Cyber criminals behind REvil ransomware are auctioning off stolen data to the highest bidder, hinting at changing tactics and possibly the economic impact of COVID-19 on cybersecurity.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
With rising risks of Internet of Things, the draft of the NIST 800-53 revision 5 addresses IoT security and privacy challenges head on.
The SEC has been clear that proper risk management and timely cyber incident disclosures protect investors and other stakeholders. The regulators may make an example out of SolarWinds and its leadership at the time of the Orion incident to set the tone for the importance of software supply chain security.
Emerging cyber risk quantification methods are allowing boards to ask “what if” questions if operating conditions change, and to align cyber risk with what they know about the business—upcoming economic challenges, potential merger and acquisition activities, or even the effect on the company’s financial statements or stock price.
2020 saw a spike in healthcare data breaches. A new report from cybersecurity firm Tenable finds that this spike can be overwhelmingly attributed to ransomware attacks.
Data loss is a rising risk for companies during coronavirus due to the hundreds of terabytes of potentially sensitive corporate data being stored in employee homes on USB drives.
The reasons that boards approve investments are quite different to the decision-making process undertaken by CISOs and IT decision makers themselves.
Ritz data breach allowed cybercriminals to steal credit card information from guests to make expensive purchases at Argos. The hackers impersonated staff and bank officials.
A confirmed cyber attack on Rockstar led to the GTA6 leak of in-game videos via the internal Slack channel. The hacker claims that they are also sitting on stolen source code and asking for a ransom.
The AI agent incident is described as "unprecedented" as the model went to "extreme lengths" to achieve a security testing goal, independently opting to find a path to internet access and break into Hugging Face to obtain secret solution information.










