Utah's K-12 districts now have new cybersecurity requirements under HB 44. The Utah Cyber Alliance was built to help navigate what comes next.
Our inaugural forum is May 29 in Draper. The bill's sponsor, a former university CISO, and the head of UEN are all in the room. Free for all government and education employees.
Register: https://t.co/tIebE3rJTq
HB 44 is now law in Utah. The Cybersecurity Commission is setting minimum standards for every school district in the state.
On May 29, we're walking through what's coming and how to prepare.
Free for government and education staff.
Utah now has its first cybersecurity trade association built for the public sector.
Join us on May 29 in Draper. No registration fee for government or education employees.
do you understand what just happened to Robinhood..
Someone sent a perfect phishing email - real domain, DKIM pass, SPF pass, DMARC pass and Robinhood's own servers delivered it.
Here's the chain:
→ Gmail treats john.doe@ and johndoe@ as the same inbox
→ Attacker registers a NEW Robinhood account using the dot trick of YOUR email
→ Sets the device name to raw HTML code
→ Robinhood's "unrecognized activity" email renders it unsanitized
The "Review Activity Now" button? Attacker's phishing site.
The email? 100% real.. Sent by Robinhood.. Signed by Robinhood..
Just because it passed every security check doesn't mean it's safe.
🚨 BREAKING: Toronto Police just seized “SMS Blasters” fake cell towers never seen before in Canada.
These portable devices hijack thousands of phones at once, blast fake bank/Canada Post texts, and knock out real service (even 911 calls).
Tens of thousands of phones hit.
Over 13 MILLION disruptions.
Three men charged 🇨🇳
• Dafeng Lin, 27, of Hamilton
• Junmin Shi, 25, of Markham
• Weitong Hu, 21, of Markham
This is next-level cyber crime on our streets. Stay alert. Never click surprise links.
#Toronto #CyberCrime #ScamAlert
Some of the problem is that you only hear mostly about the attacks on big, publicly traded companies that can't hide. Small and medium sized companies are too embarrassed or don't want the fallout from disclosure. So, everyone thinks it won't happen to them. Until it does.
Here is a video of a North Korean IT worker being stopped dead in their tracks upon being required to insult Kim Jong Un.
It won't work forever, but right now it's genuinely an effective filter. I'm yet to come across one who can say it.
1/ Meet Kabir Singh, an Indian scammer who impersonates Apple support and then rips off innocent vulnerable people.
He tried to scam me......but instead of paying him money, I hacked into his laptop and redeemed $10,000 worth of giftcards live on webcam!
NIST just launched an AI Agent Standards Initiative for identity, security, and interoperability. AI agents are becoming economic actors with zero legal infrastructure in place. We require businesses to register to operate. Why expect less of AI agents? https://t.co/pYFg2nGEv5
Treating your SD-WAN like 'set it and forget it' infrastructure? That assumption is being exploited right now.
CISA confirmed active global exploitation of Cisco SD-WAN vulnerabilities -- including an auth bypass that requires *zero credentials*. A compromised controller isn't one device. It's your routing, your segmentation, your visibility.
Three things to do today:
1. Confirm patch status on your SD-WAN controllers -- not your MSP's word, actual confirmation
2. Audit who has management-plane access and from where
3. If a third party manages this for you, ask for their patch cadence in writing
Patched the Ivanti EPMM zero-days and moved on? Stop. These backdoors survive patching -- meaning you may have locked an attacker *inside* your MDM. MDM owns every managed mobile device. Audit for compromise first, then patch. #CyberSecurity#MDM