5G networks are exciting and open the door to many new possibilities for IoT, however it also comes with security risks as manufacturers rush to dominate the new untapped market their devices.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Thomson Reuters database leak exposed 3TB of platform information and customer data after the media company left three databases unsecured and publicly accessible for days.
Chinese hackers have attempted to interfere in US elections before. Anonymous official sources have spoken out claiming that this year's free-ranging espionage campaign is seeking phone data from senior officials and leading candidates regardless of party affiliation.
Popular domain registrar and web hosting company GoDaddy was slapped with an FTC order mandating a robust information security program for allegedly failing to stop data breaches and misleading customers about its cybersecurity practices.
A API vulnerability documented by independent security blogger "bobdahacker" created a path to replacing the FIFA World Cup matches playing out on televisions and devices all over the world with any video of the attacker's choosing.
Healthcare web application attacks increased by 51% since the introduction of COVID-19 vaccines. Cross-site scripting (XSS) and SQL injections were the most detected by volume.
Russian hackers are exploiting hotel Wi-Fi networks at various locations that attract corporate travelers to compromise Microsoft 365 accounts and install malware.
Recently discovered TikTok's security flaws make it possible to spoof the source of SMS messages, alter people's feeds and accounts, and also access sensitive personal information via API calls.
While we often think about malicious users when we speak of insider threats, the "real" problem lies with users that may unintentionally be putting their organizations at risk. This includes users that get phished, bypass controls for convenience or efficiency, and connect their own devices to the corporate networks.
New study suggests that a combination of broken and poorly configured SIEM rules are providing organizations with a far lower level of threat coverage than they believe they have.










