home.social

#dbir — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dbir, aggregated by home.social.

fetched live
  1. By the numbers: 3 stats from Verizon’s DBIR reveal a patching problem. AI is being leveraged to accelerate time to exploit known vulnerabilitiesshrinking window of defense from months to mere hours. itbrew.com/stories/by-the-numb #cybersecurity #Verizon #DBIR #TooMany #vulnerabilities

  2. Happy Verizon DBIR day to all who celebrate!

    #DBIR

  3. as is tradition, I just published my commentary on this year's Verizon Data Breach Investigations Report (aka #DBIR): kellyshortridge.com/blog/posts

    In the post, I include the following sections covering what I felt were the most notable insights and facets in the report:

    🌍 So, what?

    💃 Espionage: fast fashion or couture?

    👻 APTs go BWAA-haha >:3

    💸 How do the money crimes generate money?

    🤖 Attackers are still not really using GenAI

    👩‍🍳 If you can’t make your own 0day, store-bought creds are fine

    🔓 #Security was the real supply chain threat all along

    🍄 Things Rot Apart

    🕵‍ Scooby Doo's Spooky Kooky Corporate IT Caper

    🌈 At least some things are improving somewhere

    Go forth and enjoy my commentary, and then make sure to find me at #RSAC to tell me what you loved or hated Tuesday 14:30 at the @fastlydevs booth (where you'll also get a free copy of my book ✨)

    thanks @alexcpsec for the early copy <3

  4. If you think your government is above doing some black hat shit for money, odds are you're wrong.

    If you think that 72% of state sponsored incidents without a known financial motive means 72% of *states* not going for the money, I'll remind you that the CIA got caught selling crack cocaine in American cities in order to fund "black ops."

  5. In this year’s DBIR, vulnerabilities in Virtual Private Networks (VPNs) and edge devices were particular areas of concern, accounting for 22% of the CVE-related breaches in this year’s report, almost eight times the amount of 3% found in the 2024 report.

    tenable.com/209928

    #dbir #vulnerabilities #vpn #patching #infosec

  6. DomainTools is proud to be a Contributing Organization for this year’s Verizon Business Data Breach Investigations Report.

    A special thank you to the DBIR team, C. David Hylender, Philippe Langlois, Alex Pinto, and Suzanne Widup!

    Here’s a tl;dr of our takeaways from an Internet intelligence perspective:

    🔹30% of all analyzed breaches featured third-party involvement, double the amount from past year
    🔹Human involvement (i.e., clicking on a phishing email or visiting a malicious website) appeared in 60% of breaches
    🔹20% of breaches involved the exploitation of vulnerabilities, up 34% from the 2024 report
    🔹Ransomware was present in 44% of all breaches
    🔹The use of synthetically-generated text in malicious emails has doubled over the past two years

    Curious to find out how all of these threats involve DNS? Check out our blog summary here: domaintools.com/resources/blog

    #DBIR

  7. Reading through the Verizon #DBIR. The report is great and all, but the footnotes is where it's at 🙂
    #CyberSecurity

  8. Tara Seals also gives an excellent overview of the Verizon report and she concludes, correctly, that we suck at writing software.

    darkreading.com/cyberattacks-d

    #security #dbir

  9. The Industry: "We need to spend our security budget on anti-malware and supply chain security!"

    #DBIR: "You're getting popped by two kids in a trenchcoat doing credential stuffing because you don't have human factor security."

    buff.ly/3JJwZF9

  10. "There is a lot of focus on how fully automated attacks can ruin an organization’s day, 6 but it is often surprising how much the people inside the company can have a positive effect on security outcomes."

    A statement from this year's #DBIR that is part of our manifesto at Crowdalert.

    (The rest of the report is worth a read: buff.ly/3JJwZF9)

  11. Almost 60% of breaches involve credential misuse or phishing, according to this year's #DBIR. Your auth provider can't be your only solution, you need human-in-the-loop monitoring.

    buff.ly/3JJwZF9

  12. 68% of breaches described in this year's #DBIR involved a human element. You ignore the human side of security at your peril.

    Hint: the answer isn't to talk to your team _less_.

  13. The 2024 Verizon #DBIR is out and it's the Year of the Vuln, as exploit attempts surge + orgs struggle to patch in time. Check out our analysis on the evolving landscape + how GreyNoise helps ID targeted attacks faster + buys remediation time. 🦾 buff.ly/3JJK6WR

  14. Verizon said they saw a 180% increase in the exploitation of vulnerabilities as an initial access method in data breaches #DBIR

  15. We've been pouring over Verizon's new #DBIR, and expect more from us in the coming days on that, but a great place to start is seeing how @shortridge is making sense of it.

    kellyshortridge.com/blog/posts

  16. The 2024 Verizon Data Breach Investigations Report (#DBIR) is out this morning, and I make sense of it in my new post: kellyshortridge.com/blog/posts

    I focused on what felt like the most notable points, from #ransomware to MOVEit to web app pwnage to #GenAI and more.

    I have insights, quibbles, and hot takes as always — but the fact remains it’s our best source of empirical data on cyberattack impacts. If you’re a #cybersecurity vendor, please consider contributing data to it.

  17. Verizon's Data Breach Investigations Report covers a lot of sectors of society, including #education. This year's #DBIR reports that 98% of breaches and #cybercrime affecting schools was financially motivated.

    What was that famous thing a bank robber once said about going where the money is? Is someone going to tell them?

    verizon.com/business/resources