It's a hot topic, the old "pay or don't pay" for hackers not to leak your data. Since recording this a few days ago, we've had Grafana go with the "no pay" approach, and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom". I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which really waters down the severity of the whole thing. It looks like, for the time being, "pay or leak" is the new norm... along with nonsensical statements like "the data was returned to us" 🤷♂️
Weekly update- Homepage
- International
- Weekly Update 504
Related
Exposed Fuel Tank Gauges Under Attack in the US
8 hours ago
5
Adaptive, Agentic AI Worms Loom as Next Enterprise Threat
12 hours ago
9
Trump AI Order Seeks Voluntary Frontier Model Testing
14 hours ago
9
Rust-Written IronWorm Hits NPM Supply Chain
1 day ago
16
China's TA4922 Expands Cybercrime Attacks Globally
1 day ago
13








.png)

