{"id":208869,"date":"2025-09-11T09:14:29","date_gmt":"2025-09-11T13:14:29","guid":{"rendered":"https:\/\/nationalcybersecuritysociety.org\/?p=208869"},"modified":"2025-11-14T09:30:28","modified_gmt":"2025-11-14T14:30:28","slug":"ctw-19-may-2025","status":"publish","type":"post","link":"https:\/\/nationalcybersecuritysociety.org\/?p=208869","title":{"rendered":"CTW #19 \u2014 May 2025"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||0px|||&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||72px|||&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/NCSS-3397-Bulletin-Header-Footer-Header-Graphic-1600&#215;350-Compressed.png&#8221; title_text=&#8221;NCSS-3397-Bulletin-Header-Footer-Header Graphic 1600&#215;350-Compressed&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><em>Published: May 28, 2025<\/em><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><span>Our new bulletin <strong><em>Cyber Threat Watch<\/em><\/strong> has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_heading title=&#8221;Featured Cyber News \u2014 New Approach to the Digital Identity and Password Management&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; title_level=&#8221;h2&#8243; title_font=&#8221;|600|||||||&#8221; title_text_color=&#8221;#00688E&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/AdobeStock_1274737171-scaled.jpeg&#8221; title_text=&#8221;Cyber crime and cyber security alert warning concept. Hand using laptop and smartphone with 2 step verification for identity identification, multi factor authentication, information secure encryption.&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_3_text_color=&#8221;#00688E&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>In August 2024, the <span><a href=\"https:\/\/www.nist.gov\/cybersecurity\">National Institute of Standards and Technology<\/a><\/span> (NIST) released the <span><a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-63-4.2pd.pdf\">Second Public Draft of SP 800-63-4 Digital Identity Guidelines<\/a><\/span> to help organizations better protect digital accounts. The public comment period closed in October 2024, with the final version expected this year.<\/p>\n<p>For professional services firms, this update reflects a shift in how businesses can safeguard client accounts and sensitive data with a simpler, more effective approach. With <span><a href=\"https:\/\/nationaltoday.com\/world-password-day\/\">World Password Day<\/a><\/span> on May 1 this year, it is a timely opportunity to learn about evolving password practices.<\/p>\n<h3>What Are the NIST Digital Identity Guidelines?<\/h3>\n<p>The NIST guidelines are federally developed standards for managing digital identities. Originally designed for government use, they are widely adopted in the private sector, particularly by the organizations handling regulated or confidential data.<\/p>\n<p>SP 800-63-4 is the upcoming major revision that covers all three parts below, based on public feedback, research, and evolving technologies.<\/p>\n<ul>\n<li><span><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63a.html\"><strong>SP 800-63A<\/strong><\/a><\/span><strong>:<\/strong> Enrollment and Identity Proofing (verifying a real person)<\/li>\n<li><span><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63b.html\"><strong>SP 800-63B<\/strong><\/a><\/span><strong>: <\/strong>Authentication and Lifecycle Management (authenticating a user)<\/li>\n<li><span><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63c.html\"><strong>SP 800-63C<\/strong><\/a><\/span><strong>:<\/strong> Federation and Assertions (sharing identity across systems)<\/li>\n<\/ul>\n<h3>What&#8217;s Going to Change<\/h3>\n<p><span><a href=\"https:\/\/scytale.ai\/resources\/2024-nist-password-guidelines-enhancing-security-practices\/\">The new guidelines reflect how people use digital tools today<\/a>, such as password syncing, password managers, and digital wallets. Key password-related updates are as follows:<\/span><\/p>\n<p><span><\/span><\/p>\n<table border=\"1\" style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr style=\"background-color: #666666;\">\n<td width=\"144\" style=\"width: 25.046%;\"><span style=\"color: #ffffff;\"><strong>Requirement<\/strong><\/span><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span style=\"color: #ffffff;\"><strong>Current Guidelines <\/strong><strong>(SP 800-63B-3)<\/strong><\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span style=\"color: #ffffff;\"><strong>New Guidelines <\/strong><strong>(SP 800-63B-4 Second Draft)<\/strong><\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Minimum Password Length<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Minimum of 8 characters<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Minimum of 8; 12-16 characters recommended<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Maximum Password Length<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Not clearly defined; often limited<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Up to 64 characters supported<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Enforced Complexity<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Allowed but not required; many systems force mixed use of upper\/lowercase, numbers, and special characters.<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>No forced mix; focus is on length.<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Password Expiration<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Not required unless compromised; many reset every 60\u201390 days.