Study of password managers finds security vulnerabilities in the way master passwords are stored. While password managers are still widely considered to be a best security practice, it's important to keep in mind that no system is perfect or without vulnerabilities.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
With the unprecedented increase in remote work, new study shows a global increase in nearly all types of cyber attacks since the COVID-19 social distancing measures began.
CISA's new security-by-design and security-by-default guidance was released in collaboration with multiple other security agencies in the US as well as ones in Australia, Canada, New Zealand, the UK, Germany, and the Netherlands, formalizing the principles at an international level for the first time.
New Senate report reveals that the government’s biggest targets are not keeping pace with threats. Seven of eight federal agencies were found to have not made any meaningful improvements to their security since 2019.
76% of ransomware attacks in 2022 were tied to a known vulnerability that was made public between 2010 and 2019, and old vulnerabilities that were discovered as far back as 2015 are still commonly exploited.
New report detailed a wide variety of IoT security and privacy flaws in common smart devices bought off-the-shelf from major retailers. Some of which are sending personal information to third party companies in China.
North Korean hackers are focusing heavily on Magecart attacks by planting malicious code in online shopping carts of individual stores and payment processors.
Nearly 10,000 Android apps are found with a variety of undocumented backdoor abilities such as remotely resetting user passwords and blocking users from loading certain types of content.
Even though organizations are expecting security automation to reduce their cybersecurity workforce, it also helps them to focus on overall network security and the most serious vulnerabilities.
Honeypots set up by Sophos logged a staggering amount of scripted attacks attempting to pass default credentials. What’s more alarming is the aggressive speed and scale of these attempts with the first attack in less than 60 seconds.










