Blog
-
Third Party Breach Exposes UK Armed Forces Pay Information; Chinese State-Backed Hackers Suspected
Another hole in a contractor’s defenses has led to a third party breach of a system containing sensitive government information, as the Ministry of Defense has confirmed that the financial information of some 272,000 UK armed forces personnel has been exposed.
-
Microsoft to Prioritize Company Focus on Cyber Threats With Security Initiative Revision
CEO Satya Nadella has specifically noted that Microsoft’s security initiative and focus on cyber threats must always come ahead of any other concern, including feature additions and improvement and support for legacy products.
-
Annual Verizon DBIR Highlights “Era of Vulnerability Exploitation,” Continued Importance of Timely Patching
Aside from continuing employee- and staffing-related struggles, the Verizon DBIR report also sees something of a “golden age” of vulnerability exploitation developing for cyber criminals.
-
North Korean Hackers Have Been Exploiting South Korean Defense Companies for Nearly Two Years
A report issued by South Korea’s National Police Agency indicates that the “big three” of North Korean hackers have all been involved in a project to hack national defense companies since at least late 2022.
-
TikTok Ban Moving Forward in the Name of National Security, But Legal Challenges Await
The government has a valid theoretical national security concern, one that has already led to TikTok bans on most federal devices and at numerous state and local levels, but the argument is not landing well with a US public that has almost half its population on the app.
-
Change Healthcare Breach Update: 6 TB Patient Data Stolen, $22 Million Ransom Payment Confirmed, $100 Billion Loss Projected
The Change Healthcare attack that leaked patient data and disrupted medical care across the US was indeed settled by a ransom payment. Now the former AlphV affiliate that perpetrated the attack has taken the data to a new extortion service and is demanding a second payment.
-
Nation-State Hacker Rampage With Ivanti Zero-Day Vulnerabilities Includes Breach of MITRE
As the Ivanti and MITRE incident demonstrates, serious zero-day vulnerabilities continue to linger even at security-minded organizations. MITRE was penetrated by a chain of two specific Ivanti vulnerabilities that were reported to the public in January, and nation-state hackers have been blamed.
-
Law Enforcement Operation Reveals Phishing Services Are Drawing in Young and Inexperienced Clients
A recent law enforcement operation that took down the LabHost phishing service has raised some questions about the “mainstreaming” of cyber crime, as the London police found that young university students with no prior record of hacking or online criminal activity were among the suspects that were rounded up.
-
String of Water Treatment Plant Invasions Linked to Russian Hackers
The water treatment plant incidents appeared to be more of a show of capability than a serious attempt to cause damage, with the Russian hackers taking videos of at least two of these incidents to boast about on Telegram.
-
2024 Credential Stuffing Attacks Have Pushed Roku to Require 2FA Logins
Two successful credential stuffing attacks since the beginning of 2024 have caused Roku to now require all users to log in with 2FA. At the moment, the company only supports email 2FA.