<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Changes required only after known or suspected compromise<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Password Hints<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Allowed<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Not allowed<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Security Questions<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Allowed<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Not allowed<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><span><a href=\"https:\/\/www.authsignal.com\/blog\/articles\/why-sms-based-authentication-is-no-longer-enough-for-secure-account-protection\"><strong>SMS-based MFA<\/strong><\/a><\/span><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Allowed but discouraged<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Strongly discouraged; <a href=\"https:\/\/teampassword.com\/blog\/best-authenticator-apps\">app<\/a>&#8211; or <a href=\"https:\/\/securityscorecard.com\/blog\/what-is-a-hardware-token-comparing-authentication-methods\/\">hardware<\/a>-based MFA recommended<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Breached Password Checks<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Recommended<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Required; must check against known breached lists<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><span><a href=\"https:\/\/www.dashlane.com\/blog\/how-password-managers-work-beginners-guide\"><strong>Password Manager<\/strong><\/a><strong> Use and Support<\/strong><\/span><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Use suggested; paste from password manager should be allowed.<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span>Use strongly encouraged; paste from password manager must be allowed.<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"144\" style=\"width: 25.046%;\"><strong><span>Character Support<\/span><\/strong><\/td>\n<td width=\"240\" style=\"width: 37.9374%;\"><span>Only basic <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/ASCII-American-Standard-Code-for-Information-Interchange\">ASCII<\/a> characters supported<\/span><\/td>\n<td width=\"240\" style=\"width: 36.8324%;\"><span><a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/ASCII-American-Standard-Code-for-Information-Interchange\">ASCII<\/a>, <a href=\"https:\/\/home.unicode.org\/\">Unicode<\/a>, and space characters supported<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/AdobeStock_864716949-scaled.jpeg&#8221; title_text=&#8221;AdobeStock_864716949&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_3_text_color=&#8221;#00688E&#8221; custom_css_free_form=&#8221;ol {||  list-style: none !important; ||  counter-reset: item; ||}||||ol li {||  counter-increment: item; ||  position: relative; ||  padding-left: 2em; \/* Adjust as needed for spacing *\/||}||||ol li::before {||  content: counter(item) %22.%22; ||  font-weight: bold; ||  position: absolute;||  left: 0; ||  width: 1.5em; ||  text-align: right;||}&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Why This Update Matters<\/h3>\n<p><span>Beyond password rules, the updated version introduces broader improvements. Remote identity verification via video calls, <a href=\"https:\/\/acante.co.uk\/news\/kiosk-for-id-authentication\/\">kiosks<\/a>, or other self-service options streamlines authentication. To meet fraud detection requirements, systems must include ways to detect suspicious behavior, such as unusual logins or repeated failed attempts. Privacy and accessibility are enhanced by limiting data collection, requiring clear disclosures, and ensuring access for users with limited technology. Support for digital wallets like portable user-controlled credentials enables secure, passwordless logins\u2014advancing user experience while<\/span> aligning with compliance frameworks like <span><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html\">HIPAA<\/a><\/span>, <span><a href=\"https:\/\/www.aicpa-cima.com\/topic\/audit-assurance\/audit-and-assurance-greater-than-soc-2\">SOC 2<\/a><\/span>, and <span><a href=\"https:\/\/www.iso.org\/standard\/27001\">ISO 27001<\/a><\/span>.<\/p>\n<h3>Next Steps: What Your Business Should Consider<\/h3>\n<p>Looking ahead, the following recommendations reflect NIST\u2019s intended direction and serve as a practical basis for preparation, allowing<span> your business to start considering changes.<\/span><\/p>\n<ol>\n<li><strong><span>Update Password Policies<br \/><\/span><\/strong>&#8211; Require <span>longer passwords (12+ characters)<br \/><\/span><span>&#8211; Remove forced complexity and periodic reset rules<br \/><\/span><\/li>\n<li><strong>Block Risky Passwords<br \/><\/strong><span>&#8211; Use a <a href=\"https:\/\/haveibeenpwned.com\/Passwords\">password blacklist<\/a> (also called a breach blocklist) to block known weak or compromised passwords<\/span><strong><\/strong><span><\/span><\/li>\n<li><strong>Enable Strong <\/strong><a href=\"https:\/\/duo.com\/product\/multi-factor-authentication-mfa\"><strong>MFA<\/strong><\/a><strong> Methods<br \/><\/strong><span>&#8211; Implement <a href=\"https:\/\/teampassword.com\/blog\/best-authenticator-apps\">app-based<\/a> (e.g., authenticator apps) or <a href=\"https:\/\/securityscorecard.com\/blog\/what-is-a-hardware-token-comparing-authentication-methods\/\">hardware-based<\/a> (e.g., security keys) MFA, instead of SMS<br \/><\/span><strong><\/strong><\/li>\n<li><strong>Remove Hints and Security