Lapsus$ hackers compromised Microsoft's Azure DevOps Server, exfiltrated and published source code for the company's web infrastructure, websites, and mobile apps.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Lapsus$ hackers repeatedly accessed T-Mobile's internal systems, including Atlas account management system capable of SIM swapping, and downloaded thousands of source code repositories.
Globant SAS confirmed a data breach affecting a "limited" number of customers after Lapsus$ hackers published 70GB of source code allegedly stolen from the company. Screenshots suggested that the leaked customer source code belonged to companies like Apple, Facebook and DHL.
Panda Express, the largest Chinese fast food chain in the US, leaked sensitive personal data during the March 2024 cyber attack that affected the parent company’s corporate systems.
The Japanese port of Nagoya suffered a ransomware attack that impacted the central computer system and disrupted cargo operations, causing temporary congestion. LockBit 3.0 has claimed responsibility.
Thanks to some unsecured public-facing databases, Verifications.io email data breach has set a new record for leaking 2 billion personal records which can be useful for identity theft and scams.
NFT marketplace OpenSea acknowledged a data breach after an employee of a third-party email delivery vendor downloaded email addresses and shared them with an unauthorized party.
With the doubling of security vulnerabilities found in popular open source projects between 2018 and 2019, many are concerned on the record being broken again in 2020.
2019 password security report shows that even though businesses are increasingly adopting MFA and password generator solution, the passwords are still not strong enough or being reused between different accounts.
Password Manager LastPass says no master password was compromised after multiple users received unauthorized login alerts. The company blamed credential stuffing and system errors.










