CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also
Interpol's Operation Jackal IV has resulted in 58 arrests and identified 263 cybercrime suspects distributed across 22 countries, representing a significant multinational enforcement action. The operation demonstrates coordinated international law enforcement efforts targeting cybercriminal networks on a global scale.
Baby monitoring companies like Nanit are expanding their surveillance capabilities through AI-powered systems designed to track infants and young children's health, development, and behavior around the clock. These platforms are collecting increasingly granular biometric and behavioral data—from speech and language development to motor skills—while planning to extend their monitoring reach into early adolescence. The sector's significant funding and ambitions raise concerns about the scale and scope of data collection on minors who cannot consent to surveillance.
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation. Given the volume of
Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. The post The MFA Identity Trap: When Authentication Creates a False Sense of Security appeared first on SecurityWeek.