The Cyber Safety Review Board finds that the open source community is "under-equipped" to fully deal with the Log4j vulnerability and that it will be making appearances in the wild for "a decade or more."
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
New cyber security directive from DHS has cut mandatory time for U.S. federal government agencies to patch vulnerabilities considered critical from 30 to 15 days, failure to do so may result in administrative penalties.
A new and wide-ranging cybersecurity executive order from the Trump administration rolls back some Biden- and Obama-era directives and looks to steer government cyber defense efforts to "identifying and managing vulnerabilities, rather than censorship."
UK MSPs will be brought under the same cybersecurity laws that govern essential services, such as critical infrastructure and health care. The move stems in large part from an increasing focus on MSPs by the most advanced nation-state security actors.
Latest CyberX study analyzed real-world traffic on 1,800 production networks and uncovered an alarming number of IoT and ICS security vulnerabilities that put them at greater risk of cyber attacks.
New 4iQ report indicates that data breaches were up by over 420% from 2017, exposing a total of almost 15 billion identity records. Small businesses are being targeted much more frequently than previously thought and that even relatively tiny businesses are now on the menu for sophisticated hackers.
New report showing individual compliance regulations and their propensity to allow breached passwords into the fold – up to 83% of known breached passwords can satisfy regulatory compliance standards.
New discovery of over 142 million guest credentials on the dark web expands the scope of the 2019 MGM data breach and appears to confirm that a number of MGM Resorts properties were affected.
The Salt Typhoon state-sponsored hackers were able to maintain a footing in a state National Guard unit for nine months and use this position to intercept traffic from other national guard networks in all 50 states as well as at least four US territories.
Most of the attempts on the US government websites appear to have been unsuccessful, but the OpenAI agents sought to find login credentials and in at least one case were able to do so to access the Commerce Department. The agents also engaged in an extended and varied campaign against the UN Trade and Development (UNCTAD) statistics website.










