Recent federal directives on finding and reducing cyber risks correctly, along with the change from traditional cybersecurity methods to managing hybrid attack surfaces, show how complicated things are getting when it comes to federal cybersecurity.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The FCC warned about increased robotext scams from automated smishing attacks stealing personal information by impersonating known companies such as credit card companies, parcel delivery services, and law enforcement agencies.
The official word from Meta, via its main Instagram account, is that an "issue" that allowed third parties to request password resets for "some people" was fixed on January 11 and that users could safely ignore the strange password reset messages. They also reassured users that there is no new data breach.
Indian government has cited national security as the reason for banning 59 Chinese apps, including popular apps such as TikTok, UC Browser and Clash of Kings.
Hackers compromised carding site Card Mafia exposing 300,000 user account credentials. A hacker later offered the stolen data for free on a different hacking forum.
Dropbox says that the security breach did not involve the contents of any customer accounts. The attackers were instead focused on company GitHub repositories, raiding 130 of them for code and tools.
ITRC report noted that the 3,205 data breaches recorded last year shatters the prior record of 1,860 and is a 78% increase from a similar number (1,806) seen in 2022.
The Cyber Safety Review Board finds that the open source community is "under-equipped" to fully deal with the Log4j vulnerability and that it will be making appearances in the wild for "a decade or more."
North Korean hackers had their secrets exposed online after altruistic hacktivists breached a computer belonging to a member of the state-backed Kimsuky group.
Cynet launches free IR tool providing unmatched speed and efficiency to help organizations and IR providers accurately determine the breach scope and impact; and ensure that all malicious presence and activity are completely eliminated.










