Cloud computing company ServiceNow has confirmed a security breach that affected enterprise customers’ instances stemming from an unsecured REST API endpoint.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Nearly half of IT and business leaders said that the expanding attack surface is “spiraling out of control.” But throwing even more tooling and people at the issue doesn’t address the underlying problem which lies in a disconnect between the teams, processes and tools that a CISO probably already has in place.
MFA can be circumvented by modern identity attack techniques. Thwarting cyber attackers starts by understanding the techniques they rely on to bypass MFA protected users, and responding with a holistic, well-rounded identity security strategy that can fill these gaps.
A data breach at Japan’s telecommunications company KDDI Corporation’s third-party email system has compromised numerous ISPs and tens of millions of customers.
API security flaws on millions of vehicles from 16 car manufacturers expose them to unauthorized remote control, account takeovers, and personal information disclosure. Multiple car manufacturers using nearly identical car systems with almost similar functionality.
Shadow AI is the new “known unknown,” and it lives inside every modern enterprise. Legacy cyber products won't secure AI; only AI built to govern AI can.
Security and privacy leaders must bring employee-built AI workflows into full view before they become enterprise risks, especially considering the rise of shadow AI.
Shadow API is the greatest API security risk, with 31% of malicious requests targeting unknown, unmanaged, or unprotected APIs, according to the Cequence API protection report.
Report shows that shadow code from third-party libraries is a risk for web applications and concern for owners afraid of brand damage, lawsuits, and regulatory actions.
IT security teams need to develop a SaaS management strategy to mitigate and address their shadow applications to mitigate the security and compliance risks shadow IT poses to their organizations.










