Threats: Page 22


  • Cloud computing technology internet on binary code with abstract background. Cloud Service, Cloud Storage Concept. 3D render.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Most organizations had a cloud-related security incident in the past year

    Security leaders consider the risk of cloud-based incidents higher than on-premises incidents, yet they expect to move more applications to the cloud. 

    By Sept. 28, 2022
  • A lit Microsoft log seen above a group of people in shadow.
    Image attribution tooltip
    Jeenah Moon via Getty Images
    Image attribution tooltip

    Malicious OAuth applications used to control Exchange tenants in sweepstakes scam

    Microsoft researchers said a threat actor launched credential-stuffing attacks against high-risk accounts that failed to deploy multifactor authentication.

    By Sept. 23, 2022
  • Trendline

    Managing identity sprawl

    Cyber threat actors know the simplest way to hack into an enterprise and remain under the radar is with stolen, legitimate user credentials -- and cloud services and AI are making managing and securing digital identities more challenging than ever.

    By Cybersecurity Dive staff
  • Cyberattack and internet crime, hacking and malware concepts.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Stolen single sign-on credentials for major firms available for sale on dark web

    Stolen SSO credentials are available for half of the top 20 public companies, and 25% of the entire S&P 500, BitSight found.

    By Sept. 21, 2022
  • A stack of $20 U.S. bills lay on top of a scattering of more $20 bills.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    State education leaders prioritize cybersecurity, but lack funding

    In a survey by the State Educational Technology Directors Association, 57% of respondents said their state provides a low amount of funding for cybersecurity.

    By Anna Merod • Sept. 15, 2022
  • Windmills behind a field of solar panels.
    Image attribution tooltip
    Kevork Djansezian via Getty Images
    Image attribution tooltip

    Energy providers hit by North Korea-linked Lazarus exploiting Log4j VMware vulnerabilities

    Cisco Talos researchers observed the advanced persistent threat actor infiltrating networks during a six-month campaign.

    By Sept. 13, 2022
  • Statue of Alexander Hamilton.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    US Treasury sanctions Iran intelligence agency following Albanian government attack

    The Treasury Department said Iran has engaged in malicious cyber activity against government and private sector organizations, including critical infrastructure targets, since at least 2007.

    By Sept. 12, 2022
  • Cyberattack and internet crime, hacking and malware concepts.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Researchers warn older D-Link routers are under threat from Mirai malware variant

    Attackers are leveraging vulnerabilities in the devices to build botnets and launch DDoS attacks, according to Palo Alto Networks research.

    By Sept. 8, 2022
  • Lloyd's employee at company headquarters
    Image attribution tooltip
    Matt Cardy via Getty Images
    Image attribution tooltip

    Changing cyber insurance guidance from Lloyd’s reflects a market in turmoil

    Rising ransomware attacks and higher payout demands have battered the insurance industry, leaving many organizations exposed and vulnerable. 

    By Aug. 29, 2022
  • Woman Walking On Staircase Of Building
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Sponsored by Delinea

    How does Privileged Access Management work?

    The model is a framework to help you set the right PAM foundation and get your organization on the PAM journey, now and in the future.

    Aug. 29, 2022
  • Blue padlock made to resemble a circuit board and placed on binary computer code.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Tips for how to safeguard against third-party attacks

    Organizations need to demand and ensure all vendors implement rigorous security measures. Sometimes the least likely tools pose the most risk. 

    By Aug. 25, 2022
  • Digital technology vector background depicting a cyberattack.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ransomware attack surges tied to crypto spikes

    Not every ransomware attempt leads to a successful attack. But with more attempts comes more potential damage.

    By Aug. 24, 2022
  • Image attribution tooltip
    Leon Neal via Getty Images
    Image attribution tooltip

    Credential stuffing hammers US businesses as account data for sale in bulk

    Media companies, retailers, restaurant groups and food delivery services are at heightened risk, the FBI said.

