In today’s threat landscape, security professionals aren’t short on signals. Rather, they’re drowning in them. From endpoint telemetry to user activity to cloud platform events, we’re collecting more indicators than ever before. Despite the volume of alerts, or perhaps because of them, organizations still struggle to detect threats early and accurately.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A recent spate of crippling ransomware attacks against healthcare organizations signals that these assaults remain a major threat. Healthcare leaders should focus their efforts by moving beyond a prevention strategy and focusing on developing a proactive preparedness plan.
Cryptojacking incidents are increasing faster than any other types of cyber incident with reports indicate that it has tripled since 2017. Why are cryptojacking rates on the rise and how do you recognize it?
Microsoft has released security patches for the zero-day vulnerability chain dubbed ToolShell, capable of remote code execution on SharePoint, resulting in the exploitation of at least 54 organizations worldwide.
A cyber attack that continues to impact the Stryker medtech group's business operations as of this writing has been linked to a pro-Palestine hacking group thought to be supported by the Iranian government.
A whistleblower says that Ubiquiti downplayed its data breach to protect its stocks. He claims that Ubiquiti was the source of the breach, and hackers gained administrative rights.
Choosing whether to pay ransom isn’t a moral or ethical decision. It is always a business decision based on risk reduction and protecting the interests of an organization’s customers, employees and key stakeholders.
The New York Department of Financial Services (NYDFS) Cybersecurity Regulation blazed a trail in 2017, forming the basis for similar laws for other industries in other states. Currently, the regulation serves as a useful model for managing cybersecurity risks, regardless of industry.
Recent research shows a sharp increase in Magecart attacks with a peak experienced in July when 962 sites were hit in one day and 17,000 domains infected through misconfigured Amazon S3 buckets.
FlexBooker, a commonly used appointment scheduling and calendar service, is apologizing to its customers after 3.7 million records appeared on a dark web hacker forum following a DDoS attack.










