The IoT Cybersecurity Improvement Act of 2020 is now federal law, meaning that US government "smart devices" will be subject to a new and more stringent set of security standards.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
High-profile cyber attack that struck British budget airline EasyJet may have been carried out by Chinese hackers who have stolen email addresses and travel details of millions of passengers.
Planning for cyber resilience requires making assumptions about the future as well as anticipating trends and developments that could gain significance over time. Here are some trends that could potentially dominate headlines in 2022.
A joint cybersecurity advisory warns of Iranian hackers using brute-force attacks to compromise critical infrastructure to obtain initial access for sale to other threat actors.
A strong recovery and resilience strategy will ensure that crypto and DeFi firms are able to rebound from cyber attacks with minimal disruptions to their operations, mitigating losses for their investors and users.
Defending organizations utilize AI-powered email security measures to enhance network protection, detect advanced malware and ransomware, optimize critical data center processes, improve threat response times, and reduce human error. Unfortunately, threat actors have also identified the benefits of AI technology.
SIM swap attack is on the rise which includes the recent Twitter hack on their CEO’s account. Attackers used social engineering to convince telco to switch target’s number to their own SIM cards.
A massive brute force password attack involving 2.8 million IP addresses targets VPN devices from various companies including Palo Alto Networks, Ivanti, and SonicWall.
Nearly half of IT and business leaders said that the expanding attack surface is “spiraling out of control.” But throwing even more tooling and people at the issue doesn’t address the underlying problem which lies in a disconnect between the teams, processes and tools that a CISO probably already has in place.
Okta has about 15,000 clients and provides authentication services for remote logins, usually for employees and students. A known security breach took place in January, but LAPSUS$ says this is something else.










