MGM Resorts will pay $45 million to settle a consolidated data breach lawsuit stemming from a 2019 data leak and a 2023 ransomware attack that exposed the PII of 37 million people.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The Chinese hackers are able to run a massive but stealthy campaign of password-spraying attacks while evading logs, targeting Microsoft 365 accounts that require only basic authentication and do not have MFA enabled.
The new Microsoft security initiative update promises more sweeping changes. This move is also likely tied directly to the company's security woes and issues with cyber threats in 2023 and early 2024.
Microsoft says its Azure cloud platform was hit by the largest of its kind DDoS attack from a Turbo Mirai-class IoT botnet, Aisuru, harnessing over 500,000 residential IPs.
Microsoft has banned the developer accounts of high-profile open-source projects, leaving them unable to publish software updates, exposing Windows users to various cyber threats.
Cybercriminals inserted malicious ads into Microsoft Bing Search AI chatbot to trick unsuspecting users into downloading trojanized software from spoofed domains.
Security firm disclosed a Microsoft data breach that exposed customer data affecting over 65,000 organizations in 111 countries. Microsoft expressed disappointment at the security firm for exaggerated numbers and releasing a search tool.
Nation-state attacks on critical infrastructure and cyberespionage, and password attacks from ordinary cybercriminals increased tremendously within a year, according to Microsoft report.
Microsoft says many IoT and operational technology devices suffer from 25 IoT security critical vulnerabilities originating from vulnerable SDKs, RTOS, and the C standard library.
Microsoft detected a second hacking team targeting Orion software and running its campaign parallel to the Russian hacking group; SolarWinds acknowledges the threat.










