#cybersecurity

Posts mentioning hashtag #cybersecurity

Below are all the posts — topics as well as replies — that mention the hashtag #cybersecurity.

Mention #cybersecurity in your post to continue the discussion!

Palo Alto Networks Finalizes CyberArk Merger, Layoffs Expected

Palo Alto Networks completed its $25 billion merger. The deal combined two major cybersecurity firms. The merger with CyberArk closed on Wednesday. Layoffs are planned following the acquisition. CyberArk employed about 300 people in Massachusetts.

https://www.bizjournals.com/boston/news/2026/02/11/cyberark-closes-merger.html


A Thriving Circus without a Ringmaster

Working in TIAA’s cybersecurity department is akin to being part of an elaborate circus act, only without the clowns—because let’s be honest, they would probably steal the show. Our fearless leader, the CISO, appears to be playing hide and seek with responsibility. He seems to have magically abstracted himself from the daily grind while trying to hold the rest of us accountable for our hybrid work schedules. Imagine getting a lecture from a guy who’s dialing in from California while we’re sweating it out in the office. “Do as I say, not as I do,” right?

Culture is always a favorite topic, championed by the Cyber C.A.T. But spoiler alert: it’s all talk and no action. We keep waiting for substantive changes to materialize, but they remain as elusive as a good cup of coffee in the break room. The recent culture survey results? They came back to become just another tool for the CISO to deflect blame. He sees numbers that suggest managers are doing great, yet somehow, he’s convinced the managers are the root of our problems. Newsflash: the results reflect a total loss of trust in senior leadership, but he believes those at the top—the CEO and her directs—are where the issues lie. Most of us don’t care about what the CEO is doing because all we see is our CISO and his cohort stumbling through leadership.

And let’s talk about team dynamics. There’s always a lovely tension brewing between our US and India teams, pitted against each other like rival factions instead of working collaboratively. Our CISO’s pawn in India can do whatever he pleases, blissfully ignoring any input from stateside teams on the history or progress of tasks. Despite multiple reports about this ongoing issue, it’s “old no action nelly” to the rescue! The question is, is this no action or is it really built in on purpose. There are really smart people on both sides that could get everything fixed in cyber if it were one team. But hey, if neither of those work out we can always hire more contractors that have no real buy-in with the company at triple the costs….oh and not only for engineering and projects but lets also hire contractors for BAU work in operations because we all know that tying BAU to strategic dollars is a great idea, right? Speaking of operations, why do you have a deputy and an ops lead that you make an MD without a clear seat at the table. It is hard to lead from the sidelines guys, but somehow that is the story for people that actually know what they are doing in cyber.

Quarterly meetings seem to wrap up with a word cloud that supposedly sums up our thoughts on where the problems lie. It’s unintentionally hilarious that this becomes just another tool for the blame game. Newsflash again: don’t do anonymous word clouds if you don’t want to hear the truth!

And let’s not overlook the CISO's endless pursuit of patents. Why is that his priority? Especially for projects that wholeheartedly fail. Do we really think he’s there to lead, or is it all about stacking patents for his own ego, even if they go nowhere? It seems his focus is less on fostering a successful environment and more on keeping up appearances.

At the end of the day, I just hope this mounting frustration doesn’t lead to a mass exodus after bonus season. I’ve heard whispers that many good people are already on the lookout for their next opportunity, and honestly, who can blame them?

So here’s to TIAA’s cybersecurity: where leadership is absent, culture is a punchline, and accountability is clearly for the little folks. If you enjoy working under a CISO who epitomizes the phrase “lead like a mo--n,” then welcome aboard!


Just keeps on giving

All those supposedly great security and cost saving decisions by moving to the cloud without knowing what was being done or securing it made by Legg and Baich just keeps on giving... why didn't their heads roll while staff did?

https://www.malwarebytes.com/blog/news/2026/02/att-breach-data-resurfaces-with-new-risks-for-customers


RF has a new gig to keep him busy - TikTok

Now even less time for DXC. The AI bot who wrote the earnings call speech is now the DXC CEO.

