Attackers now have access to the same AI-powered tools that defenders use to discover weaknesses, and they can use them just as quickly. Fully autonomous cyberattacks are now an inevitable evolution.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
With the doubling of security vulnerabilities found in popular open source projects between 2018 and 2019, many are concerned on the record being broken again in 2020.
T-Mobile has seemingly had annual data breaches since 2018, but the new FCC settlement addresses just those that took place in the post-Covid period (and that involved the largest total count of customer records).
The cyber attack impacted a "small number of servers" but nevertheless caused issues with NHS 111 scheduling, and the system outages may not be fully resolved for at least several days.
NIST’s Guide to a Secure Enterprise Network Landscape released in November 2022 examines the shift from on-premise networks to multiple cloud servers. Although the guide doesn’t address SaaS applications directly many of the principles it discusses can be applied to the SaaS ecosystem.
Law enforcement authorities have seized the notorious cybercrime forum RAMP, which advertised and facilitated the sale of various hacking services, including ransomware.
The new “agentjacking” attack takes almost no real hacking ability to pull off. It's predicated on pulling a public credential that can readily be found in a web site's JavaScript source code, which can be used by anyone to get Sentry to accept an error event full of malicious instructions that is passed on to AI coding agents.
Data security has increasingly become a key aspect of cybersecurity because of the large amounts of data being generated, stored and shared by both individuals and organizations. The shift from cybersecurity to data security indicates a more holistic approach to protecting sensitive data in organizations.
The Pokémon developer has confirmed that a data breach took place about two months ago and was the result of illegal access to the company's internal network, spilling internal secrets and some employee contact information.
McAfee researchers discovered a cyber espionage campaign involving Chinese Red Delta and Mustang Panda hackers trying to steal 5G technology secrets using a fake Huawei website.










