Attackers exfiltrated sensitive data from thousands of websites, desktop, and mobile applications in a supply chain attack leveraging typo-squatting in popular NPM packages.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
By searching the internet, hackers have begun hijacking smart building access control systems to recruit these IoT devices into botnets for launching DDoS attacks.
Malicious actors are using deepfake videos impersonating YouTube’s CEO to steal users’ credentials in a multi-month phishing campaign. The attackers sent private videos to targeted users via legitimate-looking emails, warning them that YouTube was changing its monetization policies.
The campaign was conducted by malicious hackers who sold the stolen credentials off, with much of the info being put to use in spam and phishing campaigns. The attack simply made use of open-source tools to scan IP ranges for potentially vulnerable Git config files.
The FBI arrested and charged a New York man Connor Brian Fitzpatrick with cybercrime. Connor is alleged to be the hacking forum “BreachForums” owner and operator, Pompompurin.
A leak on a hacking forum that exposed internal AMD data appears to have been confirmed by the company, as it acknowledged that an unnamed third-party vendor involved in product assembly was breached. Questions remain about the extent of the data breach, however.
Okta has about 15,000 clients and provides authentication services for remote logins, usually for employees and students. A known security breach took place in January, but LAPSUS$ says this is something else.
Hacking group ShinyHunters released Pixlr's 1.9 million stolen user credentials on a hacker forum. The data was accessed from an AWS S3 bucket while breaching sister site 123rf.
Whatever new technologies are adopted, social engineering will evolve in parallel and find work arounds. Even as these security defenses mature, it will always be easier to hack a human than hack a system.
As our vehicles become increasingly smarter and an extension of our mobile phones, users' security and privacy is being threatened by car hacking. Luckily, there are relatively simple measures you can take to protect your vehicle data, safety and security.









