F5 has disclosed that an August breach exposed source code and customer data to what it calls "nation-state hackers." The company has not made an official attribution, but third-party security researcher sources are linking the attack to China's UNC5221.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Businesses are turning to Zero Trust security with multi-factor authentication as a step towards passwordless, which is a key factor in an identity-first cybersecurity strategy.
The FBI confirmed that North Korea’s state-sponsored hacking group Lazarus carried out the $100 million Horizon bridge crypto theft. The agency said it successfully stopped the transfer of some stolen assets and subsequently published wallet addresses with purloined cryptocurrencies.
On May 19 GitHub confirmed the security breach across its social media channels, verifying that there was unauthorized access to internal repositories and stating that it was monitoring the situation for further activity. It also said that it had no evidence that information stored in customer repositories or internal information about customers was compromised.
Having hundreds or more enterprise data sources to monitor a company’s security is overwhelming and unmanageable for SecOps, what they really need is a “small data” movement.
Code signing is like a virtual mechanic, ensuring trust across the software supply chain by validating the identities of source code and verifying that it hasn’t been tampered with. Code signing isn’t new, but it has changed.
Dropbox says that the security breach did not involve the contents of any customer accounts. The attackers were instead focused on company GitHub repositories, raiding 130 of them for code and tools.
Report prepared by the New York Cyber Task Force examines the leading cyber defense challenges and finds that coordination between government agencies and private business must be revamped.
Tornado Cash said that the OFAC sanctioned address that was being used to process the $625 million stolen from NFT game Axie Infinity's Ronin bridge had already been blocked.
A 19-year-old "security specialist" has found a vulnerability in third party software used by certain Tesla vehicles, which allows the remote control of certain functions such as the engine and the security system.










