Security researchers have discovered a network of over 3,000 GitHub accounts involved in an extensive malware distribution campaign.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A ransomware attack on fintech firm Marquis Software Solutions has impacted at least 74 banks and credit unions across multiple states, leaking customer data of over 400,000 people.
The attack the food delivery company DoorDash appears to have been part of the ongoing "0ktapus" campaign, which first made news when it ensnared Twilio. Customers may have had contact information exposed along with order information and partial credit card information.
The cybersecurity workforce has grown by a little over 11% since last year, filling 464,000 more positions, but the workforce gap has more than doubled during that time due to increased demand.
Snake oil marketing tactics by cybersecurity vendors complicate organizations’ security stack and expand the attack surface, according to Egress cybersecurity hype report. 91% of decision-makers found it difficult to select cybersecurity vendors due to unclear marketing about their specific offerings.
To ensure that the patient information being generated, stored and exchanged is secure, healthcare organizations are rapidly implementing mobile device management (MDM solutions) to push extensive security policies and tailor the usage of their diverse types of devices to ensure that the data stored on them is secured efficiently.
Companies with significant amounts of sensitive stored data – whether stored on site or in the cloud -- should begin to invest in emerging quantum-resistant data storage, key management, and multiple encryption technologies.
The CISA 2026 budget cuts would be accompanied by a reduction of 1,083 CISA positions, a cut of almost a third of its present count of 3,292 employees. The Cyber Defense Education and Training program would also be gutted, with the budget proposal suggesting that it could be replaced by free resources.
CISA added single-factor authentication to bad cybersecurity practices, adding that it was extremely risky for remote and administrative access to critical infrastructure.
The NSA urged developers and organizations to switch to memory-safe languages to address memory safety issues responsible for most exploitable vulnerabilities. Microsoft and Google attribute 70% of some of their product vulnerabilities to software memory safety issues.










