A recent breach of biometrics giant Suprema has exposed 28 million records of facial recognition and fingerprint data including unencrypted username-password combinations stored in plain text.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Information from 3.68 million leaked user accounts of Mobifriends dating app allow hackers to exploit password reuse problem and unlock a lot more accounts.
Hackers recently gained access to internal tools at leading email marketing platform Mailchimp, and made use of them in targeted phishing attacks on owners of crypto wallets.
Domain name registrar Web.com announced a data breach that could lead to an explosion of phishing scams as the exposed personal information can be connected directly to websites and their owners.
Unknown hackers reportedly breached AT&T customer email accounts for months via an API security issue to conduct a massive crypto theft scheme estimated at nearly $20 million.
According to iapp, almost half of all data breaches in 2022 began with stolen credentials and ransomware damages are expected to exceed $30 billion worldwide in 2023.
The raid of the hacking forum follows the auction of stolen data from Europol last week and an April leak of information said to have been taken from a contractor used by the Five Eyes intelligence agencies.
As we step into 2024, the IAM landscape continues to evolve. Decentralized identity, identity data engineering, and the integration of analytics and generative AI stand as pivotal pillars that will shape the success of IAM strategies in the coming year.
46% of cybersecurity professionals in a recent survey said their stress level has increased in the past 12 months, and an almost identical percentage – in the same study – indicated they’ve considered quitting the industry because of the stress level.
As children spend more time online and engage with devices at an earlier age, it becomes a collective responsibility of parents, teachers, schools, governments, and businesses to help create a safer internet for children.