TikTok USDS Joint Venture LLC Established in Compliance with U.S. Regulatory Requirements

Today, TikTok USDS Joint Venture LLC has been established in compliance with the Executive Order signed by President Trump on September 25, 2025, now enabling more than 200 million Americans and 7.5 million businesses to continue to discover, create, and thrive as part of TikTok's vibrant global community and experience. The majority American owned Joint Venture will operate under defined safeguards that protect national security through comprehensive data protections, algorithm security, content moderation, and software assurances for U.S. users.
TikTok USDS Joint Venture's mandate is to secure U.S. user data, apps and the algorithm through comprehensive data privacy and cybersecurity measures. It will safeguard the U.S. content ecosystem through robust trust and safety policies and content moderation while ensuring continuous accountability through transparency reporting and third-party certifications.
….
Data Protection: U.S. user data will be protected by USDS Joint Venture in Oracle's secure U.S. cloud environment. The Joint Venture will operate a comprehensive data privacy and cybersecurity program that is audited and certified by third party cybersecurity experts. The program will adhere to major industry standards, including the National Institute of Standards and Technology (NIST) CSF and 800-53 and ISO 27001 as well as the Cybersecurity & Infrastructure Security Agency (CISA) Security Requirements for Restricted Transactions.
Algorithm Security: The Joint Venture will retrain, test, and update the content recommendation algorithm on U.S. user data. The content recommendation algorithm will be secured in Oracle's U.S. cloud environment.
Software Assurance: The Joint Venture will secure U.S. apps through software assurance protocols, and review and validate source code on an ongoing basis, assisted by its Trusted Security Partner, Oracle.
Trust & Safety: The Joint Venture will safeguard the U.S. content ecosystem and have decision-making authority for trust and safety policies and content moderation.
Interoperability enables the Joint Venture to provide U.S. users with a global TikTok experience, ensuring U.S. creators can be discovered and businesses can operate on a global scale. TikTok global's U.S. entities will manage global product interoperability and certain commercial activities, including e-commerce, advertising, and marketing.
The Joint Venture, built on the foundation of the TikTok U.S. Data Security (USDS) organization, will operate as an independent entity governed by the following seven-member, majority-American board of directors:

Raul Fernandez – Independent Director and Chair of the Security Committee: Raul Fernandez is President and Chief Executive Officer of DXC Technology and a member of its Board of Directors. He brings more than three decades of experience at the intersection of technology, risk, and national security.

Full Press Release here: https://newsroom.tiktok.com/announcement-from-the-new-tiktok-usds-joint-venture-llc?lang=en


AI is not helping Venezuela’s security-compromised oil industry

The company’s SAP software is still down and many processes are being done manually, the people said. The company still cannot access system platforms on which accounting, payments and production data run.

https://www.bloomberg.com/news/articles/2026-01-15/venezuelan-oil-industry-is-running-on-whatsapp-after-cyberattack


AT&T expands in Charlotte, hiring 200 people for cybersecurity jobs in new office

Employees in Charlotte will focus on emerging cyber threats, designing defenses using AI and serving as part of AT&T Dynamic Defense, a network-based security service designed to detect and stop threats before they impact a business.
New office to be located approximately 1 mile from the Charlotte NRC.
And yes, RTO will be in full effect


FLD - your pursuit of revenue over quality finally caught up to you...

https://www.kiro7.com/news/local/lawsuit-claims-seattle-based-f5-overstated-cybersecurity-strength-before-revealing-major-breach/EVFK25KTSRDUXH5IXHL6JVZF3I/

I let my managers and directors know of the decline in quality for the last many years. And I was ignored.


Cyber security cleaning house

Cyber security executives have recently been firing people because they have been putting their own spin on executive orders and thus individuals have been terminated for not meeting company expected standards. Starting in quarter one management is further informed to start cutting manpower based on personal perception and end of year reviews. It's not about your job it's about popularity contest and thus as long as you make your manager and managers above them happy then you're in a good place but if you try to protect the bank or do something that is against the CISO new secure design plan they are going to terminate you without a chance to redeem yourself. Management is further encouraged to get rid of people who do not get above meets.

In short the new management chain wants nothing more than mindless monkeys to push buttons and follow scripts where pictures match the words this is why cybersecurity management is incapable of protecting its employees and throwing them underneath the bus.

Majority of the roles that cybersecurity fulfills will be replaced by AI and managers will be displaced or move to another team to fulfill another role depending on if that executive likes them or not. For managers who are not near a hub location and were promised a year and a half to two year extension to keep their job that's expected to end in quarter one and those managers are expected to be laid off or terminated.

To those individuals in the cyber security line of business good luck now that you are forced to compete like a model competes in a beauty pageant there is no reason for you to even willingly stay here now that you are degraded even more.

And for those who are not aware of cyber security is making this adjustment in quarter one because they're taking advantage of the PTO burn for the holiday season.

If you are not liked by your manager or your manager has given you biased end of year reviews in the last 2 years then your ticket is punched you are going to be gone quarter one


The new granular AWS/Azure roles are going to be a disaster

Trying to split britive permissions down to granular level based on what a random vp in cyber thinks a developer does. Fails to account for the fact we've been doing every role since frank's reign of te---r. I for one am going to feel great saying I cant do the work because cyber says it's not my responsibility


System Outage today?

