- AI Strategist News
- Posts
- AI Weekly News Update: 03/17/2025
AI Weekly News Update: 03/17/2025
AI Strategist News: Navigating the transformative world of AI for your business
Table of Contents
This Week’s News
In partnership with the U.S. Cybersecurity and Infrastructure Security Agency, the FBI has issued a joint March 12 cybersecurity advisory against the backdrop of attacks by the Medusa ransomware group. The full FBI alert, AA25-071A, goes into great depth regarding the technicalities of the Medusa operation. As such, it is of importance that this should be read by all cyber-defenders. However, for the purposes of this article I am going to focus on the attack mitigation advice offered by the FBI.
FBI Warning Does Not Go Far Enough
Not everyone is happy with the advice that has been given by the FBI and CISA with regard to the Medusa ransomware group threat. Take Roger Grimes, a data-driven defence evangelist at KnowBe4, who said that it continues a long tradition of “warning people about ransomware that spreads using social engineering, that then does not suggest security awareness training as a primary way to defeat it.” Grimes said that, in the experience of KnowBe4, social engineering is involved in 70% - 90% of all successful hacking attacks. Yet, despite the official alert noting that social engineering is one of the primary methods of distributing the ransomware threats, awareness isn’t mentioned in the 15 recommended mitigations. “It's like learning that criminals are breaking into your house all the time through the windows and then recommending more locks for the doors,” Grimes said.