Zagg has disclosed a credit card data breach after an unauthorized third party injected malicious code into their BigCommerce platform via a third-party add-on, FreshClick.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
At ANY.RUN malware analysis sandbox, we noticed an increase in phishing scams that direct users to fake Microsoft Outlook login pages, collecting confidential credentials. We decided to analyze one such campaign.
While Presidents Putin and Biden still appear to be far apart on the issue of cyber attacks originating from the former's country, the two at least appear to be negotiating. Biden presented Putin with a list of critical infrastructure targets that could trigger serious retaliation.
Attempted ransomware attack on NYPD fingerprint database was the result of a “bumbling” third-party contractor who was installing video equipment at one of the department’s training academies.
Compromised data belonging to ten companies is on sale on the dark web by a hacking group called ShinyHunters. The 73 million stolen user records is being sold for $18,000.
While it might be tempting to view a major vulnerability as an indication of open source somehow being deficient, the reality is far from that. Open source software is not more or less secure than commercial software, and in reality, most commercial software either includes or runs on open source technologies.
Agencies published a list of tactics, techniques, and procedures used by Russian APTs and mitigations to protect critical infrastructure networks from state-sponsored attacks.
New US sanctions have been imposed on the creators of the Triton malware, which was designed to specifically target the control and safety systems of critical infrastructure.
The supply chain attack on third-party library Axios has forced OpenAI to revoke its code-signing certificate and require users to update their macOS certificates.
Through robust communication and targeted employee education, leaders can achieve a balance between introducing new security controls and ensuring employees understand the need for them in the first place.










