Microsoft Azure Cosmos DB cloud databases have had their read-write keys exposed by a flaw that has been present since 2019, allowing an attacker to not just access the contents but also to change or delete them.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
In addition to the DDoS campaign and claimed theft of Microsoft accounts, Anonymous Sudan has busied itself with a campaign of attacks against European banks as of late. Microsoft says there is no evidence of a data breach.
A third-party data breach affecting Oxford University’s CareerConnect job portal has exposed personal information belonging to students, alumni, researchers, and employers.
New, decentralized Web3 technologies stand to address virtually all concerns of the old internet, but there’s a catch. All too often these networks are still built upon legacy infrastructure, and, as such, are exposed to many of the same defects.
The 2021 World Economic Forum (WEF) Global Risk Report has named "cybersecurity challenges" as the 4th most pressing danger to the global economy.
Scattered Spider didn’t need zero-days, malware, or a government’s budget to bring a Fortune 500 company to its knees. They didn’t even need to break in. They just logged in.
For most organizations, especially small and mid-market businesses, tracking who is behind an attack delivers far less value than understanding what attackers are doing and how to defend against it.
A U.S. nuclear agency was among the victims of the SharePoint vulnerability chain, which was exploited to compromise over 54 organizations across the United States, Europe, and Asia.
New AI security guidelines offers a general overview of expected risks and threats from the initial design process, through the development life cycle and deployment, and all the way through ongoing operation and maintenance after deployment.
Polymorphic phishing attacks are highly effective as they use randomization of email components which are hard to be detected by signature-based email security tools.










