Posts

Week 5

https://www.csoonline.com/article/3663688/congressional-hearings-focus-on-ai-machine-learning-challenges-in-cybersecurity.html Using artificial intelligence as a defense in cybersecurity could potentially be much more effective than traditional security methods, but is it reliable? In its current state, AI is expensive to train, is easily interfered with during the training process, and the training data may or may not be trustworthy. With enough work, AI defense could become much better. Microsoft's chief science officer recommended doubling down on efforts toward AI defense, but the lack of cybersecurity personnel is a problem.

Week 4

 https://www.csoonline.com/article/3238080/5-top-vulnerability-management-tools-and-how-they-help-prioritize-threats.html As we learn about using tools to help scan for security vulnerabilities, I thought it would be relevant to share some more tools that could be used to help with this. As I am new to cybersecurity, I am unsure of what the best way is to manage multiple security tools, but I imagine using a combination of them would lead to a more secure cyberspace. From reading this, I have learned that there is a huge variety of security software. Some take advantage of the cloud, some use artificial intelligence, and more.

Week 3

https://thehackernews.com/2022/05/how-secrets-lurking-in-source-code-lead.html An increasing threat to cybersecurity is software secrets being leaked to places like GitHub. By secrets, I do not mean secrets in the traditional sense, although they are secret, in this case, a secret is a key for software engineering teams to use in order to access source code. Secrets are similar to passwords, however, they are meant to be shared among a team. Sharing passwords can be convenient for a team, but it opens up security risks for these secrets to be leaked and accessed by hackers.  In the process of software development, previous versions of the software are saved in case a new version introduces bugs. Sometimes previous versions are saved for years. Often what gets leaked is the keys to the older versions of the software which still resembles much of the current day software, leading to open access to the source code. Knowledge of the source code can give hackers what they need to access...

Week 2

Source:  https://www.csoonline.com/article/3661633/chaos-ransomware-explained-a-rapidly-evolving-threat.html Chaos ransomware is a current and growing threat to cybersecurity. Victims of this threat have been U.S. emergency services, medical facilities, and other industries. What makes chaos ransomware different from normal ransomware, is that it is widely available and threat organization members can create their own strands from the base ransomware which makes it hard for cybersecurity organization members to build a defense against it.

Week 1

CSOonline provides a way for the public to access up-to-date news articles regarding cybersecurity to keep up with current threats. This website seems to be a good resource for finding articles because of its credibility and quantity of articles. They also host virtual live events to go more in-depth on certain topics which can include a range of IT topics.