US law enforcement agencies make up the majority of the information requests and nearly all of the ‘three letter’ players are getting in on the action, from the FBI to the IRS.
Almost 18 months since the 2017 massive outbreak, the WannaCry ransomware remains a cyber threat based on recent research from Kaspersky Labs showing 75,000 infections over the last three months.
Whether it is company culture or an individual attitude, developers do appear to be commonly shipping vulnerable code with the full knowledge that there are weaknesses in it.
The first Bitcoin privacy update in four years is bringing changes that are broadly popular among the user base. The "Taproot" update, scheduled for November, changes the digital signature algorithm underpinning the system.
A hacker on a Russian-speaking forum is selling hundreds of business executives' email and password combinations for Office 365 and Microsoft accounts for use in BEC scams.
Over 87 gigabytes of personal information is now being sold on the dark web as part of this password leak of 773 million email addresses and 21 million passwords, raising very important questions about personal data security online.
The 18th installment of the DBIR surveyed 22,052 total cyber attacks logged by Verizon's internal threat research team, over half of which (12,195) involved confirmed data breaches. Credential abuse continues in the lead at 22%. Exploitation of vulnerabilities is now up to 20%, followed by phishing at 16%.
Bad bots account for 30% of internet traffic and are increasingly used in account takeover and API attacks, while human traffic fell to an 8-year low of just over half of all internet traffic.
With a total of €2.92 billion levied throughout the bloc in 2022, GDPR fines are up in spite of a small drop in the overall data breach count as the bloc eyes stronger regulation for AI.
In what is shaping up to be a major test case for the entire cyber insurance industry, Zurich Insurance is refusing to pay out a $100 million claim from Mondelez, saying that the ransomware attack was actually an act of “cyber war,” and therefore, is not covered by the policy.










