Alibaba's security team was the first to discover the Log4j vulnerability. Though Alibaba Cloud was not compromised, the company is nevertheless facing consequences for failing to notify Chinese regulators within two days as required by new laws passed in September 2021.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
More than 3,000 #cybersecurity specialists and 1,258 algorithmic models worked 24 hours around the clock to fend off 2.2 billion cyber attacks on Singles Day. Just another day's work for Alibaba defending 300 million hacking attempts per day.
Qualys researchers said the 12-year-old memory corruption local privilege escalation vulnerability on polkit's Set User ID program pkexec is easily exploitable by novice attackers and affects every major Linux distribution.
Consumers can now access all Microsoft accounts using passwordless authentication using Microsoft Authenticator App, Windows Hello, security key, or SMS and email verification codes.
A member of a hacker forum claims that they have stolen Razer's "keys to the kingdom" in the form of source code, encryption keys and employee credentials, and is looking for a $100,000 Monero payout. Razer has yet to confirm the data breach.
NATO is investigating an alleged data theft by a hacktivist group SiegedSec. 845 MB of compressed data was leaked and found to contain unclassified information and 8,000 employee records from 31 nations.
Allianz Life Insurance Company of North America (Allianz Life) is notifying 1.4 million customers, financial professionals, and employees of a data breach that leaked their personal information via a third-party CRM platform.
Numbers drawn from Allianz internal customer data show a 17% increase in the value of cyber claims and a 14% increase in frequency during this period. The central driver is class action lawsuits connected to data and privacy breaches.
Insurance giant Allianz SE's annual survey on business risk finds that organizations are most concerned about cyber events going into 2024, once again placing it as their top risk category above business interruption and natural catastrophes.
Researchers discovered that almost all cyber attacks on cloud servers are aimed at installing cryptocurrency mining malware.










