The IoT Cybersecurity Improvement Act of 2020 is now federal law, meaning that US government "smart devices" will be subject to a new and more stringent set of security standards.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Study showed that most popular home routers contain known vulnerabilities in their firmware, with no security updates over the last 12 months for 46 out of 172 router models.
An SEC filing has revealed that GoDaddy suffered a data breach that impacts some 1.2 million of its current and former managed hosting customers. Wordpress users may have had their email addresses exposed.
The world’s third-largest cybersecurity company Fortinet has disclosed a data breach after a threat actor Fortibitch leaked 440 GB of the company’s allegedly stolen SharePoint data.
Big Data is revolutionizing how and why potential threats are detected, and demanding a substantial shift in next generation SIEM.
NATO is investigating an alleged data theft by a hacktivist group SiegedSec. 845 MB of compressed data was leaked and found to contain unclassified information and 8,000 employee records from 31 nations.
Anonymous officials from the Biden administration have told the New York Times that Chinese malware has been planted in the networks that control the critical infrastructure of military bases. The "ticking time bomb" could potentially cripple military systems in the event of a conflict between the two countries.
UK law enforcement has shared over half a million compromised passwords found in cloud storage with Have I Been Pwned. The headline item is that over one-third of these passwords (about 225 million) have not been logged before.
Panda Express, the largest Chinese fast food chain in the US, leaked sensitive personal data during the March 2024 cyber attack that affected the parent company’s corporate systems.
A new Russia-based family of malware has been observed using a large language model (LLM) to issue commands on compromised systems in real time, which can potentially improve attacker capability by allowing them to shift tactics during an attack without having to introduce new payloads.










