Postmeds’ Truepill data breach impacted over 2.3 million individuals and is the subject of a class-action lawsuit alleging the digital pharmacy's negligence.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Developments in Delaware’s Caremark doctrine for breaches of fiduciary duty have paved a narrow path for plaintiffs to hold directors liable for failing to adequately address and oversee their company’s cybersecurity and data privacy risks.
A leading lobbying group in the Asia Pacific region is raising a warning about China's new proposed cyber security rules for financial firms, sending a letter to the China Securities Regulatory Commission.
Threat actors behind the 2024 PowerSchool data breach continue to extort individual schools, despite the education software developer having already made a ransom payment.
Have you noticed how swiftly predictive and generative AI have become indispensable to modern cybersecurity?
Prescription management provider Sav-Rx is notifying 2.8 million individuals of a data breach impacting their personal information after an unauthorized party accessed certain non-clinical systems.
With the executive order signed, leading industry standards organizations should be heavily involved to help apply standards and regulations to make sure all connected devices have a proper level of security to create a secure ecosystem and prevent further critical infrastructure attacks.
As more recipients get wise to the usual phishing tactics, attackers are adopting another strategy: pretexting. Protecting an organization against pretexting attacks requires a layered approach that includes preventing attack messages from reaching employees, and making employees aware of how pretexting works.
Hackers are reverse engineering mobile apps and embedding malicious code to steal data for downstream attacks or to cause other direct harm to the user.
Given the growth of wire fraud and grey area when it comes to liability, creating a system that guarantees protection has become incredibly important. The best way to prevent uncertainty about who is at fault is to prevent the risk from happening all together.










