Blog
-
Fears of Online Activity Tracking as Hidden Russian Software Found in Thousands of Apps From US Government Agencies and Major Companies
A Russian software company that appears to have gone out of its way to hide its origins has raised alarms of online activity tracking in the US Army and several other government agencies, as its code is present in thousands of apps.
-
Over $100 Million in Ransom Payments Recorded by Hive Ransomware, FBI and CISA Urge Organizations To Take Protective Measures
Hive ransomware has racked up over $100 million in ransom payments and over 1,300 organizations have been impacted as the group becomes one of the biggest criminal service providers of the moment. The group likes to prey on poorly secured VPNs and unpatched Microsoft Exchange vulnerabilities.
-
80% Of Companies Have Filed at Least One Cyber Insurance Claim; Need for Security Controls Expands as Market Tightens
Report shows a full four out of five companies have filed at least one cyber insurance claim; half have filed more than one. Insurers’ next move appears to be more stringent and thorough security controls as a standard term of obtaining a policy.
-
UK Government Begins Vulnerability Scanning of All of the Country’s Internet Devices
While the vulnerability scanning program appears to primarily be a public service, the UK government is looking to fortify national security and improve its own cyber readiness using data that it gathers from regularly scanning internet devices.
-
Years-Long Spear Phishing Campaign Plagues Smaller Countries as French-Speaking APT Group Pilfers $11 Million
APT group “OPERA1ER” is active in Africa, Asia and Latin America and conducted sophisticated spear phishing since 2018 and usually notches anywhere from either a few to a dozen successful attacks each year.
-
Medibank Accepts the Consequences of Health Data Being Leaked as It Refuses Ransom Payments
Attackers started leaking health data of selected public figures and politicians as well as people who may have had compromising conditions or treatments as Medibank has publicly committed to not making ransom payments.
-
ICS Cybersecurity Improving, but Legacy Systems & Staffing Continue To Be Major Impediments
Hackers are continuing to show a very strong interest in industrial control systems, but organizations also tend to be much more prepared. However, 35% are still not able to tell if they have been compromised and 17% still aren’t monitoring ICS cybersecurity.
-
4 Data Breaches in 4 Years Prompts FTC Action Against Edtech Giant Chegg
The four data breaches that prompted FTC involvement collectively involved the loss of tens of millions of both customer and employee records, and were very preventable had the edtech giant been following basic cybersecurity best practices.
-
Code Stolen From Company GitHub Repositories as Dropbox Suffers Security Breach Tied To Phishing
Security breach was traced back to an employee that followed a phishing link to a bogus login page and entered their credentials on October 13. The attackers then took the credentials and used them to raid some 130 GitHub repositories belonging to Dropbox.
-
New Study Finds Cybersecurity Workforce Gap Continuing To Grow Despite Historic Influx of New Security Professionals
The good news is that the cybersecurity workforce has grown to about 4.7 million strong worldwide. But a workforce gap of 3.4 million remains in spite of good recent growth.










