A massive credentials leak has compromised the login information of over 149 million accounts, stolen via an infostealer after a threat actor failed to secure a cloud database.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Nothing much seems done to fix IoT security issues over the years with latest ISE report showing 125 CVEs, Common Vulnerabilities and Exposures, which has increased from 52 since 2013.
The big threat posed by this attack on Zendesk support systems is that the bogus message is seen as originating from the impersonated company's servers, giving it a leg up on penetrating automated spam and security filters.
Smart Devices Adding Security Updates to Combat Vulnerabilities, but EU Consumers Remain Unimpressed
Research finds that a number of manufacturers are not providing security updates for smart devices for nearly as long as their expected life cycles. In addition, manufacturers often do not specify exactly how long they plan to support security updates.
Cloudflare, one of the world's largest content delivery networks and web security service providers, is taking on AI bots with a new "Easy button" that simplifies the shutdown of unauthorized content scraping.
World Leaks ransomware gang has published sensitive files, including blueprints and supplier lists, stolen following a data breach at India's largest nuclear power plant.
Latest variant of Fakebank Android malware adds even more functional threats to banking clients – in the form of ‘vishing’ (voice phishing). It can now intercept outgoing and incoming calls which is then redirected to scammers which allows them to pose as legitimate employees of the bank.
API Vulnerabilities and Bot Attacks Cost Businesses $187 Billion, Increased Adoption Worsens Problem
API vulnerabilities and bot attacks cost businesses $187 billion annually, and the problem is worsening with rapid adoption, underscoring the need for investment in API security and bot management.
A cyber attack hits cardiac device maker Boston Scientific, disrupting manufacturing, order processing, and shipments, with no timeline for resuming normal operations.
DeFi protocols had a bad day as Sonne Finance took the bulk of the loss, with about $20 million stolen via an exploitable bug. Cyber attacks also hit two other providers.










