September 8, 2020
Post-mortem analysis of data breaches shows that most of today’s cyber-attacks are front ended by phishing campaigns. The most recent CryptoForHealth Twitter Hacker is just one of many examples. While paying close attention to established hackers tactics, techniques, and procedures (TTPs) increases an organization’s ability to implement effective cyber defense strategies, businesses need to stay abreast of emerging TTPs. A good example is vishing, which is a new take on an old scam. Read more >>>
August 31, 2020
Email service provider Sendgrid is grappling with an unusually large number of customer accounts whose passwords have been cracked, sold to spammers, and abused for sending phishing and email malware attacks. Sendgrid’s parent company Twilio says it is working on a plan to require multi-factor authentication for all of its customers, but that solution may not come fast enough for organizations having trouble dealing with the fallout in the meantime. Read more >>>
August 26, 2020
North American land developer and homebuilder Brookfield Residential is the first victim of the new DarkSide Ransomware. DarkSide will breach a network and spread laterally between devices while stealing unencrypted data. Upon gaining access to a Windows domain controller, the threat actors deploy ransomware throughout the network. As part of their extortion strategy, DarkSide will create an entry for each victim whose data has been stolen on their data leak site. Read more >>>
There was a time when the main tech-based worry for any business were viruses. Large companies spent thousands of dollars on antivirus software, while those that didn’t paid the price when one of their client machines became infected. A new threat has emerged over the last decade or so, that is equally as devastating if deployed correctly, but this threat doesn’t target weaknesses in coding, but rather weaknesses in us, the human being. That threat is phishing. Read more >>>