SolarWinds hack may impact cloud services from major providers such as Microsoft and Amazon, especially since the Orion software stores API keys and other security credentials.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Cloud solution provider PCM claimed minimal impact to their customers even though recent breach of Office 365 administrative credentials could lead to exposure of personal data and sensitive business documents.
In many ways, the benefit of cloud computing is also its main drawback. How can organizations keep their IT environments secure while leveraging the full benefits of a cloud-native approach?
A data breach has impacted Otelier, exposing millions of hotel guest records after a threat actor breached the cloud-based hotel management software provider’s AWS S3 bucket.
Cloudflare, one of the world's largest content delivery networks and web security service providers, is taking on AI bots with a new "Easy button" that simplifies the shutdown of unauthorized content scraping.
Cloudflare reports attackers using the HTTP/2 protocol zero-day vulnerability to conduct over 1,100 DDoS attacks at over 10 million requests per second since August, and 184 broke the previous record of 71 million requests. At its peak, 200 million requests per second was observed.
CloudSphere says configuring cloud access control was a major problem for most organizations and many companies were unaware that their cloud platforms had been illegally accessed.
Centers for Medicare & Medicaid Services (CMS) is notifying 946,801 Medicare beneficiaries that the May 2023 MOVEit breach compromised their protected health and personal information.
Codecov supply chain attack remained undetected for months and likely affected Google, IBM, HP, and others. Hackers stole user data from the company’s continuous integration environment.
Recent class action lawsuits filed against popular crypto exchange Coinbase accuse the service of cybersecurity failures in preventing crypto theft and misuse of fees that were ostensibly to be put toward safeguarding accounts.










