The US Cyber Command is expecting the TrickBot botnet to be involved in election interference attempts, and is actively running persistent operations against it along with Microsoft.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A joint operation by Meta and law enforcement authorities from 10 countries has taken down 150,000 scam accounts and nabbed 21 suspected masterminds of online fraud.
Russian hackers affiliated with the Killnet group executed a DDoS cyber attack that rendered 20 Japanese government websites inaccessible, including a tax and an e-Government portal.
A recent audit of websites by the well-known Online Trust Alliance has revealed something that many consumers have long suspected. Financial institutions are the least trusted when it comes to cybersecurity. Although the results are no doubt coloured by the inherent fear that many consumers have when it comes to the security of their money, it should still be a worry for banks which have long struggled with issues around online trust.
Botnet discovered by Chinese researchers introduced a backdoor and a web shell on compromised AT&T VoIP servers, mostly in the US, for DDoS attacks and data exfiltration.
The BlackByte ransomware gang's "2.0" reboot of their data leak site sports a new "feature" for its victims: a tiered payment system that allows for smaller payments to delay publication of sensitive data, or to simply download and recover it prior to having it dumped for public viewing.
Russia has been making news for hacking utility systems in other nations and for a change, news has emerged that U.S. is conducting cyber attack on power grid in Russia by planting malicious code.
Tripwire's latest survey highlights that shortage of cyber security skills is exposing an organization's vulnerabilities, leading to increased outsourcing.
Popular collaboration tool Slack is the latest to suffer a security breach involving its GitHub repositories, with the company reporting that private source code was stolen in late December.
Authorities in the U.S. and Australia have warned that the BianLian ransomware gang has abandoned the double extortion model for purely data extortion attacks. More groups are likely to follow suit and forego the hassle of developing and managing the encryption and decryption process in favor of a less complicated attack,










