As cyber threats loom around every corner and privileged accounts become prime targets, the significance of implementing a robust Privileged Access Management (PAM) solution can’t be overstated.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Attackers are combining DDoS attacks and "click fraud" in new email extortion scams that target publishers with websites monetized through Google AdSense program.
Many IT professionals are also starting to recognise the ability of Shadow IT to maximise operations; IT departments now set aside 40% of its enterprise budget for Shadow IT and this is only going to increase.
Generative AI models in the style of ChatGPT are being sold that promise to help create malware, write phishing emails, set up attack sites, scan for vulnerabilities, and more. The latest DarkBART and DarkBERT projects have been trained on dark web sites.
Researchers warn about the return of Emotet malware through TrickBot's infrastructure and a new phishing campaign through infected email attachments after a year of inactivity.
An international law enforcement campaign that began in 2020 culminated in the infiltration and control of the botnet's infrastructure, with a beneficial payload delivered to infected devices that scrubs the Emotet malware.
A hacker is selling multiple employee databases belonging to several Fortune 500 companies, including Tata Consultancy Services, General Electric, and McDonald's.
GoTo says that the stolen information varies by product, but encryption keys that were also taken in the hack will grant access to "a portion" of the encrypted backups that were stolen.
Popular password manager LastPass has confirmed that a previously reported November security incident was a data breach that resulted in the theft of customer data, including encrypted password vaults.
Phishing, BEC and social engineering scams work particularly well on employees who are working from home and has become a “perfect storm” for attackers who want to target businesses through their remote workers.










