Trivy, Not LiteLLM Behind the 2,500 Org Compromise

A Complex Web of Compromise: Unraveling the TeamPCP Attack on 2,500 Organizations In a shocking revelation, it appears that most of the 2,500 organizations affected by the LiteLLM supply chain attack were actually exposed through a compromise involving Aqua Security’s Trivy scanner, not LiteLLM itself. This twist highlights the intricate and interconnected nature of modern … Read more

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

The National Institute of Standards and Technology (NIST) is grappling with a daunting challenge: how to manage the ever-growing deluge of software vulnerabilities. The problem has been exacerbated by AI-augmented research and scanning, which has led to a surge in vulnerability discovery. To address this issue, NIST is seeking guidance on whether AI can be … Read more

Mission-Driven Security: Inside a Global Bank’s Defense

As global financial institutions continue to face a barrage of sophisticated cyber threats, the role of the chief information security officer (CISO) has never been more critical – or complex. At Standard Chartered, group CISO Cezary Piekarski is helping shape the modern security executive, one who must balance technical expertise with business acumen and cultural … Read more

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

A massive supply chain attack has left thousands of organizations vulnerable to cyber threats, with a surprising twist: most of the compromised systems were actually infected by a previous vulnerability in a popular security scanner, rather than the original malware. According to SOCRadar’s analysis, more than 2,500 organizations were likely affected by the LiteLLM attack, … Read more

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor’s Office

A potentially far-reaching data breach has struck the Scottish government, with thousands of employees’ personal information potentially compromised due to a third-party supplier’s security lapse. The breach is linked to an external contractor that was involved in an online data maturity assessment organized by the national government. The assessment, which aimed to gauge various agencies’ … Read more

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

A Perfect Storm of Vulnerabilities: Can AI-Driven Solutions Rescue the National Vulnerability Database? The cybersecurity landscape has never been more challenging. A tidal wave of software vulnerabilities, fueled in part by artificial intelligence-augmented research and scanning, has left many organizations struggling to keep up. In an effort to stay ahead of this trend, the National … Read more

Mission-Driven Security: Inside a Global Bank’s Defense

Cybersecurity’s New Frontier: How a Global Bank’s CISO is Redefining Security Leadership In an era where cyber threats evolve at breakneck speed and financial institutions remain prime targets for sophisticated adversaries, the role of the chief information security officer (CISO) has never been more critical. Cezary Piekarski, group CISO at global bank Standard Chartered, is … Read more

What Boards Need to Know About Tech Risk

Boards Underestimate Technology Risks Until It’s Too Late Technology has become an integral part of modern business operations, and its risks are often hidden in plain sight. Despite this, many boardrooms underestimate technology risk until it becomes a full-blown crisis. This is largely due to the way technology investments are perceived: as opportunities for growth … Read more