Threat actors hijack thousands of reputable domains and subdomains to deliver over 5 million malicious emails daily in a mass ad fraud campaign dubbed SubdoMailing.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The Biden administration is examining the possible national security risks of having thousands of Chinese smart cars on US roadways. One possibility is that all of these cars could be remotely disabled at once, but there are also data privacy concerns.
Addressing automation through a powerful patch management system and streamlining device control can allow IT teams to consistently and more cost-effectively monitor gaps in security as well as proactively enhance enterprise security measures.
American moving and self-storage rental company U-Haul suffered a data breach affecting a customer records system, impacting 67,000 individuals in the US and Canada.
OpenAI is facing a number of copyright lawsuits that could shape the future of generative AI, and one of the biggest comes from the New York Times. OpenAI is now accusing the paper of what is essentially evidence fabrication, claiming that it hacked ChatGPT to produce results containing content from its articles.
Cyber recruitment requires an overhaul, with new practices needing to be incorporated. What's the connection between cyber recruitment and "The Traitors," and what insights can we learn?
The Biden administration will sign an executive order to bolster port cybersecurity with additional actions to enhance maritime cybersecurity, secure supply chains, and strengthen the US industrial base.
CISA: Admin Credentials of a Former Employee Leveraged to Compromise a State Government Organization
The Cybersecurity and Infrastructure Security Agency (CISA) and Multi-State Information Sharing and Analysis Center (MS-ISAC) discovered that a threat actor compromised a state government organization using a former employee’s leaked admin credentials.
Shortly after a major international law enforcement takedown, the LockBit ransomware group says that it is back online and has launched a new data leak site complete with "countdown clocks" for its current victims.
Although it can be easy to get caught up in the novelty and buzz surrounding new security tools, it isn’t always in a company’s best interest to continue adding to their tech stack before spending time to ensure that the current systems are being utilized to the best of their ability.










