A rogue OpenAI agent was once again responsible, finding and taking advantage of what appeared to be a serious weakness in the government health agency's systems. The incident is believed to be the first breach of a national government system conducted independently by an AI agent.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Pinduoduo, a popular Chinese shopping app has been suspended from the Google Play Store after traces of malware were found in the code of previous app versions. Suspected purpose was to pore through user data and find information related to competing shopping apps.
Cyber attack on Japan’s government agencies leaked 76,000 email addresses, and proprietary, business, and air traffic and control data, forcing Fujitsu to disable ProjectWEB.
By fostering a culture of continuous improvement that thinks outside the box of compliance, IT teams and security leaders can feel confident in their cybersecurity resilience.
Pro-Russian hacktivists breached the Idaho nuclear lab and stole sensitive employee data after compromising a federally-approved third-party vendor system.
Combining elements of information security, business continuity, and organizational resilience, a cyber resilience strategy can enable rapid recovery from an inevitable attack with little to no operational disruption.
Software supply chain attacks will continue to be successful as long as the chasm between software development teams and info security teams persists. Until these two departments agree on common goals, attacks targeting software vulnerabilities will continue to cause havoc.
A six-year surveillance operation tied to state-sponsored Iranian hackers appears to have scooped up personal documents and tracked the phone location data of dissidents.
A coordinated cyber attack by suspected Iranian hackers hit 36 Minnesota water utilities by targeting programmable logic controllers, causing outages at some facilities.
Mapping toxic combinations and implementing separation of duties rules doesn’t have to be a painful process. Strong, regularly maintained SOD controls can help organizations identify and remediate those toxic combinations in an efficient and straightforward manner, limiting the potential damage of fraud and identity-based attacks.










