Chainalysis finds that state-backed North Korean hackers are more reliant than ever on illicit crypto exchanges in Russia to move money. North Korean hackers are thought to have stolen $3.54 billion in cryptocurrency over the last seven and a half years.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A massive data leak stemming from a cyber attack on a third-party subcontractor has affected Swiss banks UBS and Pictet, as well as over a dozen other multinational companies, potentially including auditing firm KPMG.
Compliance requirements do not always reflect the complexities of new cloud systems or indicate where problems with traditional security approaches do not work as well for cloud security.
UnitedHealth Group has released further details about the devastating Change Healthcare attack that caused widespread damage throughout the US, taking large chunks of revenue from some care providers and in some cases keeping patients from needed medication. The group has confirmed that it made a ransom payment to restore service.
The only way to truly understand and react appropriately to a security event is with context. Without context in detection and response, alerts become noise. Context lends a level of intelligence that aids in proper, proactive response.
With an immediate need to remedy the headcount shortage in cybersecurity, staffing a security operations center (SOC) is only half the battle though. We need to focus on cultivating our workplace culture to better retain talent.
An attacker could use a vulnerability to issue fake alerts via the Emergency Alert Systems. The vulnerable software is in the possession of television and radio stations throughout the country, who are being called upon to download a software update.
The Chinese government claims that the NSA is conducting cyber espionage with repeated attacks on an aerospace and space research university funded by Beijing.
The attribution of the Wuhan cyber attack was followed by an announcement from Chinese authorities that a "highly secretive global reconnaissance system" run by US intelligence agencies would be exposed.
A new report cites insider sources in naming Charter Communications, Consolidated Communications and Windstream among the breached US telecom companies. The sources also state that the Salt Typhoon campaign may have started in late 2023.










