Many IT professionals are also starting to recognise the ability of Shadow IT to maximise operations; IT departments now set aside 40% of its enterprise budget for Shadow IT and this is only going to increase.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Open-source software company Red Hat has confirmed a security breach on one of its GitLab instances after a threat actor claimed to have stolen nearly 570 GB of data from across various repositories.
RansomHub has claimed credit for the new cyber extortion attempt on Change Healthcare. The group says that it stole 4 TB of data that includes sensitive personal information, including financial information and medical records belonging to US military personnel.
Final adoption of the EU AI law is expected to be a formality at this point, but is not slated to take place until April 2024. From there, individual components of the regulation go into effect anywhere from 6 to 36 months from that date.
Nokia's Threat Intelligence Report noted an increase in IoT attacks stemming from poor security practices, the use of automated tools by attackers, and Internet visibility of devices.
Broadband Provider Brightspeed has experienced a data breach that exposed over 1 million customers, with hackers threatening to disconnect home internet customers.
Attackers who are blocked by strong defenses in other areas, are exploiting exposures from mismanaged machine identities to exploit the trust these systems are designed for.
The cyberattack on Colonial Pipeline was a big lesson. It is imperative that critical infrastructure companies uplevel their protection against modern security risks by using modern techniques and automation to comply with new cybersecurity regulations.
A threat actor sold for an undisclosed amount a toolkit to conceal and execute malicious code without detection on most graphics cards, including AMD, Nvidia, and Intel.
Argentina suffered one of the most catastrophic data breaches possible last week, as access to a government database containing national ID card information for every citizen was found for sale on the dark web.










