Archive

Snail Mail Fail: Fake Ransom Note Campaign Preys on Fear

March 4, 2025 In early March 2025, GRIT received reports from multiple organizations regarding suspicious physical letters delivered by mail from US addresses to members of their executive team.

Proactive Security: Navigating HIPAA’s Proposed Risk Analysis Updates

March 4, 2025 NOTE:  This article discusses proposed changes to existing regulations.

Untangling AWS Networks with Cloud WAN

February 25, 2025 As organizations grow so does their infrastructure, often without a well-designed underlying infrastructure to support this growth.

GRIT’s 2025 Report: Ransomware Group Dynamics and Case Studies

February 18, 2025 Ransomware threats continue evolving, with the most successful groups refining their tactics to maximize impact over the last year.

GRIT’s 2025 Report: Annual Vulnerability Analysis and Exploitation Trends

February 4, 2025 2024 saw an unprecedented surge in vulnerability disclosures, with over 39,000 vulnerabilities published.

Ongoing report: Babuk2 (Babuk-Bjorka)

January 29, 2025 Editor’s note: We will continue to provide updates as further information is forthcoming.

GRIT’s 2025 Report: Post-Compromise Detection Strategies

January 28, 2025 This blog marks the beginning of a series based on the findings in the GRIT 2025 Ransomware and Cyber Threat Report.

OT/ICS Security: Beyond the Easy Button

January 23, 2025 In the world of Operational Technology (OT) and Industrial Control Systems (ICS), security cannot rely on a “set it and forget it” mindset or an over-reliance on the lates…

Unveiling the GRIT 2025 Ransomware and Cyber Threat Report

January 16, 2025 The ransomware landscape is shifting, and understanding these changes is critical to staying ahead.

RansomHub Affiliate leverages Python-based backdoor

January 15, 2025 In an incident response in Q4 of 2024, GuidePoint Security identified evidence of a threat actor utilizing a Python-based backdoor to maintain access to compromised endpoints.

Considerations for a Balanced Critical Infrastructure Security Strategy

January 7, 2025 With the Presidential administration changeover happening soon, there has been much discussion of potential regulatory rollback, restructuring, or elimination of agencies like the Cybe…

Understanding and Taking Advantage of the NYDFS Risk Assessment Requirement

December 11, 2024 As organizations prepare for the coming year those affected by NYDFS may struggle to efficiently include the requirements in their plans.