MITRE Launches EMB3D Threat Model Framework for Critical Infrastructure Protection

MITRE, in collaboration with Niyo Little Thunder Pearson, Red Balloon Security, and Narf Industries, has launched EMB3D, a new threat model framework specifically designed to protect operational technology and industrial control systems by providing a comprehensive knowledge base of cyber threats specific to embedded devices used in critical infrastructure environments.

Non-Human Access Emerges as Significant Vulnerability in Cyber Attacks

Non-human access, particularly API keys and tokens, has become a major vulnerability in cyber attacks, leading to data breaches and supply chain attacks on companies like Okta, GitHub, Microsoft, Slack, and CircleCI. The adoption of GenAI tools and services has further exacerbated this issue, highlighting the need for proper security measures and policies to protect non-human identities and their access credentials.