The speed at which applications are developed and deployed means businesses must move quickly to meet customer needs. While this is transformative for the development side of the house, security teams have been unable to keep up.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Several New Zealand government agencies were impacted by a ransomware attack on Mercury IT, a 25-employee firm that serves dozens of public and private organizations in the country. New Zealand’s Ministry of Justice and Health New Zealand (Te Whatu Ora) have confirmed being impacted by the cyber incident.
The Uber data breach resulted in the theft of a variety of internal company information, and stemmed from a third-party vendor. The thieves also got away with source code and employee personal information.
Security vulnerabilities in languages like PHP, Python, and Java may involve updating the language. The problem is that when a language level update is released, it traditionally does not simply address security issues – it introduces other, unrelated, language changes which may break existing code.
The holiday season is rapidly approaching, and with it, a surge in hacker activity. The massive increase in online shopping around the holidays offers hackers ample opportunity to deceive shoppers with social engineering attacks like phishing campaigns.
Our increasing reliance on SaaS apps is leading to data being left unsecured and vulnerable – and malicious actors know this. The key to safeguarding the data you store on SaaS apps is understanding how the Shared Responsibility Model (SRM) works.
A combination of EASM with CMDB delivers real-time visibility of the entire stack. Previously unknown or unmanaged assets come into focus and automated workflows weed out vulnerabilities at scale, which simplifies the previously overwhelming proposition of exhaustive investigation and patching, asset by asset.
Security researchers discovered an Android malware active since 2008 in Google Play Store and third-party app stores stealing Facebook logins of 300,000 users in 71 countries.
You can’t control bad actors targeting your brand and customers. What’s most important is to ensure that you’re monitoring for the abuse of your brand online so that you can take action as quickly as possible to disrupt impersonation attacks before your brand falls victim.
Cyberattack methods are constantly changing as criminals find new ways to automate breaches, crack strong networks, and target vulnerable systems. From a growing need for intelligence-led security to increased infrastructure protections, organizations must look years into the future to stay ahead of the attacks of tomorrow.










