To address supply chain attacks, the latest Firmware Integrity Measurement (FIM) specification, released by Trusted Computing Group, provides a framework to establish the integrity baseline of the firmware running on a device at the manufacturing stage.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Fraudsters stole at least S$8.5 million from OCBC Bank customers through fake SMS impersonating the bank. OCBC warned of increased phishing scams in December 2021.
Work from home has quickly taken over in many enterprises due to the recent crisis. However, a majority of enterprises forced into the remote work paradigm were unprepared at an infrastructural, policy, and cultural level.
Quantitative cybersecurity budgeting helps security professionals properly translate security risks into business risks and demonstrate how cyber risks impact the organization as a whole – which are key to getting buy-in from non-technical stakeholders.
Positive Technologies found that cybercriminals can penetrate 93% of company networks, disrupt processes and services, steal funds and data, while insiders can breach 100% of networks.
Ethereum DeFi system Polygon has announced that it patched a critical vulnerability that stood to put some $24 billion of its MATIC coins at risk. The company kept the issue quiet for weeks as it worked to patch it out.
To properly address the new breed of cyber threats, we must approach network protection from a more foundational level. Protective DNS (PDNS) solutions use the Domain Name System to alert and/or block communication with domains associated with bad actors.
ReasonLabs researchers warned that a 'Spider-Man: No Way Home’ illegal download was a torrent malware containing a persistent Monero crypto miner.
While providers are doing their best to ensure the security and integrity of their cloud software, there are also some steps that businesses can take to mitigate any cloud-associated risks. Let’s take a look at some of the most important things to consider when it comes to cloud-based platforms and risk mitigation.
CISA released its customized Log4Shell scanning solution and a list of other third-party scanners. However, all the Log4j scanners tested by Rezilion failed to detect all file formats.










