Study on 9 billion recovered login credentials shows significant password reuse which can help cybercriminals conduct credential stuffing attacks and possible account takeover.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Tardigrade malware could shut down biomanufacturing facilities, exfiltrate data, deliver ransomware, and act as a backdoor for hackers to perform custom operations.
The fallout from the Log4j vulnerability has prompted bipartisan action to beef up open source software security. Proposed act would task CISA with developing a risk framework to evaluate open source code used by the federal government, and could be passed on to critical infrastructure businesses.
The final amount of stolen crypto is still being tallied as investigations continue, but about 56 BTC (about $1.5 million) has been confirmed to be lost. General Bytes has over 15,000 bitcoin ATMs in circulation in over 100 countries.
PCBA manufacturer Keytronic has reported that the Black Basta ransomware attack in May 2024 resulted in over $17 million in direct costs and lost revenue.
The emergence of Venice.ai AI chatbot may mark the beginning of a new stage of the security race. Available for free via the "clear web," the service promises capabilities on par with ChatGPT and other popular models but with no guardrails or security restrictions in place.
It took two months for the public to learn of the Blackbaud ransomware supply chain attack, and has led to data breaches in more than a hundred universities and nonprofit organizations.
Security vulnerability that impacts an older form of a BlackBerry industrial systems OS, still in use in both industrial settings and hospital equipment, was discovered by Microsoft researchers in April of this year. Many are only now learning about it.
The BlackByte ransomware gang's "2.0" reboot of their data leak site sports a new "feature" for its victims: a tiered payment system that allows for smaller payments to delay publication of sensitive data, or to simply download and recover it prior to having it dumped for public viewing.
BlackByte ransomware group attacked organizations in at least three critical infrastructure sectors and multiple foreign and U.S. Businesses, according to the FBI and U.S. Secret Service. San Francisco 49ers also suffered ransomware attack.










