Quora suffered a massive data leak, exposing their password database with 100 million passwords. But the passwords were securely stored and are next-to-useless to criminals.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The annual Verizon DBIR provides further confirmation that attackers are showing a renewed interest in social engineering, particularly in conjunction with business email compromise (BEC) attacks. And the average financial damage of a ransomware attack has doubled and is almost certain to cost organizations at least $1 million to remediate.
The White House said that there is "no certainty" that there will be a cyber attack from Russia, but that the country is exploring options to target US critical infrastructure and that companies should harden cyber defenses.
Phishing attacks known as CEO Fraud or Business Email Compromise are affecting the bottom line of companies and are devastating because the spoof emails have all the appearances of being real, and the victims voluntarily hand over the money.
U.S. Department of Homeland Security aims to help software developers and security researchers eliminate common software vulnerabilities by releasing a list of top 25 most dangerous software errors.
A series of moves by the Trump administration in the past week seems to signal sensitivity to public negative sentiment toward US-based frontier AI developers and their rogue "misaligned" models. Not the least of these moves is the escalation of an ongoing FTC investigation into the AI safety practices of leading developers.
Research found that email was the riskiest channel for accidental data loss, accounting for 65% of data losses, ahead of cloud sharing and instant messaging platforms.
For the developers who take their time to painstakingly code, test, deploy and publish software for public use, any compromise to the process can ruin the entire project. To be effective at securing your software supply chain, you cannot afford to be myopic or take a shortcut in the process.
The IoT Cybersecurity Improvement Act of 2020 is now federal law, meaning that US government "smart devices" will be subject to a new and more stringent set of security standards.
Here’s what needs to be done at the enterprise level to ensure bulletproof cybersecurity against state-sponsored cyber attacks in the most uncertain times of COVID-19 and beyond.










