Hackers demanded $17 million in Compal's security breach despite its denial of the ransomware attack. Compal also claimed that its production lines were not affected.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
While many CSOs may seek solace in the eventual return to the safe confines of an office network, it is unlikely cyber criminals will cease their attacks. Rather, they will be emboldened to find more ways to take advantage of an increasing number of hybrid workplaces.
A massive 600 gigabyte file containing about 2.2 billion breached accounts has been spotted floating about the dark web, freely available to anyone who cares to download it via torrent.
While the transition to passwordless security procedures is already underway, adoption is still limited mainly in larger companies in certain industries. There are many steps that can (and should) be taken to accelerate the authentication journey to make passwordless authentication mainstream.
Ransomware attack was part of an ongoing campaign against targets in the France's medical sector and France indicated that an active response is something under consideration.
The U.S. Treasury Department has handed down the first sanctions to a crypto exchange, hitting Russia-based SUEX.io for facilitating ransomware payments.
SolarWinds hack may impact cloud services from major providers such as Microsoft and Amazon, especially since the Orion software stores API keys and other security credentials.
The security industry was hit by an increasing number of AI-powered cyberattacks in 2023, and that is not going to slow down in 2024. As these attacks evolve as AI infiltrates every aspect of business, here’s what security leaders should resolve to do this year amid AI threats.
The NSA urged developers and organizations to switch to memory-safe languages to address memory safety issues responsible for most exploitable vulnerabilities. Microsoft and Google attribute 70% of some of their product vulnerabilities to software memory safety issues.
Imperva found that bot traffic accounted for 40% of internet activity. Malicious scripts were responsible for 26% of website visits and could interfere with the COVID-19 vaccine.