Questions<br \/><\/strong><span>&#8211; Eliminate these from login and recovery processes<br \/><\/span><strong><\/strong><\/li>\n<li><strong>Support <\/strong><a href=\"https:\/\/www.dashlane.com\/blog\/how-password-managers-work-beginners-guide\"><strong>Password Managers<\/strong><\/a><span><\/span><span><br \/>&#8211; Allow copy\/paste and long-character input<\/span><\/li>\n<li><strong><span>Modernize Identity Verification<br \/><\/span><\/strong><span>&#8211; Consider remote options like video or <a href=\"https:\/\/acante.co.uk\/news\/kiosk-for-id-authentication\/\">kiosk-based<\/a> ID checks<\/span><strong><span><\/span><\/strong><\/li>\n<li><strong>Implement Basic Fraud Checks<br \/><\/strong>&#8211; Set up alerts to monitor unusual login behavior<\/li>\n<\/ol>\n<h3>Conclusion<\/h3>\n<p>The upcoming NIST update is more than a password refresh\u2014it offers a smarter, more practical approach to managing digital identity and passwords. Professional services firms, particularly those with regulated clients or systems, will benefit from early planning to ensure better protection of client information, smoother operations, and improved readiness for future security and compliance demands.<\/p>\n<p>The NCSS encourages businesses to adopt comprehensive security practices and stay informed about evolving cybersecurity requirements. <span>We recommend you consider becoming an NCSS member to access a wide range of our services. For more information, visit our <a href=\"https:\/\/nationalcybersecuritysociety.org\/small-business\/\">Small Business page<\/a><\/span>.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; custom_padding=&#8221;||42px|||&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_divider _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||-2px|||&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_divider][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_2_font=&#8221;|600|||||||&#8221; header_2_text_color=&#8221;#00688E&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>References<\/h2>\n<p><a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-63-4.2pd.pdf\">https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-63-4.2pd.pdf<\/a><\/p>\n<p><a href=\"https:\/\/scytale.ai\/resources\/2024-nist-password-guidelines-enhancing-security-practices\/\">https:\/\/scytale.ai\/resources\/2024-nist-password-guidelines-enhancing-security-practices\/<\/a><\/p>\n<p><a href=\"https:\/\/sprinto.com\/blog\/nist-password-guidelines\/\">https:\/\/sprinto.com\/blog\/nist-password-guidelines\/<\/a><\/p>\n<p><a href=\"https:\/\/linfordco.com\/blog\/nist-password-policy-guidelines\/\">https:\/\/linfordco.com\/blog\/nist-password-policy-guidelines\/<\/a><\/p>\n<p><a href=\"https:\/\/www.hipaajournal.com\/nist-password-guidelines-update-2024\/\">https:\/\/www.hipaajournal.com\/nist-password-guidelines-update-2024\/<\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;2px|||||&#8221; global_module=&#8221;208703&#8243; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;48px|||||&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/NCSS-3397-Bulletin-Header-Footer-Attribution-Banner-1600&#215;200-1.png&#8221; title_text=&#8221;NCSS-3397-Bulletin-Header-Footer-Attribution Banner 1600&#215;200&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; text_font_size=&#8221;8px&#8221; header_2_font=&#8221;|600|||||||&#8221; header_2_text_color=&#8221;#CCC21B&#8221; text_font_size_tablet=&#8221;13px&#8221; text_font_size_phone=&#8221;&#8221; text_font_size_last_edited=&#8221;on|tablet&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>About the NCSS<\/h2>\n<p><span>The National Cybersecurity Society (NCSS) is committed to improving the online safety and security of the small business community through education, awareness, and advocacy. As a 501(3)(c) organization, the NCSS uses funds from charitable donations and grants to develop educational materials, webinars, weekly cyber tips, videos, and how-to-guides. The organization\u2019s goal is to enable and empower small and medium businesses to obtain cybersecurity services, assist them in understanding their cyber risk, and advise on the type of protection needed. We want to continue to grow our community and encourage you to tell other small businesses we are here to help.<\/span><\/p>\n<p><em>The NCSS is committed to respecting the use of images in our communication efforts. Accordingly, unless otherwise specifically noted, the graphics in our bulletin are sourced under license from Adobe Stock. The header and footer images were designed and purchased through a contract with Eyedea Advertising &amp; Design Studio.<\/em><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Published: May 28, 2025Our new bulletin Cyber Threat Watch has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.In August 2024, the National Institute of Standards and [&hellip;]<\/p>\n","protected":false},"author":85,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"<!