A recent surge in phishing messages by profit-seeking criminal hackers has been tied to OpenAI tools, but a new report from Microsoft finds that state-sponsored hacking groups are making of use of these new AI abilities as well.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Microsoft's threat research team says that the Chinese hackers breached at least two dozen organizations in total, including government email accounts at multiple federal agencies. Campaign reportedly began in mid-May.
Microsoft has experienced another security lapse after inadvertently exposing employee credentials for accessing internal databases and systems via an unsecured Azure cloud server, which was accessible over the public Internet without a password for nearly a month after discovery.
Spyware campaign stole sensitive user information through 111 fake Google Chrome extensions which gathered over 32 million downloads on the Chrome Web Store.
The US Secret Service is now pointing the finger at state-backed Chinese hackers, accusing a known advanced persistent threat group APT41 of stealing about $20 million of US Covid benefits during the pandemic.
Security researchers discovered 33 vulnerabilities in millions of devices using four popular open-source libraries. The bugs allow attacks, including remote code execution and DDoS.
Despite the NSA warning of hackers exploiting bugs such as Bluekeep and Heartbleed vulnerabilities and updates being released, millions of vulnerable systems remained unpatched.
Mimecast’s forensic investigation found that SolarWinds hackers accessed limited source code repositories and account details after compromising customers' Microsoft 365 tenants.
Only one third of respondents to a recent survey include business-critical systems, like SAP, in cybersecurity monitoring. And one third of those who do include SAP in security monitoring do not review SAP logs for potential cyber threats.
The best way to deal with a vulnerability is doing what you can to prevent them from happening in the first place. Oftentimes, cyber risk can be managed even through simple and basic security hygiene practices.










