Colorado Department of Higher Education (CDHE) has suffered a massive data breach leaking sensitive personal information of current and former students and educators spanning over a decade.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Data dump containing 269 GB of police files from hundreds of U.S. law enforcement agencies and the FBI is found to be tied to a breach at a shared third-party vendor.
An adware campaign involving over 60,000 Android apps has infected devices since October 2022. Researchers warned that the infected Android apps could start distributing potent malware, including credential stealers, banking trojans, and ransomware.
Two-thirds of breaches are inside jobs. Yet, insider threat programs account for less than 10% of the budget. Are enterprise cybersecurity efforts properly prioritized?
Sprint claims recent data breach will not cause risk to fraud or identify theft but the compromised customer information could lead to SIM swap attacks and allow attackers to take over victim’s accounts.
The economic landscape requires due diligence when it comes to enterprise level SaaS spending. Shadow IT hides wasteful spending, and organizations must manage costs associated with bulky and hidden SaaS platforms.
A sophisticated vishing attack by the suspected ShinyHunters cybercrime gang has leaked business contact information from the New York-based ad tech company Optimizely.
CISA published an insight document for critical infrastructure organizations to prepare for the transition to new post-quantum cryptography standards that NIST will announce soon.
Apple argued that Corellium's use of its software constituted a copyright violation; a federal judge has disagreed, throwing the case out on the basis of the company's software being a tool for security researchers.
An as-of-yet undiagnosed compromise of the Salesloft Drift AI-driven platform has led to a rash of stolen OAuth tokens, in turn creating downstream breaches at some of the biggest names in the cybersecurity industry.










