A new report from Mandiant indicates that 70% of 2023's total of 138 exploited vulnerabilities were zero-days when first used, with the average time-to-exploit (TTE) dropping drastically from 32 days to just five.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The SolarWinds hackers (thought to be backed by Russian intelligence) are up to their old tricks with new cloud providers, and have reportedly already breached a number of companies.
Manpower has confirmed a significant data breach affecting one of its independent franchises after a prolific ransomware threat group claimed to have exfiltrated the entire company’s data.
There are various cyber attack vectors for the maritime industry which could result in taking full control over a vessel or fleet or creating damage to critical systems on board.
Marks & Spencer shut down its systems after experiencing an apparent ransomware cyber incident that disrupted order collections and contactless payment.
The sensitive personal and financial information of 672,075 people was compromised during the August 2025 Marquis cyberattack, which was previously misattributed to a Russian ransomware gang.
Marriott International has approved a $52 million FTC settlement to conclude an investigation into over half a decade of data breaches that rocked the hotel franchise.
Marriott suffered its second large data breach through two employees’ login credentials that exposed personal information of 5.2 million guests from their customer loyalty accounts.
While 79% of respondents in recent Marsh and Microsoft survey ranked “cyber risk” as a top risk management concern, only 17% of C-suite or board members spend more than a few days per year focusing on it.
A massive data leak of 2.87 billion X/Twitter profiles, more than four times the site's current active monthly user estimate and likely including most going back to the creation of Twitter, may have been the work of a disgruntled former employee laid off during Musk's takeover of the company.










