Back To Resource Center

Published: June 23, 2023

Security 3-2-1 Week of 6/23/23

By Annie articles

3 Interesting Articles

MOVEit Transfer and MOVEit Cloud Vulnerability
Multiple Sources: A critical vulnerability in Progress Software’s MoveIt Transfer is under exploitation and dozens of federal and state agencies and private companies have been impacted. Progress Software disclosed three security vulnerabilities in MOVEit Transfer software. The latest, CVE-2023-35708, is an SQL injection vulnerability potentially allowing unauthorized access to the database. Victims include Avast and Norton’s parent company, Gen Digital, and others as the Cl0p ransomware gang exploits these vulnerabilities. The company fixed the issue and urged customers to update their installations.

5 Ways Generative AI Will Help Bring Greater Precision to Cybersecurity
VentureBeat: Generative AI is being integrated into cybersecurity strategies due to its focus on data accuracy, real-time insights, and precision. Companies like Airgap Networks, CrowdStrike, and Cisco have already incorporated generative AI into their products and there are lots of ways companies are looking to use this technology: risk assessments, XDR, endpoint resilience, patch management, managing AI tools and models. The demand for generative AI-based cybersecurity solutions is predicted to grow by 22% annually from 2022 to 2023, reaching a market value of $11.2 billion in 2032​. Check out the article for a list of cybersecurity vendors that have announced generative AI products and services.

Cybersecurity Outpaces Wider Tech Market With 12.5% Growth in Challenging Economy
Canalys: In Q1 2023, the global cybersecurity market grew 12.5% YoY. Palo Alto Networks, Fortinet, CrowdStrike, Okta, and Microsoft experienced significant growth, whereas Cisco lost some ground. Identity security remained a high priority, as well as securing hybrid workers. Cybersecurity spending favored urgent projects and those yielding high returns. The fastest growth was among larger clients. Despite macroeconomic challenges and tighter IT budgets, enhancing cyber-resiliency remains a priority for most organizations. North America led in terms of market size, followed by EMEA, Asia Pacific, and LATAM.

2 Stats You Should Know

MOVEit has more than 1,700 software companies and 3.5 million users worldwide relying on its services. (source)

Manufacturing was the most targeted sector for ransomware cyber-attacks and the most extorted industry in 2022. (source)

1 More Thing

As Winston Churchill famously said, “Never let a good crisis go to waste.” Advocating for and getting the budget you need can be an uphill battle. The MOVEit hack is an opportunity to ask for the resources you need with a front-and-center example as to why security investments matter.

Our large and diverse network of experts is here to help...

Charles M.

Principal

Charlies is a 14 year cyber security expert. He started his career in the U.S. armed forces and then transitioned into commercial roles. A security engineer by training, he's well-versed in tool deployment and administration.

Ellen K.

GRC Expert

Ellen bring a decade of GRC expertise to the TalPoint community. She's knowledgeable on a variety of frameworks and employs a methodical approach to compliance. She's available for needs assessments, gap assessments, internal audits, and for certain frameworks running independent 3rd party audits.

Zachary C.

Founder and CRO

Zachary bring a 20+ year career in risk management to the TalPoint community. He's worked across healthcare, finance, and supply chain manufacturing. His broad experience offers both a holistic view of risk as well as a common sense approach to risk management.