Welcome
Welcome
Hello and Welcome!
Be sure to attend our monthly meetings. Lots of good information there. Register for our Thursday August 28th Virtual Meeting on our site ISC2CT.org
Also come Join our (ISC)2 Connecticut Chapter Discord Server
Upcoming events:
SANS Security Awareness Summit 2025 | Free Online Event: Mon, Aug 11 - Fri, Aug 15, 2025 12 CPEs (Summit Only) Join us for the 12th annual SANS Security Awareness Summit where this year’s theme is “Advancing Security Culture.” Learn, connect, and share with thousands of fellow security awareness, behavior, and culture professionals from around the world. This event is designed to equip you with the tools and knowledge needed to drive meaningful security culture change. Agenda and Registration Link
BSides CT | Saturday, Sept. 20th, 2025 | Sacred Heart University (West Campus) 3135 Easton Turnpike Fairfield, CT A conference for the Connecticut information security (infosec) community, run by the Connecticut infosec community! The annual BSides CT event is a place for the community to share ideas and learn with: Insightful discussions: Formal and informal networking and educational opportunities Practical demonstrations: Hands-on activities, like our annual Capture the Flag (CTF) and workshops Interactive sessions: Talks covering latest trends and ongoing events that shape the future of infosec. Limited amount of discounted early bird tickets are still available Registration Link
Cyber Nutmeg 2025 | Friday October 10th 2025 | Central Connecticut State University CCSU Connecticut's Premier Cybersecurity Event for community anchors institutions. Join the National Guard, Connecticut Education Network (CEN), and your fellow colleagues this October. Given the current threats posed by various actors across the cyber domain, it is more imperative than ever that we ensure our vigilance and commitment to improving our cybersecurity posture across the state. The Cyber Nutmeg event is an opportunity to share our collective challenges, discuss innovative solutions, and work toward our common goal: securing our state’s networks and protecting our data. Registration Link
NEACS - The NorthEast Annual Cybersecurity Summit | Thursday, November 13th 2025 | Quinnipiac University, North Haven, CT Succinct presentations will focus on topics that give cyber leaders immediately actionable insights. Moderated discussion will follow each topic, with streamlined talking points to maximize audience take-aways. Agenda focus: The intersection of academics and enterprise for cybersecurity leadersCyber industry trends with respect to vendors, investment, product sprawl for 2026 planning. Case studies from law enforcement agencies, focusing on recent trends. The convergence of fraud prevention/risk management and cybersecurity Zero Trust, what it means in the context of risk strategy vs products & services Agenda and Registration Link
Upcoming Training:
NII Training Certified Web Application Security Professional CWASP | August 19-21, 2025 09:00AM- 1:00PM EDT) 3 days – 12 CPEs | Standard Fee $159 ISC2 Members $129 The CWASP training is designed to provide professionals a hands-on experience of implementing security measure for safeguarding web applications through case studies and examples. The CWASP training is a 12 hours of online training spread across 3 days, 4 hours each day and the workshop module is for 12 hours which includes 11 hours of training sessions followed by 1-hour online examination. Registration Form
Thank you to our Sponsors
Quinnipiac University is committed to helping advance the field of cybersecurity through its School of Computing & Engineering. To support the growth of professionals within cybersecurity and computing, Quinnipiac offers flexible online and on-campus opportunities that deliver practical skills you can immediately apply on the job. Both its MS in Cybersecurity and MS in Computer Science programs feature hands-on experience in lab settings that simulate real-world scenarios. To learn more about these exciting opportunities, Visit Quinnipiac University
Cyber News

Microsoft Fix Targets Attacks on SharePoint Zero-Day
Microsoft issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the SharePoint flaw to breach U.S. federal and state agencies, universities, and energy companies.

Securing the Budget: Demonstrating Cybersecurity's Return
By tying security investments to measurable outcomes — like reduced breach likelihood and financial impact — CISOs can align internal stakeholders and justify spending based on real-world risk.

Enterprise printer security fails at every stage
Printer platform security is often overlooked in enterprise security strategies, leaving security gaps

Chasing Ghosts Over RDP: Lateral Movement in Tiny Bitmaps
Picture this: you’re an incident responder hot on the trail of an intruder who’s hopping between servers using Remote Desktop Protocol (RDP). They think they’re sneaky, hiding behind Windows’ built-in RDP feature

MITRE Launches AADAPT Framework for Detecting and Responding to Digital Asset Management Attacks
MITRE Corporation has launched the Adversarial Actions in Digital Asset Payment Technologies (AADAPT™) framework, a comprehensive knowledge base designed to help organizations detect and respond to sophisticated attacks targeting digital asset management systems.

Funding to protect US from Stuxnet-like worm expired
CyberSentry work grinds to a halt. Government funding for a program that hunts for threats on America's critical infrastructure networks expired

Malicious Implants Are Coming to AI Components, Applications
A red teamer is publishing research next month about how weaknesses in modern security products lay the groundwork for stealthy implants in AI-powered applications.

Millions of Cars Exposed to Remote Hacking via PerfektBlue Attack
Critical vulnerabilities in the BlueSDK Bluetooth stack that could have allowed remote code execution on car systems.

McDonald’s Chatbot Recruitment Platform Exposed 64 Million Job Applications
Vulnerabilities in an API allowed unauthorized access to contacts and chats, exposing the information of 64 million McDonald’s applicants.