Cyber espionage campaigns focus on gaining access to journalist networks by impersonating legitimate members of the profession. The state sponsored hackers then hunt for useful geopolitical information.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Third-party access can quickly transform from an enabler of operational efficiency into a security strategy Achilles heel if an organization lacks an adequate third-party identity and risk management strategy.
A Quantum ransomware attack on Professional Finance Company (PFC) impacted 657 healthcare organizations and leaked sensitive patient data for millions of patients.
The FBI, CISA, and the Treasury Department warned about Maui ransomware attacks by state-sponsored North Korean hackers targeting US healthcare organizations.
Cyber attacks are using better research and personalization to find a way to take advantage of the senior level or C-Suite — and cybersecurity operations are falling behind in combatting these whaling attacks.
Attackers exfiltrated sensitive data from thousands of websites, desktop, and mobile applications in a supply chain attack leveraging typo-squatting in popular NPM packages.
An account takeover hit Disneyland's Facebook and Instagram, and the company took some of its social media presence offline for a short period as it recovered.
The Russia-Ukraine conflict has seen cyber warfare enter the mainstream and the risk of spill-over into unrelated businesses remains a possibility. Businesses should review their existing backup and recovery strategies and cyber incident response plans or they risk getting caught in the cyber crossfire.
Inside sources at Sky Mavis claim that the record-breaking Axie Infinity crypto theft from the company's Ronin bridge in March stems from a fake job offer made to one of the company's senior engineers.
More than ten years later, DevSecOps is still more of an idea than an effective practice. There is a better way to defend your cloud environment, and you can do it in three steps.









