Hive ransomware group claimed responsibility for the cyber attack on Tata Power and began leaking stolen data, including sensitive employee and company information after ransom negotiations had conclusively failed.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Hive ransomware, one of the biggest ransomware-as-a-service (RaaS) strains circulating since 2021, has at this point brought in $100 million in ransom payments and the total victim count is at least 1,300 organizations.
The Hive ransomware threat appears to be very much in retreat as the US Department of Justice recently announced the seizure of the group's decryption keys and infrastructure, including its public-facing website, by law enforcement operations.
A zero-day windows vulnerability HiveNightmare leads to local privilege escalation, exposing system files, registry, and SAM database to non-admin users.
Even with 64% of cloud security incidents stemming from unauthorized access, businesses are still underestimating access security with only 7% of security leaders citing account takeovers as top risk.
Russian hackers have been kicking up ransomware attacks to exploit new work habits leaves many companies needing to rethink how they approach security.
Home security company ADT has confirmed a data breach stemming from unauthorized access to a customer database after a threat actor listed the stolen database on an online hacking forum.
Suspected Snake ransomware attack on Honda highlighted the need for network segmentation to prevent impact across a company during an attack.
Hong Kong-based Mixin Networks, a decentralized exchange and cross-chain transfer network, was temporarily forced to suspend operations following a hack of its cloud database. The crypto company is offering a $20 million bug bounty for full return of the stolen funds.
A Hong Kong deepfake scam that netted HK$200 million made use of a fake video conference with multiple company executives. The employee that was targeted reportedly did suspect fraud at first, but nevertheless ended up making a total of 15 bank transfers.










