Digital Shadows Photon Research team found that over 24 billion stolen user credentials were available for sale on the dark web market in 2022, an increase of 65% in two years.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Law firm Wolf Haldenstein Adler Freeman & Herz LLP has notified more than 3.4 million people that a December 2023 data breach exposed their personal information.
The FBI, CISA, and MS-ISAC have issued a joint cybersecurity advisory on the Medusa ransomware attacks impacting over 300 critical infrastructure organizations.
Over 300 malicious apps engaged in a massive ad fraud and credential and credit card theft campaign have been downloaded over 60 million times on Google Play Store.
A threat actor listed on a hacker forum data belonging to over 17 companies containing over 34 million records. Victims include Eatigo and Alibaba-owned Lazada's RedMart online grocery.
Nearly 25,000 active websites have over 47,000 malicious WordPress plugins installed, putting them at risk of attacks, including complete takeover by cybercriminals.
Research by IRONSCALES reveals that over 50,000 fake login pages targeted major brands across the world. PayPal, Microsoft, and Facebook topped the list.
Mass scanning activity targeting VMware servers with the remote code execution security bug after a Chinese researcher released proof of concept (POC) code.
An adware campaign involving over 60,000 Android apps has infected devices since October 2022. Researchers warned that the infected Android apps could start distributing potent malware, including credential stealers, banking trojans, and ransomware.
The Nov 2025 data breach at the American apparel giant Under Armour has leaked the personal information of over 72 million people following a ransomware attack.










