With the first new release since 2021, the one thing that hasn't changed about the OWASP Top 10 is that "broken access control" is still the lead category after all this time, present as a security risk in 3.73% of the apps that were tested.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
While cryptocurrencies have gone from red hot to full on meltdown in recent months, threat actors don’t show any signs of shying away from finding new and innovative ways to pursue this lucrative and relatively new financial category with increasingly complex and stealthy crypto-stealers.
Government agencies, from the municipal to the federal level, have the largest and most varied number of use cases that require a Zero Trust Architecture , because of the range of systems they operate and the weaknesses of OT security.
Authorities in the U.S. and Australia have warned that the BianLian ransomware gang has abandoned the double extortion model for purely data extortion attacks. More groups are likely to follow suit and forego the hassle of developing and managing the encryption and decryption process in favor of a less complicated attack,
Unknown hackers reportedly breached AT&T customer email accounts for months via an API security issue to conduct a massive crypto theft scheme estimated at nearly $20 million.
Cloud computing company ServiceNow has confirmed a security breach that affected enterprise customers’ instances stemming from an unsecured REST API endpoint.
Marsh report shows that companies purchasing cyber insurance in 2019 more than doubled since 2014 as more and more companies are recognizing cyber threats as a critical business risk.
ChatGPT has answers for almost everything, but there’s one answer we may not know for a while: will this tool turn out to be the genie its creators regret taking out of the bottle over unintended consequences in AI for cybersecurity?
The economic landscape requires due diligence when it comes to enterprise level SaaS spending. Shadow IT hides wasteful spending, and organizations must manage costs associated with bulky and hidden SaaS platforms.
SIM swap attack is on the rise which includes the recent Twitter hack on their CEO’s account. Attackers used social engineering to convince telco to switch target’s number to their own SIM cards.










