New study finds multi-cloud security to be the biggest IT challenge for businesses as the authorization and authentication handoffs between the different services provide opportunity for things to go wrong.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
As more recipients get wise to the usual phishing tactics, attackers are adopting another strategy: pretexting. Protecting an organization against pretexting attacks requires a layered approach that includes preventing attack messages from reaching employees, and making employees aware of how pretexting works.
Chinese APT group Weaver Ant breached and maintained a foothold on a large Asian telco network for four years using compromised Zyxel CPE routers for cyber espionage.
T-Mobile appears to have suffered a devastating data breach as a reported 100 million records have appeared for sale on a dark web forum. The customer data is about as sensitive as possible, containing accurate Social Security and driver's license numbers.
Survey of nearly 2,000 IT professionals indicates that cloud security has been improving as the need for these services grows, but organizations are still hitting some common stumbling blocks.
A massive supply chain attack on LiteLLM open-source AI gateway has exposed the authentication secrets of over 2,500 organizations and more than 434,000 CI/CD pipelines.
Microsoft Power Apps appears to list all data types as public unless the default settings are changed. The data leak exposed several coronavirus tracing and vaccination portals, as well as at least one job applicant database that contained social security numbers.
Implementing MFA methods improves an organization's security posture by lowering the likelihood of identity theft, as a hacker would require more than just the user's password to obtain access to their account.
New iPhone exploit allows anyone to permanently jailbreak by using a USB cable to bypass the bootROM. The exploit compromises all models from iPhone 4S to iPhone X and cannot be fixed with a software update.
Just a few simple strings on malware are all it takes to defeat Cylance antivirus software. This is a crushing blow for those who predicted AI and machine learning are the future of antivirus protection.










