The 18th installment of the DBIR surveyed 22,052 total cyber attacks logged by Verizon's internal threat research team, over half of which (12,195) involved confirmed data breaches. Credential abuse continues in the lead at 22%. Exploitation of vulnerabilities is now up to 20%, followed by phishing at 16%.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The now-public whistleblower allegations that Twitter may have active foreign spies on its payroll are sure to raise concerns about insider threats at companies everywhere. But focusing only on potential spies is a mistake.
Ransomware attack on Palermo city disrupted municipal services including video surveillance management, municipal police operations, online bookings, and digital communication channels.
European Court of Auditors recently released a comprehensive report detailing the cybersecurity challenges facing the European Union in 2019 and beyond, and how best to respond to the growing number of cyber threats.
The stolen passwords are for a MoD portal specifically designed to be used safely from home via member personal devices, but it appears the Russian hackers have been targeting the devices themselves and intercepting the credentials.
Iranian hackers linked to Iran’s Ministry of Intelligence and Security were responsible for the Los Angeles transit system breach that disrupted online services.
A leading lobbying group in the Asia Pacific region is raising a warning about China's new proposed cyber security rules for financial firms, sending a letter to the China Securities Regulatory Commission.
Iranian Hackers Use Password Spray Attacks to Compromise Defense Organizations, Pharmaceutical Firms
A recent campaign by Iranian hackers has been very successful in using password spray attacks to breach high-value targets, with a particular focus on defense organizations and satellites as well as pharmaceutical company research.
Microsoft has released security patches for the zero-day vulnerability chain dubbed ToolShell, capable of remote code execution on SharePoint, resulting in the exploitation of at least 54 organizations worldwide.
A ransomware attack on a third-party service provider has impacted numerous Swiss government departments, potentially leaking sensitive personally identifiable information.










