European Court of Auditors recently released a comprehensive report detailing the cybersecurity challenges facing the European Union in 2019 and beyond, and how best to respond to the growing number of cyber threats.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
California is now leading the charge to beef up the cyber security features of connected devices by banning weak passwords, forcing device manufacturers to supply a unique password or force a password change on startup.
A new draft China cybersecurity law could restrict certain U.S. companies from doing business in the country which clearly represent a tit-for-tat in the escalating trade and cyber war between U.S. and China.
A new joint alert from CISA and the FBI seeks to assist private sector software developers in removing XSS vulnerabilities from their products, with a basic overview of best practices aimed primarily at executives and business leaders.
CISA notified 93 critical infrastructure organizations of the presence of a vulnerability that could lead to ransomware attacks, and plans to scale up the program and provide more warnings in the coming months.
Unit 29155's actions since 2020 include cyber attacks on a number of federal agencies and critical infrastructure companies in a variety of countries. But the group seems to have switched most of its focus to Ukraine in the weeks prior to the 2022 military invasion.
A new CISA-NSA joint report follows many calls by both members of the cybersecurity industry and government agencies for a transition to memory-safe languages like Rust, Ruby, Java and C# due to their inherent minimization of memory-related classes of vulnerabilities.
One key finding from CNCERT report shows most cyber attacks are using U.S. servers to implant viruses and carry out botnet attacks against Chinese computer assets.
Recent Cyber Incident & Breach Trends report not only reveals a $45 billion cyber crime industry in 2018, it also suggests a shift in cyber attack trends towards focused attacks on businesses.
Cyber incident reporting is already done for the benefit of investors by many companies, but the SEC is looking to establish a more regular and predictable system to include a four-day reporting window.










