January 2025 News & Tips | Krispy Kreme, Cybersecurity & Politics

January 2025 News & Tips | Krispy Kreme, Cybersecurity & Politics
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! Wow… January has been one of those months in cybersecurity where there is so much to cover that it can’t all fit in one newsletter. The most important and interesting news stories are below. From doughnut ransomware to pardoning the founder of Silk Road, let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.

Krispy Kreme’s cybersecurity had a few holes

It’s not often that a cybersecurity incident makes its way to the Saturday Night Live satire news desk, but this one did (don’t watch the video at work – lots of NSFW jokes). The famous Krispy Kreme doughnut shop suffered a cyberattack bad enough that there were reports of closed stores, cash-only sales, and their on-line ordering system going offline. Exact details of what happened have been sparse, but their mandatory SEC filing states that “the Company is experiencing certain operational disruptions, including with online ordering in parts of the United States” and “the incident has had and is reasonably likely to have a material impact on the Company’s business operations.” The Play ransomware group took responsibility for the attack. That particular group has been active since 2022, and their other victims include Rackspace and the City of Antwerp, Belgium. They often gain their initial foothold by exploiting known vulnerabilities in Internet-facing systems where patches are available but have not been installed..

Takeaway: Ransomware is a preventable crime. Patching devices, especially those that are Internet-facing, is extremely important. More details on how to prevent ransomware attacks are available here.


When cybersecurity and politics collide


There isn’t an easy way to talk about politics without offending half (or more) of the population, but avoiding talking about politics and its direct impact on cybersecurity is dangerous in my opinion. So, we’re going to talk about it.

Collision #1: On January 16th, the previous USA administration issued an executive order on cybersecurity, requiring things such as secure software development practices, phishing-resistant authentication technologies, encryption that can withstand cracking from quantum computing, AI engines that need to go through safety checks before being released to the public, and so on. Some of these requirements are similar to those in the Defense Production Act of 1950. The new administration has revoked the cybersecurity executive order, so that is the end of that. To be honest, the order probably wasn’t going to do much good anyway, as things like laws or executive orders do not change behavior. Three things are required to change behavior: laws, enforcement of those laws, and sufficient penalties for breaking those laws. Without all three, not much is going to get done.

Collision #2: CISA stands for the Cybersecurity and Information Security Agency, which is a US government agency that, among other things, acts as an interface between the public sector and private sector for matters related to cybersecurity. I have had a number of times when information from CISA has been instrumental in determining likely attack vectors of cybercriminals while my team is actively engaged in recovering from a cyberattack. One of the advisory committees under CISA was the CSRB, or Cyber Safety Review Board. The CSRB did not have any legislative ability, but the investigated breaches such as Log4Shell and the Microsoft O365 email hack, and gave recommendations on how to prevent future similar incidents from occurring. As of January 20th, the CSRB is no more, and the entire future of CISA is in question. While CISA does a lot of “Ivory Tower” work with guidelines, frameworks, recommendations, etc. that often don’t translate well into the real world, they also maintain a list of known vulnerabilities that are being actively exploited. They even break down the list to call out vulnerabilities that are being exploited by ransomware gangs, which is extremely useful information to have. I hope that aspect of CISA continues to exist into the future.

In other new-administration news, the founder of the infamous website Silk Road, Ross Ulbricht, was recently pardoned after serving over 11 years in prison. Silk Road was a website that was often used for illegal purchases of things like weapons, drugs, and even alleged murder-for-hire schemes. There was already a significant movement to release him under the grounds that operating a website is an expression of free speech, and even if it isn’t, his sentence (two life sentences + 40 years without parole) was unreasonably long. 


Takeaway: It’s going to be a significant period of transition over the next several months, and the thought that there are going to be new rules that make it in a large company’s best interest to make cybersecurity products is very slim. Thankfully, there are many things we can do as individuals to protect ourselves from cybercrime.
 

Until next month, stay safe!

Upcoming Speaking Events

Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!


March 25-31, Oklahoma City, OK

April 1-4, New Orleans, NV

April 15-18, Las Vegas, NV

May 14-15, Des Moines, IA

May 26-30, Las Vegas, NV

June 3-6, Victoria, BC, Canada

July 3, Brainerd, MN

July 9-21, Dublin, Ireland

July 22-24, Orlando, FL

August 24-27, Indianapolis, IN

October 13-17, Waikiki, HI

November 10-12, Austin, TX


 

Interesting Articles

"This 'vicious and scary' scam involves sending an email that includes details of the victim’s home address. The so-called “We know where you live” attack. There are multiple versions doing the rounds, often including photography of your home. 'They generally either include threats of physical harm or threats of releasing damaging personal material they say they acquired through a hack,' Wen said."
AI based fraud is really starting to take off. A 900% increase YOY is quite dramatic.
Wow. Just, just wow. 100 million people's healthcare data stolen because of a lack of MFA. "New details about the hack emerged in the state’s complaint, including that the ALPHV hackers initially broke in using the stolen username and password of a 'low-level customer support employee,' which wasn’t protected with multi-factor authentication."
 
Remember the Mirai botnet from 2016? It hasn't gone away, and it has morphed to use more than security cameras. Be careful what you hook directly to the Internet!
Cybersecurity Tip of the Month

Passkeys
                                                            
Passwords are one of the biggest weak points in cybersecurity—often reused, stolen in data breaches, or compromised through phishing. Another way to protect your accounts is by using passkeys.

Passkeys are a password-free authentication method that uses cryptographic keys stored on your device. Instead of typing a password, you sign in using your fingerprint, Face ID, or a PIN. This makes passkeys phishing-resistanteasier to use, and far more secure than traditional passwords.

Many major companies, including Google, Apple, and Microsoft, now support passkeys. Setting them up is simple:

  1. Check if your email, banking, or cloud service supports passkeys.
  2. Enable passkeys in the account’s security settings.
  3. Use your device’s biometric authentication or PIN to log in securely.

Because passkeys can’t be stolen in data breaches, they significantly reduce hacking risks. They also make logging in faster, eliminating the need to remember complex passwords.

For even more security, store your passkeys in a trusted password manager that syncs across your devices.

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: