CrowdStrike secures ISO 42001 AI governance standard
As AI-driven attacks accelerate, weak governance around defensive AI introduces operational, compliance, and trust risks. CrowdStrike’s ISO/IEC 42001 certification validates that its AI capabilities are developed and managed under recognized governance and risk controls. With security teams increasingly relying on AI for detection and response, transparency and accountability in how these systems operate are becoming critical. Vendor certification adds assurance, but it should complement an organization’s broader risk framework. If you are interested to learn more about CrowdStrike and how it fits into a modern security strategy, reach out to us for a no-obligation discussion with our data security experts.
(Source: IT Brief)
|
|
Hackers Disable Windows Security With New Malware Attack
Recent malware campaigns show attackers deliberately disabling Windows security protections before deploying additional payloads. By abusing legitimate system features and user trust, threat actors can neutralize built-in defenses and operate undetected. This technique highlights the limitations of relying solely on default endpoint protections and user awareness. Organizations should reassess how endpoints are monitored when core security controls are tampered with and how quickly compromised systems can be isolated and recovered. Reviewing endpoint visibility and response readiness now can reduce exposure to similar attacks.
(Source: TechRepublic)
|
|
Fortinet Warns of Active FortiCloud SSO Bypass Attacks
Active exploitation of a FortiCloud single sign-on bypass vulnerability is allowing attackers to gain unauthorized administrative access, even on updated systems. When identity and authentication mechanisms are compromised, attackers can move laterally without deploying malware or triggering traditional alerts. This raises concerns about overreliance on centralized access services without layered verification and monitoring. Organizations should review privileged access paths, identity logging, and anomaly detection. Evaluating identity security controls today can help limit the impact of authentication-based attacks.
(Source: Security Affairs)
|
|
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
CISA has confirmed real-world exploitation of a critical VMware vCenter Server vulnerability, adding it to the Known Exploited Vulnerabilities catalog. Because vCenter often controls core virtualization infrastructure, a successful compromise can expose workloads, credentials, and recovery systems. Delayed patching or weak segmentation can significantly increase the blast radius. Organizations running virtual environments should validate patch status, restrict management access, and test recovery procedures. A focused review of virtualization security can prevent a single flaw from escalating into a broader outage.
(Source: Hackers News)
|
|
New Microsoft Office zero-day under active attack, patch now
Microsoft has released emergency patches for a zero-day vulnerability in Office that is being actively exploited through malicious documents. Given how deeply Office is embedded in daily business operations, even one successful phishing attempt can enable broader network compromise. Rapid patching is essential, but it should be paired with strong email filtering, endpoint monitoring, and tested recovery paths. Organizations should confirm updates are deployed and reassess how document-based threats are detected and contained.
(Source: Cyber News)
|
|
Ingram Micro Ransomware Attack Exposes Employee Data
Ingram Micro disclosed that a ransomware attack resulted in the theft of sensitive employee data affecting more than 42,000 individuals. The incident highlights how large organizations remain attractive targets due to the volume of data they manage and their position within global supply chains. Ransomware operators increasingly combine data theft with extortion to increase pressure on victims. Organizations should review data protection practices, third-party risk exposure, and incident response readiness. Strengthening preparedness now can reduce the impact of future ransomware incidents.
(Source: The Register)
|
|
|
|
|
| Backup and Cybersecurity Solutions Offered by Pantropic |
|
 |
|
ATEGO® ENTERPRISE
This “white glove” managed service is the next generation secure offsite backup you need right now. We monitor your backups daily, help you troubleshoot any problems, and can assist you with restorations when you need it. Our Data Security Module can perform bi-directional anti-malware scans, content disarm and reconstruction (CDR), and protect your backups with biometric Deep MFA and multi-person workflow, crucial in stopping stolen credential attacks.
|
 |
CROWDSTRIKE FALCON
A next-generation endpoint protection platform using AI and machine learning to effectively stop breaches, featuring true NGAV, powerful endpoint detection and response (EDR), threat intelligence management, and built-in automation. It delivers real-time visibility, rapid threat hunting, lightweight cloud-native performance, and seamless scalability to secure complex environments with speed and confidence. |
|
 |
|
Leading desktop and laptop backup solution providing automated and continuous data backup protection with unlimited capacity backup licensing and flexible deployment options.
|
 |
| World’s largest security awareness training platform with simulated phishing attacks, educating and empowering employees to strengthen IT security against cybercriminals. |
|
|
|