With emails bypassing defenses, humans are left as organizations’ last line of defense against phishing attacks. But it’s unreasonable to expect each employee to be a cybersecurity expert and identify these attacks every time.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
One of the most significant barriers for cybercriminals when trying to compromise a user account is Multi-Factor Authentication (MFA). But what happens when users are overrun by notifications? Enter MFA bombing attacks to exploit MFA fatigue.
South African Banking Risk Information Centre warned that banks in the country had been experiencing repeated DDoS attacks and ransom notes were delivered to a number of staff email addresses.
After more than a year of turmoil and tension, how can cybersecurity leaders keep their teams alert, convince other stakeholders to stay committed, and overcome the natural human tendency to begin relaxing defenses?
Deepfakes are a relatively new phenomenon, first starting to emerge on the internet in late 2017 but techniques to replace one face with another in a very realistic and natural-looking way have been available for years now, so why is there such a panic brewing over deepfakes?
Concerns about reprisal by the Taliban prompted the UK government to secretly grant asylum to thousands of Afghans and allow them to immigrate to the country, in the wake of a 2022 data leak by the Ministry of Defence.
The purpose of the cyber attack on WSJ appeared to be espionage, with information exfiltrated from email and Google Drive accounts since at least February 2020. Mandiant believes government-backed Chinese hackers conducted the operation.
Hong Kong-based Mixin Networks, a decentralized exchange and cross-chain transfer network, was temporarily forced to suspend operations following a hack of its cloud database. The crypto company is offering a $20 million bug bounty for full return of the stolen funds.
Misconfigured AWS buckets containing dozens of terabytes worth of social media messages were exposed to the public. The data found in Pentagon's leaked database was gathered by the U.S. military as part of their ongoing efforts to identify so called ‘persons of interest’, revealing the extent of internet surveillance.
LabCorp experienced a second data leak in a year with more damaging information exposed this round that includes medical records and social security numbers.










