Search
01.04.2022 | 7'' read
Some not-so-dire 2022 predictions cybersecurity predictions
What's behind CrowdStrike's move to switch Principal Executive Offices to Texas? Plus, my predictions for 2022 includes ransomware attacks subsiding and supply chain security hitting a crisis point.
Read10.26.2021 | 6'' read
The software supply chain pain intensifies
A lighter than normal edition this week covering malware embedded in a JavaScript library causing some jitters in software supply chain circles. Plus, more Pegasus spyware revelations and an incredible Cyberwarcon agenda.
Read10.19.2021 | 10'' read
Guest op-ed: VPNs and targeted espionage concerns
Juan Andrés Guerrero-Saade writes: "When I saw the Restore Privacy documentation about VPNs getting consolidated under a shady company with a reputation for malware and adware distribution, my concern went deeper than the usual ad-peddling."
Read07.27.2021 | 8'' read
On apathy in cybersecurity
As far as we've come, it feels like we're chasing a tail that's disappearing in the distance. Attack surfaces are expanding faster than we can react to securing them and there's still too much friction when users try to adopt the best available security tools.
Read06.07.2021 | 8'' read
The definitive SBOM FAQ, ransomware as terrorism
A note on the passing of longtime Qualys CEO Philippe Courtot, the new language of Software Bill of Materials (SBOMs) and likening ransomware incidents to terrorism.
Read06.01.2021 | 5'' read
Extending SBOMs to the firmware layer
The reality is that the tech below the OS is an alphabet soup of complexity and security problems we just can't see. It's refreshing to see .gov carrying on this conversation in such a transparent manner. Even for firmware, SBOM is coming and you should start preparing for it.
Read05.17.2021 | 6'' read
Yawning through RSA conference week
It's RSA Conference week and, quite frankly, I'm yawning through most of it this year. There's just no way to replicate the in-person experience where RSA offsite networking drive a lot of deal-making, hirings and vendor partnerships. This year, it feels staler than usual and the year-long Zoom/headphone fatigue means that no one is excited to watch another virtual presentation with poor camera/microphone settings...
Read05.03.2021 | 6'' read
Security vendor ‘awards’ are meaningless
We complain a lot about FUD and snake-oil ruining this industry but so many reputable security vendors are getting sucked into this pay-for-an-award-logo that turns you in a bit of a laughing stock among educated buyers. Stop buying these fake awards. You're doing yourself and your company a disservice.
Read04.26.2021 | 5'' read
Remembering Dan Kaminsky (1979-2021)
I share some memories of the late Dan Kaminsky, including his generosity to the hacker community and an insistence on empathy for the end user. Plus, some supply chain pain points.
Read