Human capital management (HCM) software giant Workday says that a social engineering data breach on a third-party CRM system has impacted its clients’ business information.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The mass shift to working from home precipitated by the Covid-19 pandemic created massive security challenges. A full 30% of remote workers under the age of 24 say that they circumvent or ignore security policies when they get in the way of getting work done.
A strong identity management strategy involves monitoring user behavior and activity, verifying user identity with strong authentication solutions and cybersecurity education and awareness.
Internet of Things devices may be more numerous than ever before but that does not mean they are safer. This World Password Day, remember that device security starts with you.
Scattered Spider, ShinyHunters, and LAPSUS$ are the three groups involved, and have collectively been the most active of the major cybercrime gangs over roughly the past year. The groups all had prior ties via "The Com," a broader collection of cyber criminals that loosely affiliate and come together for singular projects in a fluid way.
Final adoption of the EU AI law is expected to be a formality at this point, but is not slated to take place until April 2024. From there, individual components of the regulation go into effect anywhere from 6 to 36 months from that date.
Nikkei, the world’s largest business news outlet, which owns over 40 affiliates, including The Financial Times, and has more than 3.7 million paid subscribers and over 1.7 million daily readers, has confirmed a data breach that leaked personal information after threat actors compromised its Slack accounts.
Norfund, the sovereign wealth fund of Norway, has lost over $10 million to BEC scam and it appears that the scammers had spent months inside the networks leading to the fraud.
The secret meeting took place in Geneva in December 2024. The source says that the remarks were "indirect" and "somewhat ambiguous," but were enough to implicate Volt Typhoon and the Chinese government in the cyber attacks that have plagued US critical infrastructure.
Organizations need a modern detection and response strategy that’s more than just more technology and more people. It needs a connective tissue.










