News has recently emerged that the US Census Bureau was compromised by a cyber attack in January 2020 which was traced back to a Citrix vulnerability that had just been publicly disclosed about a month prior.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The City of Dallas, Texas, has suffered a Royal ransomware attack that impaired critical IT systems, including computer-assisted police dispatch and fire response services.
A new vulnerability chain discovered by Oasis Security can compromise the Claude AI chatbot and does not require the target to have the app installed or even have an account with the service. The attack chain instead begins with a malicious webpage doctored up to place highly in search results for Claude, which passes the user to a pre-filled chat URL that exploits other vulnerabilities in the AI agent.
In the wake of news that OpenAI agents independently breached Hugging Face and accounts with several other services, Anthropic has conducted a sweeping review of Claude activity and found that its own AI models have hacked their way to unauthorized internet access and into other organization's networks on at least three occasions.
Facial recognition firm Clearview AI has become the victim of a data breach after a hacker “gained unauthorized access” to the company’s entire client list, exposing for the first time the details of the organizations which work with the controversial firm.
Clearview AI will be fined £7,552,800, and has been ordered to stop collecting facial recognition data in the UK and to delete all of the data it had previously collected.
Software AG, Germany's second-largest software vendor, fell victim to a Clop ransomware attack that compromised company files and employee information.
Clop ransomware has breached dozens of organizations, including the City of Toronto, Virgin Red, and Pension Protection Fund via the GoAnywhere vulnerability.
Clop ransomware gang breached 130 organizations via Fortra GoAnywhere managed file transfer tool and stole 1 million CHS Healthcare patients' records.
Clop Ransomware gang encrypted South Korean Retail Operator E-Land after secretly stealing 2 million credit card details for more than a year using a stealth POS malware.










