A threat actor sold for an undisclosed amount a toolkit to conceal and execute malicious code without detection on most graphics cards, including AMD, Nvidia, and Intel.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A bill establishing a new vulnerability disclosure program for federal contractors has passed the House, and will now move on to the Senate to be reviewed by the Committee on Homeland Security and Governmental Affairs.
Insurance giant Geico mailed notifications of a data breach to its customers, indicating that an unknown number of driver's license numbers were compromised and might be used for fraudulent unemployment claims.
Quantum computing now has the potential to capture nearly $700 billion in value as early as 2035. NIST is encouraging U.S. government entities and commercial enterprises to move forward more quickly towards post-quantum cryptography since data is getting harvested today for future decryption.
Hackers are exploiting a 12-year-old router vulnerability existing in the Arcadyan firmware, potentially affecting millions of devices on home and corporate networks, and exposing serious supply chain risks.
With the pandemic accelerating digital transformation, there has also been a surge in fraudulent activity as threat actors are exploiting newly remote operations. In today’s digital world, knowing your customer is more critical than ever before.
The Lazarus hackers are generally in pursuit of profit. But in this case, the main interest appears to be cyber espionage. A report indicates that the group is targeting the Log4j vulnerability in energy companies.
No one would argue that 2018 was a turbulent year for cybercrime and identity theft, and there’s no doubt that we’ll continue to outpace this volume and velocity. How can organizations empower themselves – and their employees – to protect sensitive personal and company data?
Bad bots account for 30% of internet traffic and are increasingly used in account takeover and API attacks, while human traffic fell to an 8-year low of just over half of all internet traffic.
A whistleblower says that Ubiquiti downplayed its data breach to protect its stocks. He claims that Ubiquiti was the source of the breach, and hackers gained administrative rights.










