Study shows effects of phishing awareness training starts to wear off after four months and many employees will have lost what they learned almost entirely after six months.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
US intelligence agencies have issued a public warning indicating that APT groups have developed a "mutli-tool" malware kit that targets a commonly used range of industrial control systems.
A new report from Google Threat Intelligence Group (GTIG) and Mandiant warns of a zero-day vulnerability present in Dell RecoverPoint for Virtual Machines since 2024, and that has been actively exploited by Chinese hackers for at least that long.
Racial and gender bias may extend even to the world of cybercrime. New study finds that disadvantaged groups are not only more frequent targets of attacks, but also that they suffer disproportionate damage from them.
Miami-based healthcare provider Independent Living Systems suffered a data breach that exposed the personal and protected health information of over 4 million customers.
Cybercrime outfits are increasingly shifting to highly structured and advanced fraud operations, with "scams-as-a-service" models that reflect the similar offerings for other attack types such as ransomware.
Anonymous inside sources revealed that an attack campaign conducted in the middle of 2021 netted sensitive user data from Apple and Meta, with the hackers posing as legitimate law enforcement agencies.
Privileged identity management and privileged account management are concerned with regulating and auditing access received through any form of administrative account connected to a system; whether on-premise, cloud, or hybrid.
Crypto mining malware is now the weapon of choice for hackers worldwide. The skyrocketing prices of cryptocurrencies is driving the scale of cryptojacking attacks, and can mean very lucrative profits ranging from hundreds of dollars to twenty thousand dollars per month. Victims now include Tesla and the UK government.
Enterprises, like people, have a lot to lose if their communication data falls into the wrong hands. Sensitive company information can be stolen and used for financial gain, competitive advantage, or even personal blackmail.










