The patch comes as attempts to exploit the zero-day vulnerability began to ramp up worldwide, and was badly needed as there were no other viable remediation techniques to stop remote code execution.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Since U.S. and Europe’s first experience of ATM malware and jackpotting attacks in 2017 and 2018, evidence is mounting that the attacks are making a comeback with new twists and approaches.
Verizon Visible experienced an attack recently that saw customer accounts taken over and orders placed using stored payment information. Verizon has verified that the hacked accounts were compromised by a credential stuffing campaign.
Florida city of Oldsmar recently experienced a big scare as a hacker was able to penetrate the water treatment plant via remote access software. The hacker then attempted to poison the city's water supply.
President Biden’s Executive Order includes a provision that would require software vendors selling to the federal government to maintain a Software Bill of Materials (SBOM). Unfortunately, it’s not that simple.
When targeted by an Advanced Persistent Threat (APT), an organization needs to be ready to defend from a variety of different attacks coming from different directions, sometimes all at once, and sometimes over a period of time.
Researchers found that hackers were harvesting enterprise login details by overlaying legitimate companies' webpages with fake login prompts in an email phishing campaign.
Suspected Russian and Turkish attackers accuse account owners of copyright infringement, direct them to phishing pages to compromise accounts before demanding ransom from hacked Instagram account owners to restore access.
With evidence pointing to a nation-state attacker behind the attacks on multiple Airbus suppliers, companies should really take supply chain cyber security seriously even for smaller vendors.
International auction house Sotheby’s has disclosed a data breach that leaked sensitive personal details, including financial information and Social Security Numbers.










