A data breach on a third-party cloud-based SaaS application has hit luxury fashion retailers Chanel and Pandora, leaking the personal information of customers.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
As reliance on third parties grows, so too does the exposure to additional risk. A rigorous third party risk management program helps identify, manage and mitigate the risks to reap the rewards of these relationships.
Third-party systems form a critical component of customer experience in current digital marketplace. Companies should be aware of third party risks at all times while reaping the benefits of the increased integration.
Web3 cannot get away from Web2, and it means that businesses are going to have to find a way to marry two very different approaches to security to ensure the safety of their users in the era of decentralization.
Our reliance on SaaS across every facet of contemporary business operations has extended accessibility to nearly all enterprise resources. It is critical to properly acknowledge this shift to mitigate the full extent of risk this represents.
Thomson Reuters database leak exposed 3TB of platform information and customer data after the media company left three databases unsecured and publicly accessible for days.
GitHub users leaked their login cookies by committing cookies.sqlite database to their public projects from their Linux home directory, exposing their accounts to potential compromise.
The problem stems from developers failing to remove the Twitter API keys they use for authentication from the app before they release it to the public. This creates the possibility of account hijacking.
An access control misconfiguration on Oracle NetSuite ecommerce sites exposes customer data to unauthorized access, with many businesses unaware of deployed default instances.
Ransomware attack campaign targeted an old (and previously patched) vulnerability in VMware servers, and that it has grown to become the largest attack of its type, compromising at least 3,200 VMware servers.










