incidentresponse (4)

31255892685?profile=RESIZE_180x180Cybersecurity staff at US phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide hacks by Beijing to steal customer data, and Bloomberg has now published a report on the event.   T-Mobile’s security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut off Chinese state-backed hackers’ access to its systems.[1]

The dramatic move came amid a sprawling espionage campai

31185654276?profile=RESIZE_400xOrganizations invest heavily in cybersecurity tools, firewalls, and endpoint detection systems.  Yet many still encounter serious difficulties when an actual incident occurs. Incident response requires more than a plan on paper.  It demands swift and effective execution under pressure.  Most small and medium-sized enterprises hold only a basic notion of their actions in a crisis.  Someone would contact the IT team and systems would be examined.  In practice, a real incident arises amid uncertain

31146432269?profile=RESIZE_400xA Florida man who worked as a ransomware negotiator at a US cyber incident response firm has pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group, feeding the attackers confidential information about his own clients while simultaneously negotiating on their behalf.  Angelo Martino, 41, of Land O'Lakes, Florida, admitted to providing BlackCat operators with clients' insurance policy limits and internal negotiation strategies without his employer's or clients' knowledge.  The oper

31104785690?profile=RESIZE_400xThroughout early 2026, SentinelOne’s® Digital Forensics & Incident Response (DFIR) team has responded to several incidents in which FortiGate Next-Generation Firewalls (NGFW) have been compromised to establish a foothold in the targeted environment.  Each incident was detected and stopped during the lateral movement phase of the attack.  Fortinet disclosed and issued patches for several high-severity vulnerabilities, allowing unauthorized access during our investigation period.  Successful explo