New study suggests that a combination of broken and poorly configured SIEM rules are providing organizations with a far lower level of threat coverage than they believe they have.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A New York City SIM farm recently seized by the Secret Service was being put to use in a variety of criminal activities and had the capability of disrupting local communications networks, according to officials. In total the scheme was thought to have cost millions of dollars to set up.
SIM swap attack is on the rise which includes the recent Twitter hack on their CEO’s account. Attackers used social engineering to convince telco to switch target’s number to their own SIM cards.
A data breach affecting American medical imaging provider SimonMed Imaging has leaked the personal information of 1.2 million people. SimonMed learned of the data breach on January 7 after a third-party vendor reported malicious activity on its network.
A password compromise affecting business intelligence and analytics firm Sisense has triggered a CISA alert urging customers to reset their account login credentials and secrets.
A six-year surveillance operation tied to state-sponsored Iranian hackers appears to have scooped up personal documents and tracked the phone location data of dissidents.
SK Telecom, South Korea’s largest mobile network operator, warns about a malware attack that leaked sensitive USIM data, exposing subscribers to potential SIM swaps and surveillance.
The beleaguered cybersecurity teams of SMEs are being forced to become very creative in keeping up with modern threats, juggling a variety of outsourced solutions in the face of an onslaught of attacks.
Mercedes-Benz's source code leak for smart car components may have given software developers and hackers access to the German automaker's most lucrative intellectual assets.
Quantitative cybersecurity budgeting helps security professionals properly translate security risks into business risks and demonstrate how cyber risks impact the organization as a whole – which are key to getting buy-in from non-technical stakeholders.










