How do you know your MSSP, managed security service provider, can be trusted and is offering higher value security services that extend beyond simple monitoring and analysis?
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
When implemented holistically, a zero-trust manufacturing architecture will ensure that a product’s firmware, data and digital credentials can be trusted through every step of the manufacturing supply chain.
A Japanese government official disclosed a data leak that exposed Olympics ticket buyers' account credentials but the Olympics organizers denied being the source of the breach.
Open source software has worked its way into the vast majority of organizations around the world. That makes open source security a universal business issue, and a new report from security firm Veracode presents some very troubling findings.
The convenience of digital gift cards comes with added vulnerability as cybercriminals and bad actors have found particularly devious ways of defrauding both the buyers and sellers.
Unit 29155's actions since 2020 include cyber attacks on a number of federal agencies and critical infrastructure companies in a variety of countries. But the group seems to have switched most of its focus to Ukraine in the weeks prior to the 2022 military invasion.
There are two pieces of legislation already in front of Congress that would set reporting requirements for ransomware payments, each proposing different time windows for different industries and company sizes. A third now seeks a 48-hour limit.
CISA warns about the fast flux DNS evasion technique used by ransomware gangs and state-sponsored threat actors to shield cybercrime infrastructure, threatening national security.
Recent SWIFT report shows an evolution of cyber threats to international payment flows with cyber criminals becoming increasingly sophisticated in evading detection when carrying out fraudulent payment transactions.
A hacker is selling multiple employee databases belonging to several Fortune 500 companies, including Tata Consultancy Services, General Electric, and McDonald's.