-- wp:divi\/placeholder \/-->","_et_gb_content_width":"","footnotes":""},"categories":[25],"tags":[],"class_list":["post-208869","post","type-post","status-publish","format-standard","hentry","category-bulletins"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CTW #19 \u2014 May 2025 - National Cybersecurity Society<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nationalcybersecuritysociety.org\/?p=208869\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CTW #19 \u2014 May 2025 - National Cybersecurity Society\" \/>\n<meta property=\"og:description\" content=\"Published: May 28, 2025Our new bulletin Cyber Threat Watch has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.In August 2024, the National Institute of Standards and [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nationalcybersecuritysociety.org\/?p=208869\" \/>\n<meta property=\"og:site_name\" content=\"National Cybersecurity Society\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-11T13:14:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-14T14:30:28+00:00\" \/>\n<meta name=\"author\" content=\"Olivia Bolton\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olivia Bolton\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869\"},\"author\":{\"name\":\"Olivia Bolton\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#\\\/schema\\\/person\\\/fe5516a3932759e8d1950572f05f30fc\"},\"headline\":\"CTW #19 \u2014 May 2025\",\"datePublished\":\"2025-09-11T13:14:29+00:00\",\"dateModified\":\"2025-11-14T14:30:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869\"},\"wordCount\":1419,\"commentCount\":0,\"articleSection\":[\"Bulletins\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869\",\"url\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869\",\"name\":\"CTW #19 \u2014 May 2025 - National Cybersecurity Society\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#website\"},\"datePublished\":\"2025-09-11T13:14:29+00:00\",\"dateModified\":\"2025-11-14T14:30:28+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#\\\/schema\\\/person\\\/fe5516a3932759e8d1950572f05f30fc\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208869#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CTW #19 \u2014 May 2025\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#website\",\"url\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/\",\"name\":\"National Cybersecurity Society\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#\\\/schema\\\/person\\\/fe5516a3932759e8d1950572f05f30fc\",\"name\":\"Olivia Bolton\",\"url\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?author=85\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CTW #19 \u2014 May 2025 - National Cybersecurity Society","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nationalcybersecuritysociety.org\/?p=208869","og_locale":"en_US","og_type":"article","og_title":"CTW #19 \u2014 May 2025 - National Cybersecurity Society","og_description":"Published: May 28, 2025Our new bulletin Cyber Threat Watch has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.In August 2024, the National Institute of Standards and [&hellip;]","og_url":"https:\/\/nationalcybersecuritysociety.org\/?p=208869","og_site_name":"National Cybersecurity Society","article_published_time":"2025-09-11T13:14:29+00:00","article_modified_time":"2025-11-14T14:30:28+00:00","author":"Olivia Bolton","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Olivia Bolton"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208869#article","isPartOf":{"@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208869"},"author":{"name":"Olivia Bolton","@id":"https:\/\/nationalcybersecuritysociety.org\/#\/schema\/person\/fe5516a3932759e8d1950572f05f30fc"},"headline":"CTW #19 \u2014 May 2025","datePublished":"2025-09-11T13:14:29+00:00","dateModified":"2025-11-14T14:30:28+00:00","mainEntityOfPage":{"@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208869"},"wordCount":1419,"commentCount":0,"articleSection":["Bulletins"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nationalcybersecuritysociety.org\/?p=208869#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208869","url":"https:\/\/nationalcybersecuritysociety.org\/?p=208869","name":"CTW #19 \u2014 May 2025 - National Cybersecurity Society","isPartOf":{"@id":"https:\/\/nationalcybersecuritysociety.org\/#website"},"datePublished":"2025-09-11T13:14:29+00:00","dateModified":"2025-11-14T14:30:28+00:00","author":{"@id":"https:\/\/nationalcybersecuritysociety.org\/#\/schema\/person\/fe5516a3932759e8d1950572f05f30fc"},"breadcrumb":{"@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208869#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nationalcybersecuritysociety.org\/?p=208869"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208869#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nationalcybersecuritysociety.org\/"},{"@type":"ListItem","position":2,"name":"CTW #19 \u2014 May 2025"}]},{"@type":"WebSite","@id":"https:\/\/nationalcybersecuritysociety.org\/#website","url":"https:\/\/nationalcybersecuritysociety.org\/","name":"National Cybersecurity Society","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nationalcybersecuritysociety.org\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/nationalcybersecuritysociety.org\/#\/schema\/person\/fe5516a3932759e8d1950572f05f30fc","name":"Olivia Bolton","url":"https:\/\/nationalcybersecuritysociety.org\/?author=85"}]}},"_links":{"self":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts\/208869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/users\/85"}],"replies":[{"embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=208869"}],"version-history":[{"count":8,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts\/208869\/revisions"}],"predecessor-version":[{"id":209154,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts\/208869\/revisions\/209154"}],"wp:attachment":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=208869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=208869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=208869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}