Initial access broker with close links to ransomware groups is targeting organizations with Microsoft Teams phishing attacks, with malicious links leading to a malicious SharePoint-hosted file.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Japanese electronics company Casio is still reeling from a ransomware attack that disrupted its systems, two weeks after the incident occurred and with no expected recovery timeline.
Healthcare giant CVS exposed over a billion health records through a misconfigured cloud database leak, including visitor and session IDs, device information and multiple records for medications.
A recent cyber attack on the Canadian electric utility, Nova Scotia Power, disconnected power meters, preventing the company from reading and sending accurate bills.
Federal agencies urged FCC to consider China Telecom a national security threat, pointing to concerns that the company is vulnerable to exploitation, influence, and control by the Chinese government.
Australian companies that have connections to the country's critical infrastructure might have no choice but to allow the government to step in during cyber attacks, if new legislation proposed by the Morrison government is approved.
Boards are starting to ask the right question about AI risk. Unfortunately, many organizations still don’t have a credible answer.
For the most part the exposure appears to have been limited to names and bank details for both active members of the UK armed forces and veterans. The UK government has named SSCL, a business services provider, as the source of the third party breach.
Twitter hack of high-profile accounts a result of employees tricked into giving up access to support tools that led to compromised accounts posting Bitcoin doubling scam.
Unit 29155's actions since 2020 include cyber attacks on a number of federal agencies and critical infrastructure companies in a variety of countries. But the group seems to have switched most of its focus to Ukraine in the weeks prior to the 2022 military invasion.










