Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CMMC Level 3 Requirements and DIBCAC Assessments

When you read through the posts on the Ignyte blog focusing on CMMC, you'll see that just about everything we talk about, unless otherwise specified, refers to CMMC Level 2. This is because it's the impact level that the vast majority of DoD contractors are going to need. CMMC Level 1 is the lowest level, protecting the least sensitive of the sensitive information the government has to offer. If all you're handling is Federal Contract Information (FCI), Level 1 is enough for you.

SCADA backup and recovery: protecting PC-based supervisory control systems

This guide is written for controls and automation engineers, OT infrastructure owners and plant leaders responsible for recovering PC-based SCADA systems, including SCADA servers and clients, HMI and engineering workstations, and historians. It does not cover native backup of PLC or RTU logic and firmware; those assets remain within the automation vendor's engineering and lifecycle-management tools. A SCADA server, HMI or historian cannot be recovered like an ordinary IT workload.

Astra Just Raised the Bar for AI-Enabled Attacks. Here's What That Means for Defenders

OpenAI published its assessment of its newest GPT model, Astra, and found it to be the first of their models to reach a critical level of cybersecurity capability, meaning that given the right tools and access, it could autonomously exploit previously unknown vulnerabilities. As a result, OpenAI has restricted Astra’s most advanced cybersecurity capabilities to trusted partners before a public rollout.

Why the best vendor relationships go beyond technology in Australia

Australian MSPs have no shortage of technology vendors. The difficult part is deciding which relationships will make the business stronger after the contract is signed. A product can perform well and still create friction if the commercial model is hard to explain, enablement is generic or support disappears when an opportunity becomes complicated. A strong vendor relationship connects technology, operations and go-to-market execution.

Introducing automatic remediation policies with Cloudflare CASB

Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies. This means security teams can now design event-driven logic to revoke risky file shares and dispatch custom webhooks, without manual intervention. When we launched Cloudflare CASB, a cloud access security broker, we wanted to provide security teams complete visibility into the posture of their SaaS applications before misconfigurations became incidents.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.” OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

A recent survey from Experian found that 60% of companies report fraud losses that are “somewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern. “Businesses identify AI-generated phishing as the most common AI-enabled fraud risk at 53%,” the report says.