With roughly 70 percent of travelers unknowingly engaging in risky behaviors that could expose them - and their employers - to cyberattacks, travelers will need to add cybersecurity to their packing list in addition to sunscreen and passports.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Cloud infrastructure provider Digital Ocean severed ties with the marketing automation provider Mailchimp after a security breach exposed its customer email addresses.
A shocking whistleblower report from Peiter ‘Mudge’ Zatko, a well-known cybersecurity expert who served as Twitter's head of security from mid-2020 to early 2022, asserts that the company is "grossly negligent" in "several areas" of information security and privacy protections.
Online businesses must prioritize credential stuffing mitigations by detecting and preventing automation in credential stuffing, and identifying compromised credentials of legitimate users and forcing them to change password to disincentivize the attackers and break the attack lifecycle.
The shift to cloud-based collaboration platforms, the amount of sensitive data that is now stored and communicated on those platforms, and the level of trust that people put into communication on those platforms have an inevitable conclusion: we are going to see more attacks on those platforms.
The BlackByte ransomware gang's "2.0" reboot of their data leak site sports a new "feature" for its victims: a tiered payment system that allows for smaller payments to delay publication of sensitive data, or to simply download and recover it prior to having it dumped for public viewing.
UK water supplier, South Staffordshire PLC, suffered a Clop ransomware attack during one of the country’s worst droughts, with the gang mistakenly identifying another water utility as the victim.
While cryptocurrencies have gone from red hot to full on meltdown in recent months, threat actors don’t show any signs of shying away from finding new and innovative ways to pursue this lucrative and relatively new financial category with increasingly complex and stealthy crypto-stealers.
Twilio said that the data of 125 customers was accessed by the threat actors for some amount of time. Privacy messaging app Signal has indicated that the attackers had some level of access to about 1,900 registered phone numbers.
An organization’s information security traditionally fell to specific job titles. In some cases, this may be a simple IT administrator for many smaller organizations, while larger organizations may have a full dedicated team. Today’s new security structure leverages all levels of an organization.










