Liam Fox
- Energy markets
- Disinformation campaigns
- Bug bounties
- Black Hat
- No More Ransom Project
- GRUB
- Garmin
- Evil Corp
- Cyber-sanctions
- CWT Travel
- Boothole
July 2020
July 2020
- WastedLocker
- Test & Trace
- Sport
- Deepfake audio
- Data protection impact assessment (DPIA)
- Windows DNS
- SigRed
- Schrems II
- SAP NetWeaver
- Perfect 10 Vulnerabilities
- EU-US Privacy Shield
- Digital risk
- Digital divide
- 5G Mobile Networks
- OAuth
- Internet Balkanisation
- Hong Kong national security law
- Hong Kong
- Cosmic Lynx
- Natanz
- Mass hacking
- Internet Archive
- Efficiency vs Resilience
- EARN-IT Act
- Barclays
June 2020
June 2020
- Netsentinel
- Maersk
- Lawful Access to Encrypted Data Act
- Google Analytics
- Exchange
- Distributed Denial of Secrets
- Copy and paste
- Browser cache
- Breach notification
- Blueleaks
- Vault 7 Leaks
- Treck
- South Africa Postbank
- Public Key Infrastructure (PKI)
- Payment cards
- Like-farming
- Copy-paste compromises
- Central Intelligence Agency (CIA)
- Central Intelligence Agency
- Australia Cyber Security Centre (ACSC)
- Stalkerware
- Risk Avoidance
- Private Investigators
- Platform abuse
- Lawful hacking
- Hack-for-hire
- Dark Basin (aka Snowstorm)
- Corporate Espionage
- Citizen Lab
- Child exploitation
- Babylon Health
- REvil (Sodinokibi)
- Password stats
- Maze Group
- Israel
- Cybercrime business model
- Cyber security spending
May 2020
May 2020
- University of Cambridge
- Threat Metrix
- Octopus Scanner
- NTT Communications
- National Crime Agency (NCA)
- Mandient
- Legal privilege
- GitHub
- EasyJet
- DDoS-as-a-Service
- Capital One
- Winnti
- Virtualisation
- Collection 1
- ADT
- CyberTalks
- ThunderSpy
- Thunderbolt
- Risk quantification
- Ransomware costs
- NHSX
- Market Pricing
- Marcus Hutchins (MalwareTech)
- Malware analysis
- High-performance computing (HPC)
- Hedging
- Elexon
- CyberHedge
- Roblox
- Password Reuse
- Ohio (US State)
- Grubman Shire Meiselas & Sacks (GSM)
- Credential Stuffing
- Computer gaming
- Video Conferencing (VC)
- Video Conferencing
- Sheffield City Council
- Office 365
- Local Government
- Diversity and Inclusivity
- Automatic Number-plate Recognition (ANPR)
- Antivirus (AV)
April 2020
April 2020
- ZecOps
- Web shells
- Vulnerability identification
- UK Ministry of Defence
- Surveillance programmes
- Mail.app
- IBM Data Risk Manager
- IBM
- Cloud Hopper
- SkyWrapper
- Pastebin
- North Rhine-Westphalia
- Know your customer (KYC)
- Germany
- Department of Defense (US)
- Compliance risk
- AttackerKB
- AiR-ViBeR
- Travelex
- Rostelecom
- ransom payments
- cyber economics
- asymmetric threat
- TheyHelpYou
- Community Hubs
- Security Watercooler
- Morrisons
- Amazon Detective
March 2020
March 2020
- Third-sector data protection
- Schools & Education
- Phineas Fisher
- FSB
- FIN7
- DNS Hijacks
- Dharma
- Chubb
- Booz Allen Hamilton
- VPN
- Remote Working
- Remote Access
- VPN Security
- Securing Virtual Meetings
- Privacy vs Surveillance
- Pi-Hole
- Phased Array
- Pale Blue Dot
- Money Mules
- DuckDuckGo
- DNS Blocklist
- Whisper
- U.S. Cyber Strategy
- SMB
- Cyberspace Solarium Commission
- Avast
- US EARN IT
- Smart cameras
- Loyalty Cards
- Location Privacy
- LLHS
- INsecurity
- Certificate Scam
- Security Education
- IoT
- Authorised Push Payment