Healthcare web application attacks increased by 51% since the introduction of COVID-19 vaccines. Cross-site scripting (XSS) and SQL injections were the most detected by volume.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
While the transition to passwordless security procedures is already underway, adoption is still limited mainly in larger companies in certain industries. There are many steps that can (and should) be taken to accelerate the authentication journey to make passwordless authentication mainstream.
In yet another blow to Facebook, the latest Instagram breach exposed sensitive data of at least 49 million users when an AWS database was found online without a password for at least 72 hours.
Entire populations are being manipulated through increasingly prevalent and hyper-compelling information typically spread via social media, designed to invoke emotion and exploit known biases and provoke a tsunami of misinformation.
A trend is growing where online travel agencies and travel aggregators are unleashing armies of bots to run price scraping operations which may in certain cases, hoard tickets and prevent humans from making travel arrangements.
Oracle Health data breach stemming from a legacy server affected multiple hospitals and healthcare organizations, potentially leaking sensitive patient information.
The secret order, issued in late November, would have made India’s security app a mandatory inclusion on all new devices from smartphone makers within 90 days. Smartphone makers would have also been required to push it to older devices that are still supported via a security update.
AI deepfakes were used to contact three foreign ministers, a US Governor, and a member of Congress around the middle of June via the Signal messaging app. Two of the officials received fake voicemail messages mocked up to use Rubio's voice, and another received an invite to join a chat.
While modern collaboration communications tools have helped business continue during a time when face-to-face meetings are impossible, they can also increase the risk of data breaches and regulatory compliance violations.
The new “agentjacking” attack takes almost no real hacking ability to pull off. It's predicated on pulling a public credential that can readily be found in a web site's JavaScript source code, which can be used by anyone to get Sentry to accept an error event full of malicious instructions that is passed on to AI coding agents.










