How does a flaw potentially affecting the integrity of printer management application get a “critical” severity rating and one affecting the integrity and operation of anesthesia machines get a “moderate” severity rating? It has to do with our evolving and still immature system of rating (and therefore thinking about) cyber risk.
Reports
Ahead of Black Hat: Fear and Pessimism in Las Vegas
A survey of security professionals who have attended Black Hat reveals fears for From the 2020 Election, U.S. infrastructure
Cognitive Bias is the Threat Actor you may never detect
Cognitive bias among workers can undermine security work and lead to critical misinterpretations of data, warns Forcepoint X-Labs research scientist, Dr. Margaret Cunningham.
Dark Web Looms Large as Enterprise Threat
New research from the firm Bromium finds dark web listings are booming as operators offer tailored access to enterprise networks.
Episode 148: Joseph Menn on Cult of the Dead Cow also Veracode CEO Sam King on InfoSec’s Leaky Talent Pipeline
In this week’s episode of the podcast: Joseph Menn’s new book Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World hit store shelves this week. We reprise our March interview with Joe and talk about the origins of CDC. Also: is the talent pipeline for information security empty, or has it sprung a leak? We’re joined by Veracode CEO Sam King to talk about one of the top problems facing organizations: how to cultivate and keep information security talent.