Category: Cybersecurity
-

RSA: Cisco launches XDR, with focus on platform-based cybersecurity
Cisco took the stage at RSA 2023 to tout extended detection and response as key to a unified cross-domain security platform, plus new Duo MFA features. Image: Tobias Arhelger/Adobe Stock Day one of RSA 2023 set what is likely to be the week’s thematic tone at the event: Platforms with cross-domain telemetry in the service…
-

Credential harvesting malware appears on deep web
Image: Adobe Stock/WunderBild Cloud-focused credential harvester and spam utilities, used to illicitly extract an organization’s database of usernames, passwords and emails, are on the rise. By some estimates, over 24 billion credentials had been stolen by late 2022. One extraction tool, spotted in the wild by cloud forensics and incident response company Cado Security, is…
-

Even after armed with defense tools, CISOs say successful cyberattacks are ‘inevitable’: New study
Image: CROCOTHERY/Adobe Stock In Cisco’s new Cybersecurity Readiness Index, only 15% of respondents to the global survey said their organizations have implemented security programs mature enough to defend against current cybersecurity risks. While most enterprises have some collection of cybersecurity measures deployed, a full 82% of the 6,700 chief information security officers and other cybersecurity…
-

BECs double in 2022, overtaking ransomware
A look at 4th quarter 2022, data suggests that new threat surfaces notwithstanding, low-code cybersecurity business email compromises including phishing, as well as MFA bombing are still the prevalent exploits favored by threat actors. Image: Adobe Stock Cybersecurity defenders peering into the fog hoping to catch a glimpse of the next threat might be staring…
-

First Dero cryptojacking campaign targets unprotected Kubernetes instances
Learn how this cryptocurrency campaign operates and its scope. Then, get tips on protecting vulnerable Kubernetes instances from this cybersecurity threat. Image: Pixabay The cybersecurity company CrowdStrike has observed the first-ever Dero cryptojacking campaign. The attack targets Kubernetes clusters that were accessible on the internet and allowed anonymous access to the Kubernetes API. Jump to:…
-

The Biden administration may eye CSPs to improve security, but the real caveat emptor? Secure thyself
Image: Maksym Yemelyanov/Adobe Stock President Joe Biden’s administration, as part of its recently released National Cybersecurity Strategy, said critical sectors such as telecommunications, energy and healthcare rely on the cybersecurity and resilience of cloud service providers. Yet, recent reports suggest the administration has concerns that major cloud service providers constitute a massive threat surface —…
-

Cloud security, hampered by proliferation of tools, has a “forest for trees” problem
Image: Ar_TH/Adobe Stock A new study Networks found that, on average, organizations rely on over 30 tools for overall security, and that degree of complexity is making for less security, not more. Over 60% of organizations have been operating in a cloud environment for three or more years, but technical complexities and maintaining comprehensive security…
-

CrowdStrike: Attackers focusing on cloud exploits, data theft
Image: Ar_TH/Adobe Stock CrowdStrike, a cybersecurity firm that tracks the activities of global threat actors, reported the largest increase in adversaries it has ever observed in one year — identifying 33 new threat actors and a 95% increase in attacks on cloud architectures. Cases involving “cloud-conscious” actors nearly tripled from 2021. “This growth indicates a…
-

LastPass releases new security incident disclosure and recommendations
Image: Tada Images/Adobe Stock LastPass was hacked twice last year by the same actor; one incident was reported in late August 2022 and the other on November 30, 2022. The global password manager company released a report on Wednesday with new findings from its security incident investigation, along with recommended actions for users and businesses…
-

Rise of cloud-delivered malware poses key security challenges
The volume of cloud-based malware tripled in 2022 over the prior year, says Netskope, with 30% of the malicious downloads coming from Microsoft OneDrive. Image: AndSus/Adobe Stock As more organizations have turned to the cloud to store and work with their data, applications and other assets, cybercriminals are increasingly exploiting cloud-based services to set up…