Cosmetics giant Estée Lauder is notifying customers of a ten-month-old data breach stemming from Oracle EBS that leaked the personal information of its employees.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The AI agent incident is described as "unprecedented" as the model went to "extreme lengths" to achieve a security testing goal, independently opting to find a path to internet access and break into Hugging Face to obtain secret solution information.
A ransomware attack at Coca-Cola’s Fairlife dairy has temporarily suspended U.S. operations after the company shut down some production-related systems to contain the threat.
World Leaks ransomware gang has published sensitive files, including blueprints and supplier lists, stolen following a data breach at India's largest nuclear power plant.
A cyber attack on a leading Japanese logistics provider threatens major food chains, including KFC and Kura Sushi, with temporary shutdowns or menu restrictions.
Security teams have relied on scheduled assessments for years because the model worked. Today, that assumption no longer holds. Attackers don't operate on that schedule anymore.
Recent guidance establishes best practices for development of coordinated vulnerability disclosure (CVD) programs. This comes as both public and private organizations are grappling with the prospect of near-term "machine speed" discovery of vulnerabilities by attackers wielding AI tools, and looking at potential major overhauls to their remediation and reporting processes.
U.S. federal agencies and 15 U.S. allies warn of a state-sponsored Russian hacking campaign that targets critical infrastructure organizations using vulnerable and misconfigured routers.
The new "Gold Eagle" proposal from the White House looks to establish an AI security clearinghouse to be shared by government and private critical infrastructure companies, in the interest of coordinating cyber defense efforts as frontier AI models reshape the threat landscape.
Russian phishing campaign targets commercial messaging apps, specifically Signal, to steal recovery keys, access historical messages, private and group chats, and take over accounts.










