Chicago based meal kit service Home Chef suffered a data breach likely to be orchestrated by hacking group Shiny Hunters which resulted in over 8 million user records being sold on dark web marketplace.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A blog post by Nvidia’s Chief Security Officer David Reber refutes accusations made by the Chinese government of a backdoor in the company's AI chips that can be used as a remote kill switch.
The world’s largest cruise operator, Carnival Cruise, has confirmed a data breach that affected nearly 6 million people, with the ShinyHunters hacking group claiming responsibility.
A massive brute force password attack involving 2.8 million IP addresses targets VPN devices from various companies including Palo Alto Networks, Ivanti, and SonicWall.
The ransomware group LockBit put itself in the international headlines once again last week when it boldly claimed to have stolen 33 TB of data from the US Federal Reserve. But the sample of stolen data turns out to have come from just one US bank.
I was at the #Structure2017 conference and the term hybrid cloud (at last count a day and a half into a two-day conference) has been used 131 times. However – I hazard that between the panelists, interviewers or the audience members who used this term - all have different definitions interpretations of this catchphrase.
Twitter hack report reveals that employees were tricked into visiting a phishing page that captured their VPN credentials, a technique that worked due to move to remote working during the pandemic.
Advanced digital tools, readily available information, and new ways to buy online, unfortunately, has altered the ecommerce fraud landscape into a widely accessible territory for criminals to explore.
An access control misconfiguration on Oracle NetSuite ecommerce sites exposes customer data to unauthorized access, with many businesses unaware of deployed default instances.
Polymorphic phishing attacks are highly effective as they use randomization of email components which are hard to be detected by signature-based email security tools.










