By owning a trusted CA, Russia can also now host as many man-in-the-middle attacks, which are generally privacy attacks. Additionally, state-sponsored hacking groups can produce certificates for devices meant to intercept traffic and view all of the encrypted communications.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Stolen passwords from over 100,000 data breaches circulating on the dark web has reached 15 billion, a number that has risen by 300% within the last two years.
Fraudsters used Nordstrom’s official email system to promote a crypto scam promising to double funds sent to the scammers’ wallet addresses as a St. Patrick’s Day giveaway.
There is still an elevated threat of serious Iranian cyber attacks on US targets even as the potential for an all-out war seems to have simmered down for the moment as Iran is known to act through asymmetric warfare.
Bio-cybersecurity is not to be taken lightly as data breach could lead to healthcare companies buying back patient data from ransomware or hackers using stolen genetic data to blackmail individuals.
A new draft China cybersecurity law could restrict certain U.S. companies from doing business in the country which clearly represent a tit-for-tat in the escalating trade and cyber war between U.S. and China.
The FBI says hackers who scraped credit card data by injecting malicious PHP code on an online checkout page were targeting U.S. businesses since September 2020.
The new FDA terms will have manufacturers submit a plan with new applications that demonstrates how they will monitor, identify and address cybersecurity issues, along with "reasonable assurances" that the medical devices are protected from cyber attacks.
A ransomware attack on a third-party service provider has impacted numerous Swiss government departments, potentially leaking sensitive personally identifiable information.
Microsoft Azure Cosmos DB cloud databases have had their read-write keys exposed by a flaw that has been present since 2019, allowing an attacker to not just access the contents but also to change or delete them.