    By Aug. 23, 2022
  • Ransomware virus has encrypted data. Attacker is offering key to unlock encrypted data for money.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    LockBit ransomware group claims responsibility for Entrust attack

    The prolific ransomware gang threatened to publish data stolen during the attack.

    By Aug. 19, 2022
  • A Mailchimp logo on a phone with a larger Mailchimp in the background.
    Image attribution tooltip

    Rafael Henrique/Zumapress/Newscom

    Image attribution tooltip

    Mailchimp breach shines new light on digital identity, supply chain risk

    Sophisticated threat actors are targeting weak links in the email marketing space to go after vulnerable financial targets.

    By Aug. 18, 2022
  • Illustration of locks layered above circuity.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    The same old problems nag cybersecurity professionals

    Technical complexities abound as the perceived level of risk rises in an unrelenting fashion.

    By Aug. 17, 2022
  • Cyberattack and internet crime, hacking and malware concepts.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    How attackers are breaking into organizations

    Threat actors lean heavily on phishing attacks, vulnerabilities in software and containers, and stolen credentials, according to top cyber vendor research.

    By Aug. 15, 2022
  • close up programmer man hand typing on keyboard laptop for register data system or access password at dark operation room , cyber security concept - stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Critical flaws on widely used Cisco firewalls left unpatched for months

    Most of the vulnerabilities allow attackers to execute arbitrary code, Rapid7 researchers said.

    By Aug. 12, 2022
  • Chris Krebs, former director of the Cybersecurity and Infrastructure Security Agency, testifies on Capitol Hill, October 19, 2017 in Washington, DC.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Don’t count on government, tech vendors to fix security woes, former CISA chief Krebs says

    The state of cybersecurity is bad and it’s going to get worse, Chris Krebs said at Black Hat. But somehow things might eventually get better.

    By Aug. 10, 2022
  • Team of data center system administrators and IT specialists use laptop and tablet computers.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    AWS, Splunk lead open source effort to spot and curb cyberattacks

    A broad group of 18 tech companies are collaborating to establish a less cumbersome model for cybersecurity defense coordination.

    By Aug. 10, 2022
  • A sample phishing text message that targeted Cloudflare employees.
    Image attribution tooltip

    Cloudflare

    Image attribution tooltip

    Cloudflare thwarts ‘sophisticated’ phishing attack strategy that bruised Twilio

    Dissimilar responses from Cloudflare and Twilio bear important lessons in transparency, resiliency and access.

    By Aug. 9, 2022
  • Digital technology vector background depicting a cyberattack.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    The 11 most-prevalent malware strains of 2021 fuel cybercrime

    Cybercriminals remain the most prolific users of malware, wielding these top strains to deliver ransomware and steal data.

    By Aug. 5, 2022
  • Image depicts the implementation of cybersecurity with a lock displayed over a screen.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ransomware defense guidance risks hang-ups under many steps

    Small and mid-sized businesses don’t typically have the resources to meet every safeguard. But every action, however small, helps.

    By Aug. 4, 2022
  • close up programmer man hand typing on keyboard laptop for register data system or access password at dark operation room , cyber security concept - stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Threat actors hide malware in legitimate — and high profile — applications

    Researchers from VirusTotal show how attackers use social engineering techniques to launch malicious attacks behind trusted applications.

    By Aug. 3, 2022
  • Rendered image depicting global networks.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Initial access brokers selling online access to unsuspecting MSPs

    The ads for initial access to MSPs follow warnings from the FBI, CISA and intelligence partners from the Five Eyes.

    By Aug. 2, 2022
  • Ransomware virus has encrypted data. Attacker is offering key to unlock encrypted data for money.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Most cyberattacks come from ransomware, email compromise

    Attackers are scanning for vulnerabilities in unpatched systems within 15 minutes, stressing the pace and scale of the threat.

    By Aug. 1, 2022