NSO Group was found to not only have exceeded its legal level of access to the WhatsApp servers and broken the terms of service with its Pegasus spyware, but to also have violated the US Computer Fraud and Abuse Act as well as California state law.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
U.S. federal authorities have warned about Ghost ransomware attacks targeting various industries, including critical infrastructure, in over 70 countries. “Beginning...
Microsoft has released security patches for the zero-day vulnerability chain dubbed ToolShell, capable of remote code execution on SharePoint, resulting in the exploitation of at least 54 organizations worldwide.
Citrix is the latest big name to fall victim to a major data breach. The data breach is thought to have been perpetrated by Iranian hackers in a group called IRIDIUM, which is believed to have ties to the country's government.
Colorado Department of Higher Education (CDHE) has suffered a massive data breach leaking sensitive personal information of current and former students and educators spanning over a decade.
Winnti malware makes a “comeback”, victimizing major international firms including Bayer, BASF, Siemens and others. The attackers are particularly interested in industrial secret and tracking movements of specific people.
Report from Momentum Cyber finds that the first half of 2021 was the busiest on record for the cybersecurity market in terms of investment and strategic activity. The torrid pace has been indirectly driven by the massive spike in ransomware attacks.
EEA’s PSD2 regulation aims to protect consumers against fraud by securing the digital payments for Card Not Present (CNP) transactions. Study shows that merchants have seen some higher loss from failed and abandoned transactions than that from fraudsters.
The Chinese hackers are able to run a massive but stealthy campaign of password-spraying attacks while evading logs, targeting Microsoft 365 accounts that require only basic authentication and do not have MFA enabled.
Russian hackers have claimed responsibility for recent DDoS attacks against NATO that disrupted a number of its operations including earthquake relief efforts for the Turkish-Syrian earthquake.










