New studies from FireEye Mandiant Threat Intelligence and Google’s Project Zero found that 2021 was a record year for zero-day vulnerabilities, more than doubling the amount seen in 2020.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
It has been discovered that the FBI quietly held on to the Kaseya decryption key for three weeks prior to making it available to the public in a bid to "disrupt" the attack.
A recently discovered trojan, PDFReader, exploits Facebook Ads Manager by using a legitimate-looking digital security certificate to access and grab cookies from victim’s Facebook session.
Dole Food Company has confirmed a ransomware attack that disrupted regional operations. Leaked memo shows that production was temporarily halted in several plants and deliveries suspended.
A ransomware attack on fintech firm Marquis Software Solutions has impacted at least 74 banks and credit unions across multiple states, leaking customer data of over 400,000 people.
China publicly accuses CIA of 11 years of cyber espionage however the report has little to offer as hard evidence and there is no previous reference on the alleged hacking group.
Privileged Access Management (PAM) plays a crucial role in cyber security by providing granular control over identities and accounts, particularly those with elevated access privileges within an organization.
Apple attributes iPhone security to its "walled garden" approach. Among other claims, Apple says that an Android device is up to 47 times more likely to contract malware and that allowing app sideloading would attract a wave of cyber crime to the iOS platform.
As cyber crime groups grow and "corporatize," they find themselves under pressure to keep up with wages. Operating expenses are largely devoted to paying employees and contractors for their work, with 80% a typical number.
Shortly after a major international law enforcement takedown, the LockBit ransomware group says that it is back online and has launched a new data leak site complete with "countdown clocks" for its current victims.










