T-Mobile appears to have suffered a devastating data breach as a reported 100 million records have appeared for sale on a dark web forum. The customer data is about as sensitive as possible, containing accurate Social Security and driver's license numbers.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
5G technology plus 74 billion IoT devices estimated by 2025, it’s no surprise that IoT security is one of the top concerns keeping many executives up at night.
Sony Interactive Entertainment has confirmed a MOVEit data breach that leaked the personal information of current and former employees and their family members.
The Department of Homeland Security (DHS) has issued a bulletin to law enforcement agencies warning that Russian cyber attacks in the US are possible if Ukraine is invaded.
Fujitsu is investigating a cyber attack that potentially leaked sensitive personal information after its work computers were infected by malware.
There are various cyber attack vectors for the maritime industry which could result in taking full control over a vessel or fleet or creating damage to critical systems on board.
Chinese malware deployed by a state-sponsored advanced persistent threat group is targeting critical industries and their downstream customers in a prolonged cyber espionage campaign.
DHS has published a security advisory that confirms a ransomware attack on critical infrastructure and provides recommendations for other operators to take precautions.
While roughly half of all businesses are using some type of monitoring tool to detect insider threats, the truth is that none of the most commonly deployed solutions can entirely prevent leaks of sensitive documents.
F5 Labs says web application security is the greatest cybersecurity challenge, and the cause for more than half of all the largest software security incidents experienced over the last 5 years.










