Companies are facing a new “shadow IT” pandemic during COVID-19 as employees are finding their own solutions to information technology problems that often violate existing security policy.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Outsourcing business model creates a reliance on third parties and increases security risks as more companies have access to the same information that was previously kept within a company.
Whatever new technologies are adopted, social engineering will evolve in parallel and find work arounds. Even as these security defenses mature, it will always be easier to hack a human than hack a system.
As the use of cloud has grown and matured, so too has the recognition of a need for financial discipline in its management. In much the same way that DevOps applies a developer perspective to IT operations, FinOps will apply financial rigor to cloud.
The FBI confirmed that North Korea’s state-sponsored hacking group Lazarus carried out the $100 million Horizon bridge crypto theft. The agency said it successfully stopped the transfer of some stolen assets and subsequently published wallet addresses with purloined cryptocurrencies.
UK retailer the Co-op has confirmed and apologized for the data theft stemming from a cyber attack on its systems, claimed by the Dragonforce ransomware operation.
Scattered Spider, ShinyHunters, and LAPSUS$ are the three groups involved, and have collectively been the most active of the major cybercrime gangs over roughly the past year. The groups all had prior ties via "The Com," a broader collection of cyber criminals that loosely affiliate and come together for singular projects in a fluid way.
Toyota has confirmed a third-party data breach that leaked 240 GB of sensitive information on the dark web, but says the cybersecurity incident was grossly misrepresented.
A zero-day vulnerability that has been with iOS since the first iPhone launched has been identified and patched out by Apple, but with the warning that there is evidence it has been exploited in attack chains for quite some time.
A hacker is claiming to have stolen over one billion user records, but security researchers are not convinced that this came from a legitimate TikTok hack or that account takeovers were involved.










