Popular Android file-sharing app SHAREit with over a billion downloads has a security flaw that could leak users’ sensitive information and allow remote code execution.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Healthcare provider Shields Health Care Group suffered a data breach that exposed sensitive personal health information for at least 2 million patients.
A CEO’s involvement shouldn’t only come as a last resort. CEOs should take a proactive stance to highlight that security is also in the business’s best interest and can be balanced with the overarching goals of the business. With the CEO on board, the spotlight then shifts back to the CISO who must then begin work to create a security-focused organization.
APIs are being deployed so fast and at such scale that companies risk both not knowing what they have (Shadow APIs), and losing control of API security, including exposing vital data and processes.
NIST’s Guide to a Secure Enterprise Network Landscape released in November 2022 examines the shift from on-premise networks to multiple cloud servers. Although the guide doesn’t address SaaS applications directly many of the principles it discusses can be applied to the SaaS ecosystem.
Double-extortion ransomware gang ShinyHunters has hacked its rival, Cl0p, and defaced its Tor-based data leak site after allegedly taking over its infrastructure.
A security breach at the FBI, claimed by ShinyHunters, has exposed the personal information of current and former employees, special agents, as well as job applicants.
As the world becomes more complex non-traditional approaches to ensuring data security and protection must be evaluated. In this article Wei Chieh, the founder of SWARMNETICS draws a parallel between how we treat open source software and the Asian organisational attitude toward White Hat hackers (or ‘independent security researchers’) as assets that might help to stem the tide of security breaches that Asian companies face today.
Automation is no longer an office-only reality. How can we ensure security when inviting automation into our homes? Should we be auditing smart home technology in the same way we audit our office automation?
With projections of closing out at $1 to $2 trillion by the end of the present decade and making up about a third of total regional GDP, ASEAN's rapid digital economy growth is poised to put it at the center of global conversations about cyber rights and regulations in the very near future.










