Tripwire's latest survey highlights that shortage of cyber security skills is exposing an organization's vulnerabilities, leading to increased outsourcing.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
There’s no doubt that MSSPs have a core role to play in mitigating the cybersecurity skills shortage and that automated technologies will be central to that. But they need to move beyond automating the routine and look at how they can automate more complex asks.
German banks Deutsche Bank AG, ING, Postbank, and Commerzbank’s subsidiary Comdirect, have leaked customer data via third-party service provider MOVEit data breach.
Data leak occurred when a sensitive document was mistakenly shared in connection to a freedom of information request, and takes place amidst a backdrop of increased tensions and fears of terrorism that have been growing since early 2023.
There has been considerable debate about banning ransomware payments as a means of curbing the explosive growth of the crime Assistant director of the FBI's cyber division weighed in, suggesting that it would create a new avenue of extortion.
Secure remote working procedures will be a high priority for all types of organizations after COVID-19 as many employees continue to work outside of the traditional office.
Online businesses must prioritize credential stuffing mitigations by detecting and preventing automation in credential stuffing, and identifying compromised credentials of legitimate users and forcing them to change password to disincentivize the attackers and break the attack lifecycle.
Cyber espionage hackers target Czech antivirus software company Avast's CCleaner product with more than 435 million users in 68 countries in an attempted supply chain attack.
FBI is issuing more cyber security alerts than usual, covering human trafficking, COVID-19 scams, vulnerabilities in networking platforms and cloud-based business email compromise campaigns.
Security researchers have discovered an EvilProxy phishing campaign targeting 120,000 Microsoft 365 users with a focus on business executives with access to financial assets or sensitive information.










