A U.S. nuclear agency was among the victims of the SharePoint vulnerability chain, which was exploited to compromise over 54 organizations across the United States, Europe, and Asia.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
By actively choosing to encrypt all data, all files, no matter where they are stored, we can finally build security into the only piece which has value – the data.
Newly uncovered cyber espionage scheme shows Iranian hackers using unpatched VPN vulnerabilities as a point of entrance into the networks of government and private sector organizations.
The reduction in CISA’s budget and workforce comes at a time when cyber threats are increasing in volume and sophistication. Private sector teams and state and local agencies must now take the lead in defending their assets.
Israel may become a big export player for both offensive and defensive cyber weapons used for cyber espionage as it now takes as little as four months for approval of sale.
Cox communications data breach notification disclosed that unauthorized individual(s) accessed sensitive customer information after impersonating the company's support agent.
Phishing emails were sent to DoD vendors to capture login credentials on lookalike vendor payment website. The hackers then routed payments to shell entity.
The EU Cybersecurity Commission will create a Joint Cyber Response Unit to coordinate response to security incidents, share information, forewarn members and increase resiliency.
The Russian ransomware gang ALPHV/BlackCat has threatened to leak 300 GB of top-secret and classified military documents it stole from a Pentagon contractor.
Sprint claims recent data breach will not cause risk to fraud or identify theft but the compromised customer information could lead to SIM swap attacks and allow attackers to take over victim’s accounts.










