Infosys McCamish Systems has disclosed that the LockBit ransomware gang stole the personal information of 6 million people during the November 2023 data breach which affected companies including Bank of America and Fidelity Investments Life Insurance.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Computer security researchers uncovered a macOS ransomware that exclusively targets computers running the operating system, exploiting macOS users’ false sense of security.
In a recent analysis of the companies that make up the Global 2000, nearly three quarters implemented less than half of all domain security measures. As attacks targeting domains continue to rise, it is critical to determine who is responsible for overseeing their security and the processes they implement.
Intel 471 researchers found that hackers leveraged messaging apps and their infrastructure to distribute malware, steal and store data, and deliver malicious payloads.
The FBI has declared the security breach of its surveillance system by suspected Chinese hackers a major cyber incident with potential national security implications.
Cybersecurity firm Kaspersky Lab has discovered an iOS malware variant spreading via an iPhone zero-click exploit in iMessage. Russia has accused the NSA of targeting the country’s diplomatic missions and Apple of providing backdoors.
Lazarus APT targets the employees of blockchain companies with fake job offers, tricking them into downloading trojanized apps that steal security keys and make fraudulent transactions.
Verizon’s DBIR finds that 82% of data breaches logged in 2021 involved a "human element" such as falling for phishing, re-use of stolen credentials, insider malfeasance or simply causing a configuration error.
Google fixed the Gmail bug that allowed email spoofing, a few hours after a disgruntled researcher published the exploit code. Google had delayed solving the issue by 137 days.
Despite the potential for visual hacking to take place in public, only 30% of business travelers say that their organizations have educated them on how to protect sensitive information.










