A group calling itself "Cyber Av3ngers," believed to be supported by Iran's government, has declared war against Western organizations making use of Israeli technology. One of the opening salvos in this campaign appears to be against US water utilities, with at least one confirmed strike by the Iranian hackers in Pennsylvania.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
CISA: Admin Credentials of a Former Employee Leveraged to Compromise a State Government Organization
The Cybersecurity and Infrastructure Security Agency (CISA) and Multi-State Information Sharing and Analysis Center (MS-ISAC) discovered that a threat actor compromised a state government organization using a former employee’s leaked admin credentials.
Recent Cyber Incident & Breach Trends report not only reveals a $45 billion cyber crime industry in 2018, it also suggests a shift in cyber attack trends towards focused attacks on businesses.
The US Cyber Command is expecting the TrickBot botnet to be involved in election interference attempts, and is actively running persistent operations against it along with Microsoft.
A new OpenSSH vulnerability discovered by threat researchers is the biggest security issue to appear in the utility suite in about two decades. The bug is an unauthenticated RCE vulnerability that builds on a prior issue that was patched out in 2006.
A long-term breach of Japan's national cyber security agency may be the work of state-backed Chinese hackers. The security breach occurred in October 2022 and was disclosed in August of this year.
For years, many organizations treated cybersecurity training as a mere compliance requirement. But today’s executive teams are taking a radically different approach. They're recasting cyber-readiness from a perfunctory task into a strategic lever for business resilience and growth.
The speed at which applications are developed and deployed means businesses must move quickly to meet customer needs. While this is transformative for the development side of the house, security teams have been unable to keep up.
In a digitally-advanced modern world, replacing passwords seems like an uphill battle. But with the concept of portable digital identities, renowned brands are putting the foundation stone for a whole-new rich experience for users worldwide.
Recently Discovered SAP Bug Allows Anybody Without Technical Knowledge to Hack Business Applications
SAP bug allows a remote unauthenticated attacker to gain unrestricted access to SAP systems without a username or password to create new privileged users or shut down the entire system.










