Whether it is company culture or an individual attitude, developers do appear to be commonly shipping vulnerable code with the full knowledge that there are weaknesses in it.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Remote workers faced a barrage of over 100,000 phishing attacks over the last four months, mostly involving the impersonation of Google-branded websites, according to a report by Barracuda Networks.
Brazil's Ministry of Health website data leak exposed medical records of 243 million living and deceased Brazilians after database access credentials were saved in the source code.
The LockBit gang is the latest ransomware-as-a-service outfit to push the envelope, this time by offering the criminal underworld's first known bug bounty program.
In 2018, 351,936 complaints were filed with the FBI, averaging around 900 a day, and these successful internet crime schemes resulted in about $2.7 billion in personal and business losses.
It’s important that businesses monitor Dark Web trends and activity to monitor what data has been breached and understand where there might be weak links at the employee and enterprise level.
A cyber attack on the largest telecommunications service provider in the Netherlands, Odido, has leaked the personal information of over 6 million customers.
A health data breach appears to have exposed the sensitive personal information of members of Congress and their employees. DC Health Link is used by many (but not all) members and their assorted staff.
Security researchers have discovered hundreds of federal network devices with exposed management interfaces violating the recently mandated CISA security requirements detailed in the Binding Operational Directive (BOD) 23-02.
A security breach at France’s national bank registry has compromised the personal information of 1.2 million people, after a threat actor downloaded a database containing the information of all bank accounts in the country.