What was the deal today with that firm wide system outage between 12-1:00? Comms screens, Outlook, Zoom, Surpas all went down and rumors were saying cyber attack. It was down for over 45 minutes in my area. Not one email was sent out by the powers that be to keep us in the loop of what was broken and what ETA was. Very odd and not normal. Not sure if anyone else heard anything?


“We take security very seriously.”

So here’s the story, folks. This company, a very smart company, didn’t care about security for years. Total disaster. Then bo-m! They get hacked. Suddenly, they “find” all this money for cybersecurity, like it was hiding under the CEO’s golf clubs. Now they’re bragging about their “massive investment” in security and even rolled out a shiny new “promise to customers”. Very touching, very emotional stuff. But behind the scenes? They cut the budget for training the people who actually use and develop the systems. Brilliant strategy! They say it’s about protecting customers, but everybody knows it’s just about protecting their image. “We take security very seriously,” they say. Sure they do. About as seriously as they took it the day before the breach. Sad!


Deep Specter Report: Unprecedented CISA Emergency Response

On October 15, 2025, CISA issued Emergency Directive ED 26-01 (https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices), marking an extraordinary federal response to the F5 breach. The directive's language is strikingly urgent, warning of "imminent risk to federal agencies" and scenarios "potentially leading to a catastrophic compromise of critical information systems." CISA explicitly stated that the stolen material enables threat actors to "penetrate core networks" and "decrypt a significant portion of global Internet traffic." This language reveals just how catastrophic CISA believes this breach could become. The directive mandated that federal agencies inventory ALL F5 devices and apply patches by October 22, 2025, giving them just seven days to respond. While Deep Specter claims CISA "never issued Emergency Directives for breaches before," this is technically incorrect. CISA has issued approximately 10 EDs previously, including ED 21-01 for the SolarWinds compromise. However, Deep Specter's broader point stands: Emergency Directives are extraordinarily rare and reserved for critical national security threats. The fact that CISA used such alarm-raising language and demanded such rapid action indicates they view this breach as an existential threat to federal networks.

The cybersecurity community's reaction to the F5 breach has been notably alarmed. Bruce Schneier, one of the world's most respected cryptographers and security experts, titled his analysis simply "Serious F5 Breach". This is significant because Schneier rarely sounds public alarms, and his choice to call out this incident by name signals its gravity. Robert Huber, Chief Security Officer at Tenable, called it "a five-alarm fire for national security," invoking the highest level of emergency response. CISA's Acting Director stated that "the alarming ease with which these vulnerabilities can be exploited by malicious actors demands immediate and decisive action." This language emphasizes not just the threat but the accessibility of exploitation. Perhaps most starkly, Chris Woods, a former HP security executive and founder of CyberQ Group, advised that "since that vulnerability information is out there, everyone using F5 should assume they're compromised." When experienced security professionals abandon nuance and tell customers to assume the worst, it reflects a consensus that this breach represents a fundamental breakdown in security that cannot be easily remediated.

https://www.reddit.com/r/f5networks/comments/1okn55c/factchecking_the_deep_specter_report_on_f5/?rdt=45343


breached

The actor dwell time inside their network is being quoted as 393 days. Let that sink in. Then consider this is being attributed to APT27 (China). I’m working from a position that they have everything (EVERYTHING) and are potentially still inside the network.


ushq-teamlist cybersecurity email

If you were one of the people that did download the list, I received an email from Cybersecurity letting me know I broke policy by accessing sensitive information. They only asked to respond back to confirm any copies have been deleted, and if you distributed the list, to let them know where you shared it. My director was CCd on the email, but they didn’t think it was a big deal and moved on. There will only be action taken if you don’t respond to the email.


tech, digital & cyber

so far so good today. but... are we just left for latter and will there be a massive cut within these groups as well? i kind of have a feeling that we have been sloted for a later cut but i am basing this only on my personal gut feeling and i do not have any insder information. i was talking to one director level person and she thinks that we'll be fine but i am unsure if i should trust this. i am not too concerned but given how crazy all of this i'd say anything is possible.


Ex-L3Harris executive accused of selling trade secrets to Russia

The Department of Justice filed charges against Peter Williams, an Australian national who served as general manager of Trenchant, a specialized cybersecurity division within L3Harris.

Federal prosecutors have accused a former executive at L3Harris Technologies’ cyber division of stealing trade secrets and selling them to an undisclosed buyer in Russia, according to court documents obtained by CyberScoop.

