Centers for Medicare & Medicaid Services (CMS) is notifying 946,801 Medicare beneficiaries that the May 2023 MOVEit breach compromised their protected health and personal information.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Codecov supply chain attack remained undetected for months and likely affected Google, IBM, HP, and others. Hackers stole user data from the company’s continuous integration environment.
Recent class action lawsuits filed against popular crypto exchange Coinbase accuse the service of cybersecurity failures in preventing crypto theft and misuse of fees that were ostensibly to be put toward safeguarding accounts.
Crypto exchange Coinbase has said that it will reimburse customers that lost funds due to a recent data breach, and is also setting aside a $20 million reward for information leading to the arrest and conviction of the hackers.
Fraudsters stole cryptocurrency from 6,000 users in a Coinbase hack attributed to a multi-factor authentication flaw that allowed them to exploit the account recovery process.
Are you a victim of cryptojacking? Both individuals and organizations are now at risk of this new hacking approach to tap into your computer’s processing power. Most famously, Coinhive has been promoting this controversial new practice to tap for mining the cryptocurrency Monero.
When the first reports of the Colonial fuel pipeline attack appeared, it was natural to assume the worst but an investigation by the FBI has fingered a ransomware-as-a-service operator rather than a known state-backed group.
A new password leak, the largest to date, contains over 8.4 billion credentials among which may have been the account used to get into Colonial Pipeline's network.
After losing millions to the 2021 ransomware attack that cut off fuel to parts of the United States, Colonial Pipeline may be facing more financial damage if a fine proposed by the DOT holds up.
Some of these new DHS cybersecurity regulations have been in the works for some time, but the rapid rollout of changes comes in response to the Colonial Pipeline ransomware attack that created temporary gas shortages.










