When you pirate the Game of Thrones, you win or you get malware. Or perhaps fall victim to a phishing attack. Hackers are targeting millions of fans who want to watch the TV show for free.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
XIoT devices are laden with security risks. 68% have a known vulnerability with a CVSS score of at least 8 and 18% are carrying a vulnerability of at least 9. And the average organization has three to five XIoT devices per employee.
Despite massive data, risk and compliance challenges, today’s work-from-home environment has accelerated our reliance on electronic communication apps like WhatsApp, Zoom, Microsoft Teams and more, ushering in a monumental shift in the way we communicate and conduct business.
CISA: Admin Credentials of a Former Employee Leveraged to Compromise a State Government Organization
The Cybersecurity and Infrastructure Security Agency (CISA) and Multi-State Information Sharing and Analysis Center (MS-ISAC) discovered that a threat actor compromised a state government organization using a former employee’s leaked admin credentials.
Qantas has announced a new compensation policy that reduces executive bonuses for the CEO and their team when damaging cybersecurity incidents take place. The recent data breach will cost Qantas CEO Vanessa Hudson AUD 250,000 of her expected total annual compensation of AUD 6.3 million.
Researchers recorded the largest Magecart attack that compromised over 2,000 Magento stores and exposed the private and financial details of over 10,000 customers.
Deepfakes pose significant challenges for businesses, especially as deepfake technology becomes more accessible to cyber criminals. Spotting a deepfake can be challenging, requiring vigilance and education of their common flaws.
Cloud infrastructure provider Digital Ocean severed ties with the marketing automation provider Mailchimp after a security breach exposed its customer email addresses.
A ransomware attack on eResearch Technology, the firm behind three-quarters of FDA drug approvals, slowed down clinical trials for several research facilities.
A recent audit of websites by the well-known Online Trust Alliance has revealed something that many consumers have long suspected. Financial institutions are the least trusted when it comes to cybersecurity. Although the results are no doubt coloured by the inherent fear that many consumers have when it comes to the security of their money, it should still be a worry for banks which have long struggled with issues around online trust.










