Cybersecurity firm Kaspersky Lab has discovered an iOS malware variant spreading via an iPhone zero-click exploit in iMessage. Russia has accused the NSA of targeting the country’s diplomatic missions and Apple of providing backdoors.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Setting the direction towards leading standards in authentication, encryption and data compliance will yield great benefits as these approaches begin to be increasingly implemented across public and private areas.
SDP helps companies to secure the connection when moving data into the cloud for disaster recovery by shifting perimeter defenses to the software of the DR application.
Organizations that adopt Zero Trust Architecture will see an improvement to security, and are also more attractive to insurers and can more easily meet regulatory compliance requirements. But getting started with adoption is often the biggest challenge.
Trend Micro finds the Chinese APT group has compromised at least 70 government organizations over the last two years, in 23 different countries. But the group's logs indicate it has targeted over 110 organizations in 10 additional nations.
The FBI warned that BlackCat ransomware had compromised 60 organizations worldwide as of March 2022 and demanded millions in ransom payment. Alert linked BlackCat to the now-defunct BlackMatter ransomware group.
What should you do if you knew today that a serious data breach would most likely lead to a string of public relations disasters, costing you millions, taking up 20% of the average IT staff day for two years?
Phishing attacks are not going away by any means; however, they can be mitigated with a well-defined plan which includes detection, response, training, and prevention.
In order to respond to cyber attacks, enterprises must invest their time and resources into efficiently training their teams and improving their organizational cyber resilience with the help of effective cyber exercises.
Microsoft reported that the Russian hackers behind the devastating SolarWinds attack are employing similar tactics to worm their way into tech supply chains, looking to establish long-term footholds for espionage purposes.










