New studies from FireEye Mandiant Threat Intelligence and Google’s Project Zero found that 2021 was a record year for zero-day vulnerabilities, more than doubling the amount seen in 2020.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A Microsoft whistleblower says that the Active Directory security flaw that led to the SolarWinds breach was ignored because, at the time, the company was preparing a major bid for the government's cloud computing business.
The software supply chain attack surface is a lot more complicated now, and can be compromised at every stage. Developers are the new high-value targets and we have seen developers fall victim to stolen credentials and secrets, compromised workstations, CI/CD attacks and malicious packages that end up in source code.
Security automation is increasingly becoming a necessity in order to keep up with the cyber threats, but security analysts report significant increased stress on the job driven by fear of missing alerts.
Molson Coors filed a security incident with the Security and Exchange Commission acknowledging a cyber attack that took its systems offline, suggesting a ransomware attack.
For organizations that grasp a vision of the future and begin to prepare for it now, vulnerability management will grow to be an integral part of their business risk management plan.
Criminal gangs behind ransomware attacks will continue to adapt their techniques to maximize their returns. They are increasingly using novel tactics to circumvent traditional security solutions and one of the most significant shifts is that attacks involving data exfiltration are now the norm.
Red Canary researchers said Silver Sparrow macOS malware infecting about 40,000 Macs using both Intel and ARM chips could deliver malicious payloads at a moment's notice.
The annual ENISA threat landscape report is one of the most helpful tools for keeping a finger on the pulse of current trends in cyber threats. This year's report highlights the dramatic rise in denial of service and cryptojacking attacks.
More than 3,000 #cybersecurity specialists and 1,258 algorithmic models worked 24 hours around the clock to fend off 2.2 billion cyber attacks on Singles Day. Just another day's work for Alibaba defending 300 million hacking attempts per day.










