中文

Deep Dive

来自我们记者的行业洞察

FCC investigation may throw its self-created IoT security certification program into trouble
Deep Dive

FCC investigation may throw its self-created IoT security certification program into trouble

The U.S. Federal Communications Commission (FCC) launched the U.S. Cyber Trust Mark program during the Biden administration to provide security certification for IoT devices. However, the new FCC chair under the Trump administration has initiated a China-related investigation into UL Solutions, the program's designated administrator, which may stall the program. Experts warn that a prolonged investigation will weaken the program's effectiveness and increase cybersecurity risks faced by consumers and businesses.

"Paused Partnership": U.S. Government Turmoil Undermines Critical Infrastructure Cooperation
Deep Dive

"Paused Partnership": U.S. Government Turmoil Undermines Critical Infrastructure Cooperation

According to interviews with representatives from 14 critical infrastructure sectors, four former senior government cybersecurity officials, and multiple experts, the Trump administration's federal government restructuring has severely weakened the public-private partnerships that protect U.S. critical infrastructure from cyberattacks and physical disasters. Mass layoffs, mission uncertainty, and leadership vacancies have disrupted collaboration between the government and sectors such as healthcare, water, energy, and telecommunications, while sensitive information-sharing mechanisms like CIPAC have been eliminated, leaving industries deeply concerned about the government's ability to respond to major cyberattacks.

Frequent Vulnerabilities in Network Security Devices Keep Corporate Defenses Under Pressure
Deep Dive

Frequent Vulnerabilities in Network Security Devices Keep Corporate Defenses Under Pressure

In January 2025, federal network agencies and researchers again warned that attackers were exploiting a zero-day vulnerability (CVE-2025-0282) in Ivanti Connect Secure. This came about a year after the same product was exploited via two zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887). The frequent occurrence of such incidents reveals that security flaws in network defense devices are continuously eroding corporate defenses. Edge devices such as firewalls and VPNs, lacking endpoint detection capabilities, have become preferred initial intrusion points for attackers. Experts point out that despite the risks, these devices will remain in use for the long term, and enterprises need to strengthen vulnerability management while addressing architectural challenges.

CIOs Tackle Multiple Generative AI Risks with NIST Framework
Deep Dive

CIOs Tackle Multiple Generative AI Risks with NIST Framework

The widespread application of generative AI brings numerous risks, prompting enterprise CIOs to turn to the National Institute of Standards and Technology (NIST) AI Risk Management Framework to systematically identify, quantify, and mitigate risks. Institutions like Discover Financial Services ensure compliance and security while advancing AI innovation through risk classification, human oversight, and continuous monitoring.

Microsoft's years of security debt erupt, reputation crisis intensifies
Deep Dive

Microsoft's years of security debt erupt, reputation crisis intensifies

Microsoft recently suffered two major state-sponsored cyber intrusions, sparking harsh criticism of its security culture. Experts believe the consequences of years of ignoring security warnings are now emerging, but market dominance and government customer lock-in make reform challenging.