A five-year cyber espionage campaign has been running in Asia Pacific where attackers will infiltrate a government body and use stolen data to launch targeted phishing attacks against other governments.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Company confirmed that a five-year-old Slack bug leaked your hashed password to other group participants if you interacted with an invite-sharing feature.
Threat actors accessed personally identifiable information (PII) and Social Security numbers of more than 1.5 million customers in the Flagstar Bank data breach.
Flagstar Bank suffered a MOVEit data breach via a third-party payment processor and mobile banking services provider, impacting over 800,000 customers in the US.
The Beanstalk attacker managed to get away with $80 million in illicit crypto funds, though the DeFi platform is looking at a total $182 million loss due to remediation and a sharp value drop that sent the token from $1 to 11 cents in value overnight.
A Cloudflare CDN flaw that can expose some location data to an attacker was patched before being ethically disclosed, but the security researcher that discovered it says that the trick still works with the use of a VPN service and some extra steps.
Preparing for a ransomware attack is by far the most effective way of minimizing the risk of becoming a victim. Herer are steps that can help tip the balance of power against potential attackers:
The New York Department of Financial Services (NYDFS) Cybersecurity Regulation blazed a trail in 2017, forming the basis for similar laws for other industries in other states. Currently, the regulation serves as a useful model for managing cybersecurity risks, regardless of industry.
By improving your overall security profile and demonstrating a low risk profile, you’ll be able to negotiate lower cyber insurance premiums and enjoy long-term savings.
Following Optus hack, the Telstra data breach appears to be limited to the signup process of a third-party rewards system for company staff, but two telcos losing personal information in two weeks has caused serious concern.










