After losing millions to the 2021 ransomware attack that cut off fuel to parts of the United States, Colonial Pipeline may be facing more financial damage if a fine proposed by the DOT holds up.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A more precise allocation of power, policy-based management, activity tracking and automated procedures can add a layer of security to a category that is inherently risky while maintaining administrators should do their tasks quickly and successfully.
President Biden’s Executive Order includes a provision that would require software vendors selling to the federal government to maintain a Software Bill of Materials (SBOM). Unfortunately, it’s not that simple.
LabCorp experienced a second data leak in a year with more damaging information exposed this round that includes medical records and social security numbers.
The attack the food delivery company DoorDash appears to have been part of the ongoing "0ktapus" campaign, which first made news when it ensnared Twilio. Customers may have had contact information exposed along with order information and partial credit card information.
If cyber insurance providers want to create a better system that can reduce claims and better protect their policyholders, they cannot ignore the biggest driver of cyberattacks – password security.
The Inferno Drainer malware that plagued the crypto world throughout 2023 ultimately compromised about 130,000 victims and stole about $87 million in total, according to a new report from Group-IB. It was part of a broader movement of "crypto drainer" services that some security experts believe is poised to become the next big thing in cybercrime in 2024.
With the doubling of security vulnerabilities found in popular open source projects between 2018 and 2019, many are concerned on the record being broken again in 2020.
A massive 600 gigabyte file containing about 2.2 billion breached accounts has been spotted floating about the dark web, freely available to anyone who cares to download it via torrent.
A supply chain attack on a business partner will cost semiconductor giant Applied Materials $250 million in the coming quarter due to disruption of upcoming shipments. Ransomware attack on MKS Instruments is suspected to be the cause.









