A major threat actor has been crippled by an international law enforcement action, as the Lumma infostealer malware operation saw its control panel seized along with infrastructure dwelling in Europe and Japan. This was supplemented by Microsoft seizing some 2,300 domains belonging to the group, which has infected over 394,000 Windows computers globally.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A ransomware attack at the University of Hawaii Cancer Center has exposed the sensitive personal information of more than 1.2 million people, forcing it to pay a ransom.
The Biden administration will sign an executive order to bolster port cybersecurity with additional actions to enhance maritime cybersecurity, secure supply chains, and strengthen the US industrial base.
Report found that API security was a major concern for businesses as malicious traffic grew triple that of legitimate sources and causing delays in application rollout.
T-Mobile has begun notifying 37 million prepaid and post subscribers whose personal information was accessed by unauthorized bad actors in an unsecured API data breach.
Credit monitoring giant TransUnion has suffered an apparent Salesforce data breach, affecting over 4.4 million people, with ShinyHunters claiming responsibility.
Microsoft reports a long-term campaign by Chinese hackers that has burrowed into a number of different aspects of US critical infrastructure, with the eventual goal being the creation of a system of widespread disruption that could be 'switched on' during another global crisis or a conflict between the two nations.
The UK financial regulator found that cyber insurance firms "mostly" weathered the stress test, in the sense that only a small number reported concluding the scenario with an amount of funds on hand that would put them beneath national solvency capital requirements.
The Hydra darknet market with an estimated annual turnover of $1.35 billion was taken down. It had about 17 million users and 19,000 registered seller accounts prior to the bust.
For connected medical devices, cyberattacks are a massive threat to patient safety. As BLE connectivity for IoMT devices becomes more prevalent, protocol fuzzing validation will become even more critical in maintaining patient safety and trust in advancing technologies.










