New York authorities have fined two auto insurance companies nearly $12 million for failing to prevent data breaches that compromised the personal information of 120,000 residents and resulted in fraud.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The new New York cybersecurity regulations require healthcare facilities to appoint a CISO, implement incident response plans, and to face new breach reporting requirements. They will also have access to a total of $500 million in new funding from the state.
New Zealand’s Stock Exchange was crippled by a DDoS cyber attack, lasting four days and forcing the government to activate the National Security System requiring government agencies to work together.
New Zero-Day RCE Vulnerability in Spring Java Framework; Could “Spring4Shell” Be the Next Log4Shell?
A new zero-day remote code execution (RCE) vulnerability in the Spring Java Framework is drawing comparisons to Log4Shell. It can be exploited by simply sending a crafted HTTP request to a target system.
Newly discovered set of DNS vulnerabilities puts a wide range of devices at risk, with an estimate of millions impacted. This raises fresh questions about the inherent security of DNS.
Government officials and employees, military members, and journalists the world over are being advised by the Dutch Ministry of Defence that Russian state-backed hackers are engaged in a broad campaign targeting their WhatsApp and Signal accounts.
The purpose of the cyber attack on WSJ appeared to be espionage, with information exfiltrated from email and Google Drive accounts since at least February 2020. Mandiant believes government-backed Chinese hackers conducted the operation.
Cybercriminals could run DDoS attacks on Next Generation 911 systems by using anonymized phones to issue repeated emergency calls that cannot be blocked by the network.
Researchers recently uncovered an IoT botnet that has infected more than 1M organizations. Can we survive the next DDoS attack and avoid a botnet apocalypse?
Cloud-based electronic health records and management solutions provider NextGen Healthcare has notified authorities of a data breach that leaked 1 million patient records.










