Google Threat Intelligence Group has identified state-sponsored hackers from over a dozen countries abusing Gemini AI for cyber attacks with Iran and China being the heaviest users.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Many organizations affected by Log4j’s zero-day vulnerability with mass internet scanning detected, suggesting the remote code execution flaw was actively targeted in the wild.
A new CISA-NSA joint report follows many calls by both members of the cybersecurity industry and government agencies for a transition to memory-safe languages like Rust, Ruby, Java and C# due to their inherent minimization of memory-related classes of vulnerabilities.
The Biden administration has taken the first step toward implementing a government-wide zero trust strategy with a memorandum addressed to all federal agencies, outlining the basic goals to be reached by the end of fiscal year 2024.
Security automation is increasingly becoming a necessity in order to keep up with the cyber threats, but security analysts report significant increased stress on the job driven by fear of missing alerts.
US military personnel were warned against turning on unsolicited smartwatches mailed to service members that auto-connect to Wi-Fi and smartphones, potentially collecting sensitive information.
Meet Bob. Bob’s an employee at BigCorp, and he’s confused. He’s got info security folks requiring him to take annual...
Microsoft warned that hackers are exploiting the Zerologon vulnerability to wage cyber attacks. CISA ordered federal agencies to patch or disconnect their systems from the federal network.
The only way to truly understand and react appropriately to a security event is with context. Without context in detection and response, alerts become noise. Context lends a level of intelligence that aids in proper, proactive response.
Attack campaigns conducted against Ukrainian government agencies and businesses have been linked to an initial access broker that appears to be staffed with former members of the Conti ransomware gang.










