Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials

He’s being prosecuted for giving border officials a code that wiped his phone: The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode. Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter…

BY Bruce Schneier
MIN READ 1 MIN READ
EXPLORE north_east
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security
CYBERSECURITY

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance. Key takeaways: Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Querying for isolated, hard-to-reach process-control systems, enables operators to establish a required security baseline. Predictive Vulnerability Priority Rating (VPR) scoring helps you prioritize and focus limited resources on the critical flaws that actually threaten physical safety and uptime. Advanced multi-detection engines and seamless IT workflow integrations accelerate mean-time-to-respond (MTTR) to help both security teams and operators align with a strict 72-hour reporting requirement. With the enactment of Canada’s Critical Cyber Systems Protection Act (CCSPA), commonly known as Bill C-8, the Canadian federal government is laying down a clear framework to protect the cyber-physical systems that are vital to national critical infrastructure security. For designated operators in telecommunications, energy, transportation, and banking, the mandate is clear: Establish formalized cybersecurity programs, mitigate supply chain risks, and — most critically — report cyber incidents to authorities within 72 hours. Failure to comply carries heavy consequences, including penalties that can reach up to $15 million Canadian dollars (CAD). But beyond the threat of fines, Bill C-8 highlights a fundamental operational challenge that many industrial organizations are still struggling to solve: How can you detect, investigate, and report a breach in 72 hours when you lack unified visibility across your converged IT and OT environments? Requirements for meeting Bill C-8’s 72-hour incident reporting mandate In modern industrial operations and critical infrastructure, the line between IT and OT continues to blur. The introduction of connectivity (e.g., IoT-connected cameras and building management systems) has optimized processes and service delivery, but it has also introduced new cyber exposures. Today, threat actors do not honor traditional network silos; they frequently compromise a web-facing IT asset or IoT device and move laterally into the operational technology (OT) environment to disrupt physical processes. Meeting a 72-hour incident reporting window is nearly impossible if your security team is relying on fragmented point solutions. Solutions that focus exclusively on passive OT network monitoring often leave massive blind spots — especially considering that IT and IoT devices can constitute up to 50% of an industrial environment. When an incident occurs, teams waste precious hours manually correlating alerts across disconnected tools rather than actively investigating the root cause. To comply with CCSPA and protect uptime, critical national infrastructure (CNI) operators must bridge the IT/OT security divide. Establish your CCSPA cybersecurity baseline The CCSPA requires operators to implement formalized cybersecurity programs. The foundation of any mature security program is a comprehensive asset inventory — you cannot secure what you cannot see. The Tenable One Exposure Management Platform helps organizations eliminate security blind spots by building a complete, unified inventory of all OT, IoT, and IT assets. Tenable goes beyond passive-only network monitoring with our proprietary Safe Active Query technology. This hybrid approach safely communicates with industrial devices in their native protocols to uncover significantly more assets than passive monitoring alone — including dormant process control systems, shadow IT, and unmanaged IoT — without disrupting process integrity or impacting equipment uptime. Prioritize what matters for physical safety Once you have established your security baseline, the next challenge is managing the inevitable flood of vulnerabilities. In highly regulated sectors, patching every vulnerability is simply not feasible, in part due to strict requirements for operational uptime. Instead of drowning your security teams in theoretical alerts, Tenable utilizes predictive Vulnerability Priority Rating (VPR) scoring. VPR uses data science and threat intelligence to measure the real-world exploitability of a vulnerability. By pinpointing the small fraction of critical flaws that actually threaten physical safety and production uptime, organizations can confidently prioritize remediation efforts and map their controls directly to CCSPA requirements and other compliance frameworks and industry standards like: North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) National Institute of Standards and Technology Cyber Security Framework (NIST CSF) Network and Information Security Directive 2 (NIS2) International Electrotechnical Commission (e.g., IEC 62443, 61850) Automate response to beat the clock To report an incident within 72 hours, you must be able to detect it instantly. Unlike similar reporting requirements in other regulations, the C-8 bill starts the reporting countdown the moment a cyber incident occurs, not when it’s detected. Tenable One leverages an advanced multi-detection engine, which combines behavioral anomalies, signature-based detection, and policy violations from Tenable One OT Exposure to uncover high-risk events in real time. Tenable maximizes your existing security investments through enterprise-scale integrations. By feeding critical OT intelligence directly into IT workflow platforms like ServiceNow and Jira with AI-powered workflow orchestration, you can automate incident response workflows in real-time across the necessary IT and OT teams when an anomaly is detected. This drastically reduces MTTR and provides the forensic context needed for rapid, accurate reporting. Source: Mobilization Quick Reference Guide, Tenable Docs Don’t wait for the audit Canada’s Bill C-8 is more than a compliance mandate; it is a wake-up call for critical infrastructure operators to mature their cybersecurity posture. Stop reacting to fragmented alerts and start managing risk across your entire cyber-physical ecosystem. Are you ready for the 72-hour reporting window? Request a demo of Tenable One OT Exposure today to see how you can unify your digital and physical attack surface, establish your CCSPA baseline, and secure your operations without disrupting productivity.

5 MIN READ arrow_forward
​​​​What’s new in Microsoft Security: July 2026
CYBERSECURITY

​​​​What’s new in Microsoft Security: July 2026

This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post ​​​​What’s new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog.

1 MIN READ arrow_forward
Timeless Compliance: Why Better Questions Beat Bigger Frameworks
CYBERSECURITY

Timeless Compliance: Why Better Questions Beat Bigger Frameworks

The best compliance programs aren’t the biggest ones. They’re the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger Frameworks appeared first on SecurityWeek.

1 MIN READ arrow_forward
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
CYBERSECURITY

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,

1 MIN READ arrow_forward
Novee brings continuous AI pentesting to mobile apps
CYBERSECURITY

Novee brings continuous AI pentesting to mobile apps

Novee announced the expansion of its AI penetration testing platform to mobile applications. With this addition, Novee becomes the industry’s first complete AI pentesting platform across the modern application attack surface, providing continuous, autonomous coverage. The platform tests web apps and APIs, along with desktop, AI and LLM-enabled applications. Novee transforms mobile pentesting from a periodic assessment into an ongoing security practice. Users upload a mobile application package and receive results within hours, alongside findings … More → The post Novee brings continuous AI pentesting to mobile apps appeared first on Help Net Security.

1 MIN READ arrow_forward
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
CYBERSECURITY

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The warning comes from Proofpoint, who detected emails carrying the concealed exploit hitting inboxes. “The subject lines and lures are banal, likely so the targeted user opens and skims the message, but dismisses the message as junk without … More → The post Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) appeared first on Help Net Security.

1 MIN READ arrow_forward
After the Break-In: What Attackers Do Once They're Already Inside
CYBERSECURITY

After the Break-In: What Attackers Do Once They're Already Inside

Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware.

1 MIN READ arrow_forward