Welcome
Welcome
Hello and Welcome!
Be sure to attend our monthly meetings. Lots of good information there. Register for our Thursday March 26th Virtual Meeting on our site ISC2CT.org
Also come Join our (ISC)2 Connecticut Chapter Discord Server
Upcoming events:
SANS OSINT Summit & Training 2026 | Monday March 16th, 2026 | Live Online Summit Free to Attend 6 CPEs The Open-Source Intelligence (OSINT) Summit is the premier event for cybersecurity professionals, investigators, threat analysts, and open-source researchers who are shaping the future of intelligence gathering in an increasingly complex digital world. This Summit delivers cutting-edge insights and practical techniques from top experts who leverage OSINT to drive real-world impact from uncovering cyber threats to assessing geopolitical risk. Agenda & Registration
SANS Cybersecurity Leadership Summit | Tuesday March 17th, 2026 | Live Online Summit Free to Attend 6 CPEs In a rapidly evolving threat landscape, leaders can’t just keep up - they must set the standard. The SANS Cybersecurity Leadership Summit is for industry leading CISOs, directors and managers looking to empower themselves with the knowledge and tools to not just participate, but to set the pace in cybersecurity leadership. This Summit provides invaluable insights from industry leaders who will share their strategies, lessons learned, and best advice. Agenda & Registration
ISC2 Global 50x50 Women’s Summit | Wednesday March 18th, 2026 | Virtual Free to Attend 3.5 CPEs Join us for this year’s Global 50x50 Women’s Summit which will bring together women and allies from every corner of the cyber ecosystem to explore how inclusive leadership, intentional sponsorship, and meaningful mentorship open doors to opportunity and reshape the talent pipeline. Through bold dialogue, practical skill-building, and cross-border connect, participants will examine how to expand belonging and unlock the full potential of women professionals at every career stage. Agenda and Registration
Upcoming Training:
NII ISO/IEC 42001:2023 Lead Auditor – with Global Certification by Exemplar Global, USA + 21 hours of CPE Credits| March 16 – 18, 2026 1:00 PM (GMT) onwards 7 hours for 3 days (21 hours of online training) Pricing: USD 799 regular participant Early Bird USD 575 registering by 1st March 2026 ISO/IEC 42001 is an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations. It is designed for entities providing or utilizing AI-based products or services, ensuring responsible development and use of AI systems. Registration
NII Certified Information Systems Security Professional CISSP | March 23-26, 2026 1:00 PM (GMT) onwards 7 hours for 4 days 28 CPEs Pricing: USD 799 regular participant Early Bird USD 639 registering by 1st March 2026. The Certified Information Systems Security Professional (CISSP) is a premier, globally recognized cybersecurity certification from ISC2, designed for experienced security practitioners, managers, and executives. It validates expertise in designing, implementing, and managing comprehensive security programs across eight key domains Registration
Thank you to our Sponsors
Quinnipiac University is committed to helping advance the field of cybersecurity through its School of Computing & Engineering. To support the growth of professionals within cybersecurity and computing, Quinnipiac offers flexible online and on-campus opportunities that deliver practical skills you can immediately apply on the job. Both its MS in Cybersecurity and MS in Computer Science programs feature hands-on experience in lab settings that simulate real-world scenarios. To learn more about these exciting opportunities, Visit Quinnipiac University
Cyber News
Webinar: Power up your ISC2 exam prep
Ready to get certified but not sure where to start? Get insider tips and tricks on what to do from day one to test day. Join ISC2-certified instructors and an audience of your peers for this live interactive webinar. Find out what to do in the months, weeks, days and hours leading up to your exam.
Making frontier cybersecurity capabilities available to defenders
Claude Code Security is one step towards our goal of more secure codebases and a higher security baseline across the industry.
Four Risks Boards Cannot Treat as Background Noise
Board’s must ensure business continuity and resilience in the face of emerging risks generated by AI usage and attack vectors, quantum computing and geopolitics.
Those 'Summarize With AI' Buttons May Be Lying to You
Microsoft uncovered AI recommendation poisoning in 31 companies across 14 industries, and turnkey tools make it trivially easy to pull off.
Identity Cyber Scores: The New Metric Shaping Cyber Insurance in 2026
Insurers tighten cyber underwriting as identity risks grow; breach costs hit $4.4M and MFA gaps affect payouts.
Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119)
Microsoft has disclosed a critical privilege-escalation vulnerability in Windows Admin Center (CVE-2026-26119) patched in December 2025.
OpenClaw's Gregarious Insecurities Make Safe Usage Difficult
Malicious "skills" and persnickety configuration settings are just some of the issues that security researchers have found when installing — and removing — the OpenClaw AI assistant.
Windows 11 Notepad flaw let files execute silently via Markdown links
Microsoft has fixed a "remote code execution" vulnerability in Windows 11 Notepad that allowed attackers to execute local or remote programs by tricking users into clicking specially crafted Markdown links, without displaying any Windows security warnings.
Claude didn't just plan an attack on Mexico's government. It executed one for a month — across four domains your security stack can't see.
Attackers jailbroke Anthropic’s Claude and ran it against multiple Mexican government agencies for approximately a month. They stole 150 GB of data from Mexico’s federal tax authority, the national electoral institute, four state governments, Mexico City’s civil registry, and Monterrey’s water utility
Why AI Keeps Falling for Prompt Injection Attacks
We can learn lessons about AI security at the drive-through
AI Coding Assistants Secretly Copying All Code to China
Two popular AI coding extensions with 1.5M installs secretly harvest your entire codebase and profile you. Both are still live in the marketplace.
Self-driving cars, drones hijacked by custom road signs
AI vision systems can be very literal readers
Attackers Use New Tool to Scan for React2Shell Exposure
Researchers say threat actors wielded the sophisticated — and unfortunately named — toolkit to target high-value networks for React2Shell exploitation. The "React2Shell" vulnerability is already almost a few months old, but it's far from over.
Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia
Former US defense contractor executive Peter Williams was sentenced to prison for selling exploits to a Russian cyber-tools broker.