The Department of Justice filed charges against Peter Williams, an Australian national who served as general manager of Trenchant, a specialized cybersecurity division within L3Harris, which provides hacking and surveillance tools to Western intelligence agencies. The DOJ alleges Williams misappropriated eight trade secrets from two unnamed companies between April 2022 and August 2025, charging that he earned $1.3 million in connection with the sales.

While the filings do not specify the nature of the stolen trade secrets nor do they identify the Russian buyer, they allege Williams systematically transferred confidential proprietary data over a period spanning more than three years. Prosecutors are seeking the forfeiture of Williams’ assets, including his residence, luxury watches, jewelry, and funds in seven bank and cryptocurrency accounts, claiming these were derived from the criminal activity.

Neither Trenchant nor its parent, L3Harris, is accused of any wrongdoing in the federal complaint. An arraignment and possible plea agreement are scheduled for Oct. 29 in Washington, D.C.

Trenchant, formed in 2018 following L3Harris’s acquisition of Azimuth Security and Linchpin Labs — Australian startups that developed zero-day exploits — caters to governments in the intelligence-sharing Five Eyes alliance. These technologies, based on undisclosed vulnerabilities, are considered valuable assets in intelligence and defense circles, sometimes commanding prices in the millions, and are tightly held given their national security implications.

The allegations against Williams arrive in the wake of an internal investigation at Trenchant earlier this year, reportedly prompted by a leak of hacking tools. According to multiple former employees interviewed by TechCrunch, one former exploit developer was wrongly accused by company officials of leaking the tools, particularly exploits targeting products like Google Chrome.

Whether the Justice Department’s action is tied directly to this internal leak investigation remains unclear. Court filings do not explicitly connect the sale of secrets to the incident or elaborate on overlaps between the two events.

L3Harris, headquartered in Melbourne, Fla., declined to comment. Williams’ attorney did not reply to CyberScoop requests for comment.

https://cyberscoop.com/ex-l3harris-executive-accused-of-selling-trade-secrets-to-russia/


Dell ranked high for CyberSecurity, WHAT JOKE

Maybe Newsweek should look at that a little closer. How do you get ranked a high CS company when their internal security is complete garbage, they have customer apps that have clear passwords stored and can easily be bypassed, nothing is written to follow standards, best practice as far as design or security and you have Directors mandating their staff NOT use corporate approved communication applications, that are by the way Chinese based. Would be one of the LAST companies Id pin "one of the best" on.


Another day, another Oracle breach. So many cloudy days at O

Dozens of Oracle customers impacted by Clop data theft for extortion campaign: Researchers said malicious activity dates back to early July and active exploitation was observed two months ago.

Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday.


Humana using Providence Company for “secure” Data Exchange

I can only imagine how many people will experience identity theft as a result of this.

“ LOUISVILLE, Ky.--(BUSINESS WIRE)-- Humana Inc. (NYSE: HUM) and Providence, a Washington-based health system, today announced a pioneering initiative to streamline and secure data exchange between payers and providers – setting a new standard for interoperability in support of value-based care.”

I bet in coming days, we will hear about lawsuits where major data breaches occurred as a result to this. Mark your calendars.


Hackers went for the Jackpot

Not sure what defines highly sophisticated hacker or not but clearly they went for the Jackpot Bingo. Application Delivery Controller or ADC is a single point of exposure of all traffic that goes through F5 that would be a magnet for hackers. It breaks all norms of security by concentrating in the same venue all the secret keys for every service that is on-boarded to the ADC. It is a matter of time until someone gets its hands on it. Otherwise no hacker would bother to go to break F5 if the traffic that goes through it is end to end encrypted. It was unwise and d-mb idea from the begining and only to support security of lax architecture in the back end. Now those all that were calling that is the only secure way to go about it are reaping their fruits. It was not at all driven from security point of view but more about sales, project check mark and also about sniffing transfers in the internal network for data loss prevention or DLP. Well those who pushed it all are not anymore around to be asked about it. Next all the secret vaults and smillar things.

https://forums.theregister.com/forum/all/2025/10/15/highly_sophisticated_government_hackers_breached/


so how did we get hacked?

Cyber: F5 experienced the same breach in March 2021. In Nov 2021 they announced they’re doubling their India staff which is now 20% of their headcount.

The WFH engineering is entirely in India. Only pre-sales and service engineers in US. None of these cyber SME’s will investigate India or the Beijing operations but I bet they’ll find a previously unknown vulnerability.

BTW India outlaws VPNs and these dudes WFH on Huawei networks. What happens to encrypted data traveling through China where encryption is illegal? Good question - cryptologists don’t seem to know. Bet they had anonymous security groups and no one checked logs so they didn’t even know. 95% of breaches involve insiders - negligence or intentional theft. I call it the offshore 401K.