A major password breach which was first reported this September has just been confirmed by Zynga. It appears that the 170 million affected users were not notified when the original breach news broke.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
In spite of many, many public warnings, users of Windows and Microsoft's various cloud-based services appear to still be committing the cyber sin of password reuse.
North Carolina and Florida have banned ransomware payments for government agencies. Pennsylvania, New York, Texas, Arizona and New Jersey have also had bills of this nature recently come up for consideration.
Choosing whether to pay ransom isn’t a moral or ethical decision. It is always a business decision based on risk reduction and protecting the interests of an organization’s customers, employees and key stakeholders.
A software security flaw in PayPal’s loan app leaked customer data for 6 months, forcing the payment giant to issue refunds after unauthorized transactions occurred in some affected accounts.
For nonprofits, it’s important to be aware and be protected from cybersecurity risks. While the core monetary focus of any nonprofit is always to helping those in need, some expense must be made on protecting nonprofits from hacking and cybercrime.
NSO Group was found to not only have exceeded its legal level of access to the WhatsApp servers and broken the terms of service with its Pegasus spyware, but to also have violated the US Computer Fraud and Abuse Act as well as California state law.
Lessons to be learned from the recent rash of API security incidents is that you need to adopt a Shield Right while you Shift Left strategy to protect yourself from API security threats.
Misconfigured AWS buckets containing dozens of terabytes worth of social media messages were exposed to the public. The data found in Pentagon's leaked database was gathered by the U.S. military as part of their ongoing efforts to identify so called ‘persons of interest’, revealing the extent of internet surveillance.
Every week, there seems to be a major new data breach that impacts millions. So it’s no surprise that personal cyber insurance are being offered by insurance companies, and the global market could be worth as much as $3.1 billion by the year 2025.










