A zero-day remote code execution vulnerability in Microsoft Office has come to light, and is considered very serious due to potential for code execution if a victim opens a malicious document in Word.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Many IT professionals are also starting to recognise the ability of Shadow IT to maximise operations; IT departments now set aside 40% of its enterprise budget for Shadow IT and this is only going to increase.
Because gift cards are widely accepted, equivalent to cash, and mostly anonymous, the industry is the target of many criminal schemes. How do you avoid becoming a victim of gift card fraud?
New, decentralized Web3 technologies stand to address virtually all concerns of the old internet, but there’s a catch. All too often these networks are still built upon legacy infrastructure, and, as such, are exposed to many of the same defects.
Fraudster revealed how criminals make money using underground bots that steal multifactor authentication codes and link stolen cards to contactless payments like Apple Pay.
Digital Shadows Photon Research team found that over 24 billion stolen user credentials were available for sale on the dark web market in 2022, an increase of 65% in two years.
Caesars Entertainment quietly disclosed its own recent cyber attack in a SEC filing. Unlike MGM, Caesars appears to have skated through their own incident by making a $15 million ransom payment to the hackers.
The LockBit gang is the latest ransomware-as-a-service outfit to push the envelope, this time by offering the criminal underworld's first known bug bounty program.
Marriott suffered its second large data breach through two employees’ login credentials that exposed personal information of 5.2 million guests from their customer loyalty accounts.
KELA found that the sale of network initial access methods in underground forums was worth millions of dollars, and brokers resorted to selling in private conversations.










