Postmeds’ Truepill data breach impacted over 2.3 million individuals and is the subject of a class-action lawsuit alleging the digital pharmacy's negligence.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Five regional hospitals in Ontario, Canada, rescheduled appointments and diverted non-emergency patients after a cyber attack disrupted a shared service provider.
The head of Iran Civil Defense has accused Washington of the latest large-scale DDoS attack that targeted Iranian infrastructure, shutting down 25% of Iran's Internet.
Pro-Russian hacktivists breached the Idaho nuclear lab and stole sensitive employee data after compromising a federally-approved third-party vendor system.
Lift and Shift is the cheapest and easiest cloud migration method. Organizations should consider the different application components and how they interact with each other to determine the best approach.
Home improvement retail chain Home Depot suffered a third-party data breach when a trusted vendor leaked a sample of 10,000 employee records during software testing.
Lateral movement has been a common factor in breaches, using identity as a universal attack vector to traverse environments unchecked. Organizations must have full visibility of the threat posed by identity and proactively wrap MFA round exposed assets.
Chinese malware deployed by a state-sponsored advanced persistent threat group is targeting critical industries and their downstream customers in a prolonged cyber espionage campaign.
Thousands of companies using popular NPM libraries have just learned that the hidden price of free software is that the open source developer may withdraw their consent at any time.
There is now a new breed of highly sophisticated cyber criminals who are attracted by the huge financial gains made possible by highly targeted ransomware attacks. Today, with IoT being adopted across a wide variety of industries, it seems that it’s only a matter of time before cyber criminals take Internet of Things (IoT) devices hostage using ransomware, potentially placing hundreds of thousands of people at risk. In this article, we examine the rising threat of ransomware, the potential impact on the IoT environment and how we can avoid a global ransomware pandemic.










