A 19-year-old "security specialist" has found a vulnerability in third party software used by certain Tesla vehicles, which allows the remote control of certain functions such as the engine and the security system.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
While compliance leaders must have an abundance of technical prowess, truly successful compliance executives today are the ones that seamlessly blend hard with soft skills.
Hacking group ShinyHunters released Pixlr's 1.9 million stolen user credentials on a hacker forum. The data was accessed from an AWS S3 bucket while breaching sister site 123rf.
Iranian hackers are extending their attacks to political, diplomatic and military targets in U.S, Australia, and U.K. It now appears to be part of a long-term, state-sponsored cyber hacking campaign by Iran.
Hackers were impersonating cybersecurity companies by sending phishing emails asking the target to callback to resolve potential network compromise. Victims are then guided to install remote administration tools.
Some security experts worry that open source Twitter code would thus not be tremendously helpful in revealing how the system selects content, but would create avenues of attack for threat actors that could now scrutinize its internal workings.
Apple generally does not release security updates in between iOS version updates. This practice may be changing, however, as AI hacking drives faster development of tools and quicker identification and exploitation of known vulnerabilities.
Customers affected by an Azure outage on July 30 were likely trying to access it during a newly confirmed DDoS attack, which Microsoft says was exacerbated by an error in the implementation of their automated defense systems.
A cybersecurity arms race between business security teams and the hacking communities is forcing one another to innovate and increasing the complexities needed to gain access to protected data.
The Ragnarok ransomware gang has scrubbed its public presence from the dark web, leaving behind a master decryptor key at the "leak site" it used to blackmail its victims.










