LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
ai

U.S. Bank CISO says the security role keeps growing and no one can own all of it

The role of a Chief Information Security Officer (CISO) has expanded significantly to encompass areas such as fraud, resilience, third-party risk, and AI governance, according to Ann Barron-DiCamillo, EVP and CISO at U.S. Bank. She notes that while this consolidation can make security leaders more effective by addressing interconnected risks, no single individual can realistically own every…

ZeroDay News ·

Source: Help Net Security

Photo: Myotus (CC0) via Wikimedia Commons

The role of a Chief Information Security Officer (CISO) has expanded significantly to encompass areas such as fraud, resilience, third-party risk, and AI governance, according to Ann Barron-DiCamillo, EVP and CISO at U.S. Bank. She notes that while this consolidation can make security leaders more effective by addressing interconnected risks, no single individual can realistically own every aspect of these disciplines at scale. Instead, success increasingly relies on building strong partnerships across technology, risk, legal, fraud, compliance, and business teams.

Barron-DiCamillo emphasizes that the CISO's function is evolving from direct control to convening stakeholders, aligning priorities, and ensuring risk decisions are made with a comprehensive understanding of their broader implications. She states that "cyber knows no borders," illustrating how issues like a third-party outage can become a resilience problem, AI adoption raises governance questions, and fraud techniques evolve alongside general threat activity.

Regarding incident reporting, Barron-DiCamillo acknowledges regulators' push for shorter deadlines to facilitate early awareness and assist affected organizations. However, she points out the inherent tension between speed and certainty during the initial hours of an incident, when information is incomplete and teams are focused on containment and investigation rather than drafting reports. While timely communication is important, she stresses that it should be grounded in facts to avoid confusion and maintain confidence, advocating for a balance that allows for timely information sharing without imposing excessive administrative burdens during critical response phases.

When discussing security investments, Barron-DiCamillo suggests that many organizations over-invest in compliance activities that merely demonstrate security rather than actively reducing risk. She argues that financial institutions, which often possess mature control frameworks and understand their risks, should prioritize capabilities that reduce exposure before human intervention is required. This includes greater investment in automation, asset visibility, identity management, vulnerability management, and secure-by-design engineering practices, measuring success by risk reduction and resiliency rather than the number of controls implemented.

Concerning the duplication of effort when a widely used vendor is compromised, Barron-DiCamillo believes some parallel assessment is inevitable and appropriate due to varying technology stacks, dependencies, and risk tolerances across institutions. However, she also highlights the strength of the financial sector's information sharing through organizations like FS-ISAC and FSSCC. She advocates for more effective sharing of threat intelligence, technical indicators, and mitigation approaches to allow institutions to focus on their unique risks rather than independently recreating the same situational picture.

Drawing from her experience teaching cybersecurity risk management at American University, Barron-DiCamillo notes that many students initially perceive cybersecurity as primarily a technology problem. She corrects this by emphasizing that the most challenging issues often involve people, processes, and decision-making. Furthermore, she stresses that cybersecurity is a shared responsibility, with security teams providing expertise and guidance, but lasting risk reduction achieved through collaborative efforts across technology, business, risk, and security teams.

aifinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is rolling out an invisible watermarking system for text generated by its ChatGPT and Codex models within the European Union. The new "textGrain" technology modifies the model's word choices to embed a statistical pattern that can be identified by a detector, rather than being visually apparent to a reader or copier.

CVE-2026-86360critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

CVE-2026-21589critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has reportedly removed an Accenture contractor following an alleged security failure that contributed to a data breach attributed to the ShinyHunters threat group. This incident is said to have resulted in the theft of personal details belonging to thousands of FBI employees. The reported cause of the breach was a patch failure.

malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.

nation-state

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Denmark's digitalization ministry has reported that unauthorized parties accessed the Central Person Register (CPR), the national population register, compromising data for approximately 8.8 million individuals. The accessed information includes names, addresses, and personal identification numbers. This incident, reported on October 5, affects both living and deceased persons registered in…