North Korean hackers are running cyber attacks that focus on fraudulent cash-outs at ATM machines by hacking payment systems, augmenting with use of social engineering elements.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
US intelligence agencies have issued a public warning indicating that APT groups have developed a "mutli-tool" malware kit that targets a commonly used range of industrial control systems.
US intelligence leak indicates that China is putting an emphasis on targeting enemy satellites in future conflicts. The country is bending its cyber capabilities toward disrupting and taking over communications and surveillance during whatever clashes might come.
The US cybersecurity strategy asks global partners to rally around three central principles: a broad vision of cyberspace grounded in commitment to international law and agreements, fundamental data security and privacy practices, and greater diplomatic involvement across all elements of the digital ecosystem.
U.S. Justice Department released a new drone policy update which mandates a cybersecurity evaluation for new UAS acquisition and protection of privacy and civil liberties.
Grinch bots have been a problem in the retail space for years and even beyond the Christmas season, snapping up everything from concert tickets to new video games.
The EPA memo frames vulnerabilities in public water systems as a potential point of contamination, and thus a public health threat. The new cybersecurity requirements are part of an order to include new elements in periodic sanitary surveys.
New US sanctions have been imposed on the creators of the Triton malware, which was designed to specifically target the control and safety systems of critical infrastructure.
The US authorities offered a $10 million reward for information to identify or locate REvil and DarkSide ransomware gang leaders, and $5 million for their affiliates preparing attacks.
The state-sponsored hackers stole unclassified documents during the raid, but little else is known about what they accessed. The attackers appear to have obtained the API key from a third-party vendor called BeyondTrust.










