Clop ransomware gang breached 130 organizations via Fortra GoAnywhere managed file transfer tool and stole 1 million CHS Healthcare patients' records.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
In the last few years Apple and other browsers have essentially demanded that all certificate authorities gradually reduce the lifecycle of digital certificates. To be able to replace tens of, or even hundreds of thousands, of certificates in a compressed time frame, on a regular basis, is going to be nearly impossible without automation solutions.
Cyber Incident Reporting for Critical Infrastructure Act requires critical sector entities to promptly report to the DHS's Cybersecurity and Infrastructure Security Agency (CISA) certain cyber incidents and ransomware payments.
The Cyber Safety Review Board finds that the open source community is "under-equipped" to fully deal with the Log4j vulnerability and that it will be making appearances in the wild for "a decade or more."
Taiwanese PC maker Acer confirmed a data breach after a hacker listed the stolen data on a hacking forum, including technical product specifications and infrastructure details.
Security automation is increasingly becoming a necessity in order to keep up with the cyber threats, but security analysts report significant increased stress on the job driven by fear of missing alerts.
Hackers have listed 860GB of private source code and assets stolen from Target’s Gitea self-hosted software development platform for sale on an underground hacking forum.
While the transition to passwordless security procedures is already underway, adoption is still limited mainly in larger companies in certain industries. There are many steps that can (and should) be taken to accelerate the authentication journey to make passwordless authentication mainstream.
In this article, we move beyond the buzzword to understand the high costs of passwords, the distinction between passwordless and password-free, what a world without passwords would look like and how we can finally get there.
The data breach took place at the BWI Airport Marriott near Baltimore. A social engineering attack was executed on a member of the hotel staff, who unwittingly granted access.










