The data breach took place at the BWI Airport Marriott near Baltimore. A social engineering attack was executed on a member of the hotel staff, who unwittingly granted access.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
One would hope that credit bureau Experian had learned a lesson about data leaks but the agency has a new API security vulnerability that appears to have leaked the credit scores of nearly every American that has one.
Latest Instagram password leak has exposed 10,000 plaintext credentials in the SocialCaptain app, allowing anyone to access any app profile by entering a unique user ID into a public URL.
The Binance crypto hack manipulated the Binance Smart Chain Token Hub bridge to pass forged proof messages. The attackers were then able to generate BNB directly to wallets under their control.
The US Treasury is now warning of potential sanctions violations if ransomware payments are made, citing the possibility of civil penalties even if the attacker’s identity is unknown.
The Mailchimp security breach appears to have lasted for less than a full day. The company says that client login information was not compromised, but customer support tools were used to send phishing emails.
Toyota discovered a second cloud misconfiguration data leak that exposed 260,000 domestic and international customers' in-vehicle data and personal information for over eight years.
Popular remote monitoring and management software firm AnyDesk has suffered a cyber attack that compromised its production systems and leaked source code and code signing certificates.
While API security remains a major concern for most organizations, most were unprepared, with only 11% having a concrete API security strategy to detect and stop API attacks.
Companies are rapidly adopting APIs to improve platform integration, connectivity, and efficiency and to enable digital innovation projects. Over the last few years, API attacks have increased massively, and API security concerns continue to impede innovations.










