A spyware vendor in Spain has been linked to a zero-day exploitation framework that impacted Windows, as well as the Chrome and Firefox browsers, from 2018 to 2021. Google researchers present markers found in its code including a script that is signed by the company.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The time is now for business leaders to implement zero-trust protocols to address cloud misconfigurations beyond the identity layer and into the SaaS app ecosystem, as doing so has become critical for organizations to be able to maintain a good security posture. Zero Trust Data Access (ZTDA) does just that.
Cyber leadership is currently based on individual best effort, with no agreement on what ‘good’ looks like, with Chief Information Security Officers (CISOs) typically blinkered on the implementation of controls rather than understanding the risks to the business and driving cultural change accordingly.
The battle against Log4Shell is proceeding very slowly due to a confluence of factors. It remains buried in a number of assets, particularly legacy systems that are tougher to address. But it also continues to affect organizations via new devices.
UK MSPs will be brought under the same cybersecurity laws that govern essential services, such as critical infrastructure and health care. The move stems in large part from an increasing focus on MSPs by the most advanced nation-state security actors.
Ragnar Locker ransomware gang targeted the municipality of Zwijndrecht but instead hacked a local Belgian police unit, releasing sensitive police data, including investigation reports and criminal records.
Apple, Google and Microsoft have been working closely with the FIDO Alliance to introduce passkeys, which are a much more secure and effective successor to password-based security. This commitment is likely to drive a rapid change in consumer behavior and expectations. But will other enterprises be ready to respond?
Security leak of manufacturing keys from major device producers (such as LG and Samsung) allows signing of malware apps, providing full access to an Android device, as the operating system trusts any signed app with complete system-level access.
One of the few significant holes in Apple's end user security is set to be addressed, as Cupertino has announced plans to introduce end-to-end encryption to iCloud backups. A feature Apple has delayed due primarily to pressure from US federal law enforcement agencies.
The economic landscape requires due diligence when it comes to enterprise level SaaS spending. Shadow IT hides wasteful spending, and organizations must manage costs associated with bulky and hidden SaaS platforms.










