Panda Express, the largest Chinese fast food chain in the US, leaked sensitive personal data during the March 2024 cyber attack that affected the parent company’s corporate systems.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
An audit report reveals the Truebit crypto hack was caused by a relatively simple overflow vulnerability, one that allowed an attacker to abscond with the equivalent of $26 million from the Truebit Protocol.
The court will determine how the nearly 35-year-old CFAA is interpreted. The worst possible interpretation could put employees and contractors at the mercy of the terms of service of systems and software.
According to anonymous sources, the French authorities have decided to approve the use of Huawei equipment but only in non-core parts of the 5G network.
Your people are your organization’s greatest asset, but their digital identities are also your most significant risk areas. No other facet of your IT environment is more frequently attacked. A compromised identity is the easiest way into your digital infrastructure and a gold mine for hackers.
Mobile app developers are realizing that with in-app security they can exceed third-party on-device security that relies on blacklists by only allowing the app to communicate with whitelisted servers. Mobile apps need constant monitoring and closeknit, developer-driven protections against today’s clever cybercriminals.
Even though the data of 538 million Weibo users sold on dark web is limited, the information still posed a risk especially to the anonymous users sharing unfiltered news around the country.
Codecov supply chain attack remained undetected for months and likely affected Google, IBM, HP, and others. Hackers stole user data from the company’s continuous integration environment.
With the Play Store distributing malicious apps like fake WhatsApp and malware, is downloading only from trusted Android stores still a relevant approach?
A spyware vendor in Spain has been linked to a zero-day exploitation framework that impacted Windows, as well as the Chrome and Firefox browsers, from 2018 to 2021. Google researchers present markers found in its code including a script that is signed by the company.










