README | Cynthia Brumfield

Cynthia Brumfield

README | Cynthia Brumfield

Cynthia Brumfield

March 14, 2024

Rapid7 vs JetBrains: A vulnerability disclosure process gone bad

A recent conflict between Rapid7 and JetBrains over how to disclose vulnerabilities was marred by blame, confusion and conflicting philosophies.

Cynthia Brumfield

December 08, 2023

AlphV’s bid to report its victim to the SEC could backfire

The ransomware group AlphV reported a victim to the SEC for failing to report a cybersecurity incident, placing government regulators in a precarious position.

Cynthia Brumfield

November 03, 2023

Wartime muddies waters for 'hacktivist' threat

The rise of hacktivism in a world mired in two significant wars blurs the lines between military and citizen combatants, and holding them accountable won't be easy.

Cynthia Brumfield

October 25, 2023

The problems with vulnerability reporting

Several recent incidents in the U.S. system for reporting vulnerabilities highlight the importance of accurate, comprehensive bug reports for defenders.

Cynthia Brumfield

September 20, 2023

Bad torts: Law firms feel the heat from rising cyber threats

Experts say the sensitive data law firms hold and their lagging attention to cybersecurity make them prime targets.

Cynthia Brumfield

September 08, 2023

AI’s peril and promise for policymakers and cyber defenders

At this year’s Billington Summit, experts highlighted the risks and benefits that AI poses for national security and the cybersecurity sector.

Cynthia Brumfield

August 15, 2023

Postcards from Hacker Summer Camp 2023

The promise and threat of AI, government policy and surprising revelations about the Viasat hack were among the major takeaways from Black Hat and DEF CON.

Cynthia Brumfield

August 15, 2023

Dark Caracal: A bumbling, yet surprisingly effective, cyber mercenary group

At DEF CON, EFF security researcher Cooper Quintin discussed a mysterious group called Dark Caracal that has proven effective despite making many mistakes.

Cynthia Brumfield

May 17, 2023

Spyware vendors stagger as the U.S. and allies land a punch

The Biden administration’s executive order to restrict government use of commercial spyware put the spyware industry on notice, but experts say global collaboration will be needed to truly limit the spread of these invasive toolkits.

Cynthia Brumfield

April 03, 2023

Fungi fallout? Ore. psilocybin data bill draws cybersecurity scrutiny

Oregon is the first U.S. state to have legalized psilocybin for adult use. However, a new bill proposing data collection from psilocybin users could expose vulnerable populations to cybersecurity and legal risks and create a template for other states to emulate.

Cynthia Brumfield

February 21, 2023

New strategies, “soul-searching” needed to secure critical infrastructure

At this year’s S4 conference in Miami Beach, top industrial control system experts offered various solutions that could replace the increasingly obsolete security through obscurity method for protecting ICS.

Cynthia Brumfield

November 14, 2022

Cybercrime is more of a threat than nation-state hackers

Back-to-back security conferences detailed the latest threats posed by malicious nation-states on the one hand and cybercriminals on the other. One takeaway is that cybercrime volumes are more massive and more persistent than the higher profile advanced persistent threats.

Cynthia Brumfield

November 04, 2022

Feds eye virtual reality as the next privacy and security battleground

At the Federal Trade Commission’s annual PrivacyCon this week, a top regulator and outside experts zeroed in on digital risks posed by the nascent virtual reality industry.