Microsoft has released security patches for the zero-day vulnerability chain dubbed ToolShell, capable of remote code execution on SharePoint, resulting in the exploitation of at least 54 organizations worldwide.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Vibe coding AI Replit put out some bad vibes by hallucinating components that it added to a project on its own, such as a database of 4,000 fictional people, ignored repeated orders, and eventually deleting an entire database.
A ransomware attack affecting Russian vodka producer Novabev disrupted its internal IT systems, shutting down over 2,000 liquor stores, including...
Restrictions on ransomware payments have become common for government agencies around the world, but it is still fairly rare to see them extended to the public sector or local levels of government. The new UK rules would additionally require all business types that are not impacted to notify the government.
The massive 2023 cyber attack on Clorox can be traced to a negligent help desk employee at longtime contractor Cognizant, according to a new lawsuit filed by the company. Clorox is seeking a total sum of $380 million for breach of contract, lost sales and reputational damage, with $49 million of that in direct remediation.
Dell has confirmed a security breach after the World Leaks ransomware cyber gang leaked 1.3 terabytes of data allegedly stolen from the company’s infrastructure.
The reduction in CISA’s budget and workforce comes at a time when cyber threats are increasing in volume and sophistication. Private sector teams and state and local agencies must now take the lead in defending their assets.
A U.S. nuclear agency was among the victims of the SharePoint vulnerability chain, which was exploited to compromise over 54 organizations across the United States, Europe, and Asia.
Allianz Life Insurance Company of North America (Allianz Life) is notifying 1.4 million customers, financial professionals, and employees of a data breach that leaked their personal information via a third-party CRM platform.
Aeroflot canceled 54 of its 260 scheduled flights for the day due to the cyber attack, and an undetermined number of others experienced some amount of delay. 22 outbound flights from Moscow were subsequently canceled the following day, along with 31 incoming flights operated by subsidiary Rossiya Airlines.










