A new CISA-NSA joint report follows many calls by both members of the cybersecurity industry and government agencies for a transition to memory-safe languages like Rust, Ruby, Java and C# due to their inherent minimization of memory-related classes of vulnerabilities.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Vulnerable IT service providers are becoming entry points for supply chain attacks as seen in the recent attack on Wipro. The attack follows closely after Wipro CEO declares "security cannot be a show stopper for business priorities".
Like it or not, there is a cybersecurity talent shortage. But whether or not that skills gap is catastrophic or inconvenient for your business is entirely up to you.
Threat actor is offering the alleged WhatsApp data leak for a relatively low cost, dividing it up by country of origin and offering each package for prices in the range of several thousand dollars via a dark web forum.
Johnson & Johnson’s IT service provider IBM has notified over 1 million Janssen CarePath customers of a data breach that leaked personal and medical information.
A new regulatory filing disclosed that genetic testing company 23andMe leaked the ancestry information of nearly 7 million users in the October 2023 data breach.
Retailer WH Smith suffered a cyber attack that leaked employee data, including names, dates of birth, and National Insurance Numbers. The incident leaked the data of current and former employees, but customer data was unaffected.
The USA PATRIOT Act Section 314(b) is an important enabler in the fight against financial crime, allowing financial institutions to share vital data with one another for prevention, detection, and investigations. Ronen Cohen, VP of Strategy at Duality Technologies, discusses why financial institutions have struggled to fully utilize this valuable piece of legislation and how privacy-first approaches are paving a new way forward.
Microsoft has banned the developer accounts of high-profile open-source projects, leaving them unable to publish software updates, exposing Windows users to various cyber threats.
SMBs were the subject of the overwhelming bulk of malicious cyberattacks in past years. Here are the most common and dangerous cybersecurity challenges most SMBs face and what you can do to deal with them.










