Security leaders weigh in on Life360 data breach

Security leaders weigh in on Life360 data breach

Life360 was impacted by a data breach, which they announced in early June. The malicious actors behind the data breach have appeared to target systems associated with Tile, a Life360 subsidiary. Possibly compromised information may include client names, phone numbers, addresses, email addresses and identification numbers for tile devices.  Security leaders weigh in  Piyush Pandey, CEO at Pathlock: “In this instance, it appears that access was given using the admin credentials of a former Tile…

Read More

Recovery point objectives 101: Planning for cyberattacks

Recovery point objectives 101: Planning for cyberattacks

Congressional hearings regarding the UnitedHealth cyberattack that occurred earlier this year revealed that the massive security incident could cost the company a total of $1.6 billion. During testimony, UnitedHealth CEO revealed that hackers infiltrated its systems through a remote portal that wasn’t protected by multifactor authentication and other safeguards the company had in place that were designed to prevent and detect also failed. Unfortunately, there are many companies that find themselves victims of cybercrimes like…

Read More

Beyond the breach: The ongoing fragility of healthcare cybersecurity

Beyond the breach: The ongoing fragility of healthcare cybersecurity

A wave of ransomware attacks in the United States and United Kingdom that have disrupted clinical operations and forced hospitals in both regions to turn away patients is the latest reminder of the fragility of life-saving infrastructure and how lucrative it can be for attackers looking for a payday or an opportunity to sow discord into the lives of patients.  In May, St. Louis-based Ascension Healthcare, one of the largest private healthcare systems in the…

Read More

Overcoming the IT skills gap and maintaining a secure business

Overcoming the IT skills gap and maintaining a secure business

Technology continues evolving and advancing at a rapid speed, ringing in unparalleled opportunities, but also creating new vulnerabilities. With this comes the demand for a workforce equipped with up-to-date skills to counter emerging threats. However, the pace of skill acquisition often lags the evolving threat landscape – opening organizations to increased risks.  According to a Statista report looking at global talent shortages, 54% of organizations experienced a skills shortage in tech in 2023. Yet this skills gap…

Read More

CISOs in Australia Urged to Take a Closer Look at Data Breach Risks

CISOs in Australia Urged to Take a Closer Look at Data Breach Risks

Clayton Utz cyber partner Brenton Steenkamp has seen his fair share of cyber attacks. Returning to Australia in October after a seven-year stint in Amsterdam, he has brought home tales of dealing with multiple large ransomware attacks in Europe, as well as the data governance lessons they provided. Steenkamp said he has observed many Australian organisations are yet to assume the “paradigm shifting” view of risk around data estates that is necessary for future data…

Read More

How the Change Healthcare breach can prompt real cybersecurity change

How the Change Healthcare breach can prompt real cybersecurity change

People’s lives, privacy and safety can hang in the balance when malicious criminals disrupt healthcare operations. Recently, a ransomware attack forced Change Healthcare, which maintains medical records for approximately one-third of patients in the United States, to shut down their systems and impacted pharmacies nationwide, delaying critical prescriptions. This incident is just the latest in a string of healthcare breaches affecting an alarming number of patients and giving attackers access to the most sensitive personal…

Read More

How Can Businesses Defend Themselves Against Cyberthreats?

How Can Businesses Defend Themselves Against Cyberthreats?

Today, all businesses are at risk of cyberattack, and that risk is constantly growing. Digital transformations are resulting in more sensitive and valuable data being moved onto online systems capable of exploitation, thus increasing the profitability of a successful breach. Furthermore, launching a cyberattack is becoming more accessible. Exploit kits and malware-as-a-service offerings are getting cheaper, while open-source AI tools are making masquerading as a trusted executive and exploiting vulnerabilities easier. TechRepublic consolidated expert advice…

Read More

CISOs aren’t scapegoats: Fostering a security-first culture

CISOs aren’t scapegoats: Fostering a security-first culture

Ten years ago, it was the norm for security breaches to be the sole responsibility of the chief information security officer (CISO). For this reason, the CISO role traditionally had a higher turnover rate, with many experiencing extreme burnout. But now, as data breaches make regular headlines and every organization becomes a lucrative target for cybercriminals, IT security has become a business priority, causing the full C-suite to take note.  Cybersecurity is now a business…

Read More

Devices Infected With Data-Stealing Malware Increased by 7 Times Since 2020

Devices Infected With Data-Stealing Malware Increased by 7 Times Since 2020

The number of devices infected with data-stealing malware in 2023 was 9.8 million, a sevenfold increase over the same figure for 2020, according to new research from Kaspersky Digital Footprint Intelligence. However, the researchers believe that the true figure could be as high as 16 million, as credentials from devices infected in 2023 may not be leaked onto the dark web until later this year (Figure A). Figure A: Number of infections of data-stealing malware…

Read More

Warning: Thread Hijacking Attack Targets IT Networks, Stealing NTLM Hashes

Warning: Thread Hijacking Attack Targets IT Networks, Stealing NTLM Hashes

Mar 05, 2024NewsroomEmail Security / Network Security The threat actor known as TA577 has been observed using ZIP archive attachments in phishing emails with an aim to steal NT LAN Manager (NTLM) hashes. The new attack chain “can be used for sensitive information gathering purposes and to enable follow-on activity,” enterprise security firm Proofpoint said in a Monday report. At least two campaigns taking advantage of this approach were observed on February 26 and 27,…

Read More
1 2 3 4 5 25