Secure coding training is critical, but how that training is developed and presented can make a tremendous difference between “checking the box” training – and training that yields results.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
NSA issued an advisory that hackers were exploiting VMWare’s and SolarWinds’ Orion vulnerabilities to perform federated login and execute attacks as part of SolarWinds hack.
A joint cybersecurity advisory by the NSA and GCHQ warns that Russian hackers are brute forcing passwords on the cloud using a Kubernetes cluster in a global cyber espionage campaign.
NSA released a list of the 25 top vulnerabilities exploited by state-sponsored Chinese hackers. In response, Beijing accused the US of being an "empire of hacking."
The NSA has issue a cybersecurity advisory that Russian hackers are exploiting a unique vulnerability to gain access to computer systems by sending a specially crafted email to targeted users.
The NSA urged developers and organizations to switch to memory-safe languages to address memory safety issues responsible for most exploitable vulnerabilities. Microsoft and Google attribute 70% of some of their product vulnerabilities to software memory safety issues.
Agencies published a list of tactics, techniques, and procedures used by Russian APTs and mitigations to protect critical infrastructure networks from state-sponsored attacks.
NSA director of cybersecurity says ransom payments are more difficult to process due to lack of access to assorted banking options, and inability to purchase necessary technology to set up the infrastructure for new ransomware campaigns.
ITRC 2021 Data Breach Report says compromises increased by 68% from 2020 and 23% from 2017, the highest on record, and lack of transparency hampers identity theft protection.
Tea Dating Advice, an app that allows women to perform background checks on men they are dating or interested in, faces a potential lawsuit after experiencing a data breach that leaked sensitive data, including private messages.










