Global oil and gas industry is fending off a major spyware campaign using highly targeted spear phishing attack emails with disguised .EXE file that contains Agent Tesla.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Based on a report by Microsoft, the Trump campaign is claiming that foreign state-backed hackers are behind the attack that involved a leak of a vice presidential vetting dossier and other materials to US media outlets.
The website defacement only lasted for about 30 minutes and in itself was a fairly minor incident, with the attackers posting a cryptocurrency scam reminiscent of the Twitter breach in July.
The Trump administration has proposed a $707 million cut to CISA’s operating budget, citing waste, weaponization, and redundancy concerns, as nation-state cyber threats increase.
The CISA 2026 budget cuts would be accompanied by a reduction of 1,083 CISA positions, a cut of almost a third of its present count of 3,292 employees. The Cyber Defense Education and Training program would also be gutted, with the budget proposal suggesting that it could be replaced by free resources.
How do technology partners, cloud providers, vendors, distributors, customers and organizations earn trust? There is no simple answer, but compliance standards play a significant role. There can be no trust without transparency, and modern compliance helps organizations make their security practices considerably less opaque.
SIM swap scams are increasingly profitable for criminals with the growing dependence on phone-based authentication and mobile wallets storing cryptocurrencies. Are mobile carriers doing enough to prevent SIM swap fraud?
The U.S. aviation sector is looking at new cybersecurity requirements in four fundamental areas: network segmentation and redundancy, access control, monitoring and detection of threats, and timely patching.
LockBit ransomware will undoubtedly be copied and used by other threat actors in the near term, putting the group's business at risk. But the leak of the ransomware builder also gives security researchers valuable insights.
Sophos found that 64% of healthcare organizations chose to pay ransom after ransomware attacks in 2021, up from 34% in 2020, but only 2% of payers recovered all encrypted data.










