Google warns Salesforce customers about vishing attacks by hackers impersonating IT support to lure employees into connecting a rogue app, exfiltrate data, and demand ransom.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
NFT marketplace OpenSea acknowledged a data breach after an employee of a third-party email delivery vendor downloaded email addresses and shared them with an unauthorized party.
Phishing, BEC and social engineering scams work particularly well on employees who are working from home and has become a “perfect storm” for attackers who want to target businesses through their remote workers.
Researchers found that hackers were harvesting enterprise login details by overlaying legitimate companies' webpages with fake login prompts in an email phishing campaign.
Scattered Spider, ShinyHunters, and LAPSUS$ are the three groups involved, and have collectively been the most active of the major cybercrime gangs over roughly the past year. The groups all had prior ties via "The Com," a broader collection of cyber criminals that loosely affiliate and come together for singular projects in a fluid way.
Meet Bob. Bob’s an employee at BigCorp, and he’s confused. He’s got info security folks requiring him to take annual...
$1.3 million BEC attacks on three large financial services companies in U.K. and Israel shows how far cyber criminals are willing to go and what they are capable of.
Generative AI (GenAI) has prompted fears about data security and privacy, but it may also be the tool that organizations have been looking for to improve security and privacy through better data handling.
Alibaba's web scraping data leak exposed over 1 billion user records leading to the imprisonment of the implicated software developer and his employer for three years.
A new source of cyber risk and attack may come from posting instructions that include a ZIP or MOV file name, with that text automatically converted into a URL leading to one of these new top-level domains.










