A joint FBI and CISA alert warned that hackers were exploiting Fortinet’s VPN vulnerability and the Microsoft Zerologon bug to compromise government networks hosting election systems.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Researchers discovered apps infected with Joker malware on Huawei’s AppGallery. The affected apps subscribe users to mobile premium services and were downloaded more than 500,000 times on Huawei Android phones.
Asian food giant Jollibee is investigating a data breach that impacted at least 11 million customers and other restaurants, including Burger King and Panda Express.
Law firm associated with Donald Trump and half of Fortune 500 companies leaked 100 GB of confidential client information in a third-party data breach linked to Clop ransomware.
Opet notes that the SaaS model is usually the default option for whatever software a company might need, and often is the only option available. That means a global concentration of risk such that numerous third-party security breaches could cascade.”
A data breach at SitusAMC has affected several major US banks after attackers breached the finance technology company’s network.
Twitter hack report reveals that employees were tricked into visiting a phishing page that captured their VPN credentials, a technique that worked due to move to remote working during the pandemic.
Further review of the information leaked in the recent Disney data breach has turned up sensitive and detailed financial and business strategy information, according to a new report from the Wall Street Journal.
Researchers warn that financial institutions must innovate to prevent online payment fraud losses, which are expected to exceed $343 billion between 2023 and 2027.
As the number of machines grows to the tens of billions, security needs to catch up to this rapid growth with the intelligence and automation necessary to manage thee machine identities of these critical security assets.










