Hackers compromised streaming giant HBO’s Reddit account to deliver ClickFix malware targeting both Windows and macOS in PasteSwitch social engineering campaign.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A recent confirmed T-Mobile hack has been attributed to Salt Typhoon, the Chinese cyber espionage team that also breached Verizon and AT&T earlier in the year. That means the hackers were able to penetrate all three of the country's major mobile carriers in 2024.
In military parlance, the phrase “when the balloon goes up” refers to the moment when hostilities with an adversary are imminent. The Chinese spy balloon that sailed over the continental United States signifies something different: a vast—and increasingly brazen—penetration of American networks and communications systems.
Recent FBI Flash notification warns that 52 critical infrastructure firms have been hit by Ragnar Locker ransomware as of January 2022 and remains a serious threat, with considerable penetration among critical infrastructure companies.
Secure remote working procedures will be a high priority for all types of organizations after COVID-19 as many employees continue to work outside of the traditional office.
Natural gas supplier Superior Plus suffered a ransomware attack that knocked its systems offline although customer safety and security and personal data were not affected.
Web3 cannot get away from Web2, and it means that businesses are going to have to find a way to marry two very different approaches to security to ensure the safety of their users in the era of decentralization.
Zero Trust has reached buzzword status in the security industry. But, unfortunately, many vendors that claim to provide Zero Trust solutions fall short of addressing all critical components.
The battle against Log4Shell is proceeding very slowly due to a confluence of factors. It remains buried in a number of assets, particularly legacy systems that are tougher to address. But it also continues to affect organizations via new devices.
The annual ENISA threat landscape report is one of the most helpful tools for keeping a finger on the pulse of current trends in cyber threats. This year's report highlights the dramatic rise in denial of service and cryptojacking attacks.










