Supply chain security is becoming an increasing concern in COVID-19 outbreak as new opportunities are provided to cyber criminals seeking to exploit vulnerabilities.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Supply chain vulnerability in the ThroughTek "Kalay" network, a cloud-based communications platform used by an estimated 83 million IoT devices, could allow for remote compromise and control.
Some privacy vault apps on Google Play Store are used as remote backdoor to harness devices for fake clicks in ad fraud scheme and to exfiltrate user data and files.
The CFAA case of Van Buren v. U.S. has concluded with a decision resulting in a clarification of how crimes involving "authorized access" are defined.
Survey of nearly 2,000 IT professionals indicates that cloud security has been improving as the need for these services grows, but organizations are still hitting some common stumbling blocks.
COVID-19 pandemic has driven many companies to adopt remote working model amidst the lockdowns, how can IT industry help businesses remain afloat in the new normal?
Palo Alto Networks identified a Chinese cyber espionage campaign targeting 370 critical infrastructure, education, healthcare, and technology organizations through vulnerable Zoho servers.
Suspected Chinese hackers exploited a second SolarWinds hack to compromise the National Finance Center, which processes salaries for agencies including the FBI and the DHS.
Suspected Chinese threat actors compromised an IRS-authorized online tax return website eFile.com using JavaScript malware to create backdoors on users’ devices.
Israeli media reported that several Israeli companies and a nonprofit were breached in a new cyber attack wave attributed to an Iranian ransomware gang motivated by Middle Eastern geopolitics.










