Describing cyber threats as one of its primary challenges, the FBI is asking for an additional $64 million in 2024 to add 192 new positions and improve its cyber capabilities. Much of the budget request focuses on the looming threat that China poses.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
When conducting penetration tests, regardless of an organization’s size or maturity, certain kinds of attacks recur so regularly that security teams should develop standardized practices to defend against them. Here are some suggested strategies for conducting detection and mitigation.
By leveraging public interest in generative AI chatbots like ChatGPT and Google’s Bard, hackers are distributing novel malware on Facebook and hijacking online accounts.
T-Mobile data breach second data breach of 2023 took place from February to March. Those impacted likely had their Social Security numbers, ID numbers, account pins and other sensitive data revealed.
There is the need for additional cyber defenses of growing 5G networks – and we should expect to see increasing policy pressure around the vetting process for hardware and software that are crucial to these upgraded networks. This is raising the importance of supply chain risk management for the telecommunications industry.
Roughly in keeping with numbers seen in recent years, the Google Play Store announced that it blocked 1.43 million bad apps and banned 173,000 malicious or policy-violating developer accounts in 2022.
Unknown hackers reportedly breached AT&T customer email accounts for months via an API security issue to conduct a massive crypto theft scheme estimated at nearly $20 million.
Many countries now mandate that its citizens’ data must stay in the country. This is counter to the spirit of globalization and adds layers of complexity to delivering IT services and security. It is time to put data at the center of modern security programs.
Attackers approach targets for account takeover pretending to be a member of the Meta tech support team, using Facebook profiles that they have created that have a post history that makes it appear as if they are a legitimate employee.
SaaS applications are not going anywhere, and we must face the fact that they have access to our company’s most sensitive data. With SaaS, the shadow IT challenge has expanded and deepened even further.










