U.S. Insurance giant American Family Life Assurance Company (Aflac) suffered a cyber attack that exposed extensive sensitive information, including SSNs and health information.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
In mid-July the REvil ransomware group, linked to the Kaseya and JBS incidents among other attacks, appeared to go out of business. It turns out they may have just been taking a refreshing summer break.
A considerable chunk of the Conti ransomware gang's internal communications is now available due to a data leak, and may threaten the future of the group.
The Office of the Attorney General of New York has recorded 1.1 million compromised accounts. The stolen logins were put to use in credential stuffing attacks against a variety of "well-known" online retail, food and delivery businesses.
U.S. commitment to defend Japan in the face of cyber attacks and rise of offensive cyber maneuvers is signalling a commitment to international response and a broad sea change in foreign policy.
The gist of the RubyGems cyber attack is that the AI agents uploaded "hundreds" of malicious packages to the platform and also made attempts to capture user credentials. This took place beginning on May 11, about two months before the Hugging Face cyber attack would dominate cybersecurity news and raise alarms about frontier AI capability.
Testing of frontier AI agents by the UK’s AI Security Institute (AISI) found that "autonomous, unsanctioned action" took place on the open internet in about 1 out of 12 runs, with the agents cited as attempting to socially engineer humans into taking action and in at least one case attempting to hack an open-source project using a variety of different approaches.
The integration of AI into cybersecurity has evolved significantly. Initially, AI assistants primarily supported threat research and rapid intelligence processing,...
A security breach affecting the AI aggregator platform OmniGPT has leaked the sensitive information of 30,000 individuals including API keys, chat logs, and uploaded files.
AI autonomy has redrawn the security battlefield. What was once human versus human is now AI against AI, with both attackers and defenders wielding machine power.










