Compliance requirements do not always reflect the complexities of new cloud systems or indicate where problems with traditional security approaches do not work as well for cloud security.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
CISA: Admin Credentials of a Former Employee Leveraged to Compromise a State Government Organization
The Cybersecurity and Infrastructure Security Agency (CISA) and Multi-State Information Sharing and Analysis Center (MS-ISAC) discovered that a threat actor compromised a state government organization using a former employee’s leaked admin credentials.
Data broker LexisNexis has disclosed a significant data breach that exposed the personal information of over 346,000 people after a threat actor compromised its GitHub account.
Historically, to become a successful hacker, you had to have the knowledge and skills to create your own attacks from scratch. However, all that has changed with the proliferation of the underground market for phishing-as-a-service.
Oracle Health data breach stemming from a legacy server affected multiple hospitals and healthcare organizations, potentially leaking sensitive patient information.
Fitness devices like Fitbit may no longer be used just for tracking physical health. U.K. researchers are looking into using fitness tracker technology to make people more aware of potential cyber threats and encourage them to take proactive action.
While the CFAA and all of its troubled language remains in place, the DOJ has announced that security researchers who do not have malicious intent do not have anything to fear anymore.
An update from Okta on its October customer support security breach indicates that the damage is worse than initially expected, with all of the recent users of its Help Center service now being told that the attackers likely stole their uploaded files.
A statement from TeamViewer indicated that the security breach was detected on June 26, and an employee account was apparently compromised as the APT group's source of access. There is not yet any mention of loss of data.
Report found that 43% of IT security professionals surveyed believe they are paying too much for their current SIEM solution relative to the system's capabilities and the value it brings the organization.









