Member Spotlight: Bidemi Ologunde

Bidemi (Bid) Ologunde is an intel analyst at Expedia Group. We were able to talk with Bid about topics ranging from his own podcast and background to the future of cybersecurity. His opinions expressed are his personal opinions and do not reflect the views of Expedia Group. You are no stranger to podcasts as you…

Read More

RH-ISAC Announces Synack as Title Sponsor for Cyber Intelligence Summit

Vienna, VA (June 22, 2023) – The Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) today announced that Synack will be the title sponsor of the RH-ISAC Cyber Intelligence Summit, which takes place October 2-4 in Dallas, TX. The RH-ISAC Cyber Intelligence Summit is an annual event tailored for strategic leaders and cybersecurity practitioners from…

Read More

Account Takeover Proof of Concept for 0Auth Security Flaw in Microsoft Azure Active Directory

Before publishing, Descope informed Microsoft, several “large vulnerable applications,” and two authentication platform providers of the issue and Microsoft has reportedly taken mitigating steps. Context On June 20, 2023, researchers at Descope reported the technical details of a security flaw in the Microsoft Azure Active Directory (AD) Open Authorization (OAuth) process they dubbed “n0Auth.” According…

Read More

Industry Insights Report Reveals Top Cyber Threats in the Retail & Hospitality Sector

Vienna, VA (June 15, 2023) – The Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) today released the 2023 Retail & Hospitality Industry Insights Report, which analyzes cybersecurity trends in the consumer-facing sector. The report compares key takeaways from the Verizon Data Breach Investigation Report (DBIR) with RH-ISAC member data to provide additional context that…

Read More

New “Skuld” Infostealer Malware Written in Golang Leveraged in North America, Europe, and Southeast Asia

On June 13, 2023, security researchers at Trellix reported the details of a new information stealing malware written in Golang that they dubbed “Skuld.” Context Since April 2023, Trellix researchers observed the malware active against unspecified targets in North America, Europe, and Southeast Asia. Technical Details According to the report, Skuld attempts to steal sensitive…

Read More