Motherboards from one of the world's biggest manufacturers have a firmware backdoor present that impacts systems running Windows. Gigabyte motherboards are most commonly found in high-end gaming PCs, and collectively there may be millions of tainted pieces of hardware.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
An adware campaign involving over 60,000 Android apps has infected devices since October 2022. Researchers warned that the infected Android apps could start distributing potent malware, including credential stealers, banking trojans, and ransomware.
The investment research firm’s first disclosed data breach took place between November 2021 and August 2022, and a notification on January 25 of this year indicated that 820,000 customers were impacted. That number has now been revised to 8.8 million.
It’s clear that the introduction of generative AI to the mainstream is tipping the scales towards a war of algorithms against algorithms, machines fighting machines. For cyber security, the time to introduce AI into the toolkits of defenders is now.
Cybersecurity firm Kaspersky Lab has discovered an iOS malware variant spreading via an iPhone zero-click exploit in iMessage. Russia has accused the NSA of targeting the country’s diplomatic missions and Apple of providing backdoors.
Toyota discovered a second cloud misconfiguration data leak that exposed 260,000 domestic and international customers' in-vehicle data and personal information for over eight years.
The annual Verizon DBIR provides further confirmation that attackers are showing a renewed interest in social engineering, particularly in conjunction with business email compromise (BEC) attacks. And the average financial damage of a ransomware attack has doubled and is almost certain to cost organizations at least $1 million to remediate.
Prior to its seizure in April 2022, RaidForums was one of the biggest hacking forums catering to cybercriminals that trade in stolen data. A new competitor is looking to make a name for itself by exposing some 478,000 former RaidForums members.
A growing number of organizations are beginning to recognize the potential that AI has to dramatically improve the process of cybersecurity training by improving efficiency in areas like content development, analytics, and enhanced accessibility.
Supply chain security is in the news once again as a cyber attack on Zellis, a UK-based payroll provider, has led to the compromise of numerous organizations. Among the biggest names impacted by the attack are the BBC, British Airways and major UK drugstore chain Boots.










