Personal information of over 80 million U.S. households was exposed from an unsecured cloud database, while the owner of the database remains unknown.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Hackers compromised the Namecheap email system to send DHL and MetaMask phishing emails targeting wallet credentials. The company takes full responsibility after initially blaming a third party.
Nation state hackers have been launching phishing attacks against the Biden and Trump presidential campaigns, raising fresh alarm about their cybersecurity preparedness.
Stolen documents from Russia’s FSB indicate that the country is building an IoT botnet capable of gigantic DDoS attacks by rounding up millions of poorly-secured devices.
Two zero-day vulnerabilities in Ivanti products that were disclosed in January (and patched weeks later) have turned out to be the source of a breach of MITRE, the US government-funded cybersecurity research center. China's nation-state hackers are suspected to be behind the attack given similarities in exploiting these same vulnerabilities in other incidents, but this is not confirmed as of yet.
Recent federal directives on finding and reducing cyber risks correctly, along with the change from traditional cybersecurity methods to managing hybrid attack surfaces, show how complicated things are getting when it comes to federal cybersecurity.
Individuals have been getting notifications of their information being leaked to the dark web since the National Public data breach was announced. But the splashy claims about "every Social Security number" being exposed do not appear to be holding up.
Proposed bill in U.S. will require developers to provide warning labels for apps originating from countries considered as national security risks before consumers download them.
As businesses increasingly rely on Microsoft 365, ensuring the security of data and communications within the suite becomes a critical concern.
Hundreds of NATO documents of "extreme gravity" were reportedly stolen and made available on the dark web, and the Portuguese government is facing tough questions about why the breach was not discovered for weeks.










