The Breach News

2023 API Security Trends: Are Organizations Strengthening Their Security Posture?

Application Programming Interfaces (APIs) are essential to contemporary software applications, enabling seamless interaction and data exchange between diverse systems. They grant developers the ability to integrate external services, enhancing the functionality of their applications. However, the escalating dependence on APIs has made them enticing targets for cybercriminals, leading to a…

Read More2023 API Security Trends: Are Organizations Strengthening Their Security Posture?

Understanding CCRM: Three Essential Elements of Continuous Compliance and Risk Management Webinar.

Profile of Robin Das Executive Director, Market Growth Strategy, DataBee®, A Comcast Company Robin Das serves as the Executive Director of Market Growth Strategy for DataBee, a newly established cybersecurity division within Comcast. This unit focuses on the development and deployment of innovative security solutions, including a security, risk, and…

Read MoreUnderstanding CCRM: Three Essential Elements of Continuous Compliance and Risk Management Webinar.

Inside the Modern Cyber Heist: The Growing National Risk of Personal Data Breaches

Cybercriminals Exploit Digital Trust in India: A Spotlight on Recent High-Profile Scams In early September, a 78-year-old retired banker from South Delhi lost a staggering ₹23 crore—his entire life savings—to a group of cybercriminals masquerading as law enforcement officials. The fraudulent scheme involved the manipulation of trust through a fabricated…

Read MoreInside the Modern Cyber Heist: The Growing National Risk of Personal Data Breaches

The Next Era of Network Security: Automated Internal and External Penetration Testing

In the current landscape of heightened cyber threats, it is imperative for organizations to robustly protect against cyberattacks. Traditional penetration testing has its merits but often presents challenges such as high costs and limited frequency. Automated internal and external network pentesting emerges as a transformative solution, equipping entities to proactively…

Read MoreThe Next Era of Network Security: Automated Internal and External Penetration Testing

New PseudoManuscrypt Malware Compromised More Than 35,000 Computers in 2021

A new malware botnet known as PseudoManuscrypt has emerged, targeting industrial and government organizations, particularly within military-industrial entities and research laboratories. Reports indicate that this malware strain has compromised approximately 35,000 Windows systems throughout the current year. The nomenclature for PseudoManuscrypt draws parallels to the well-known Manuscrypt malware, associated with…

Read MoreNew PseudoManuscrypt Malware Compromised More Than 35,000 Computers in 2021

Live Webinar: Streamline Your DevOps with Efficient Application Security Testing

Thank you for registering with ISMG Enhance your profile and stay informed. Select Title LevelAnalytics/Architecture/EngineeringAttorney/General Counsel/CounselAssociate Vice President (AVP)Board MemberC-Level ExecutiveC-Level – OtherChief Communications Officer (CCO)Chief Executive Officer (CEO)/PresidentChief Financial Officer (CFO)ChairpersonChief Information Officer (CIO)Chief Information Security Officer (CISO)/Chief Security Officer (CSO)CISO/CSO/CIOChief Operating Officer (COO)Chief Risk Officer (CRO)Chief Technology Officer…

Read More

Live Webinar: Streamline Your DevOps with Efficient Application Security Testing

Envoy Air Partners with Qantas, Aeroflot, and Vietnam Airlines in Major Cybersecurity Breach: A Significant Threat to the Aviation Sector This Year

Massive Cybersecurity Breach Hits Envoy Air, A Wake-Up Call for Aviation Industry In a significant cybersecurity incident, Envoy Air, a regional airline operating under the American Eagle brand, has been targeted as part of a broader breach affecting several major players in the aviation sector, including Qantas, Aeroflot, and Vietnam…

Read MoreEnvoy Air Partners with Qantas, Aeroflot, and Vietnam Airlines in Major Cybersecurity Breach: A Significant Threat to the Aviation Sector This Year

Ivanti Releases Urgent Security Updates for CSA and Connect Secure Vulnerabilities

Security Updates Released for Ivanti Products Addressing Critical Vulnerabilities Ivanti has issued security updates aimed at rectifying several severe vulnerabilities in its Cloud Services Application (CSA) and Connect Secure offerings, vulnerabilities that could potentially facilitate privilege escalation and remote code execution. The concern arises from multiple critical flaws present in…

Read MoreIvanti Releases Urgent Security Updates for CSA and Connect Secure Vulnerabilities

Apache Releases Third Patch to Address Newly Identified High-Severity Log4j Vulnerability

On Friday, the Apache Software Foundation (ASF) released version 2.17.0 of its widely adopted logging library, Log4j, addressing a new vulnerability that malicious actors can exploit for denial-of-service (DoS) attacks. This vulnerability is identified as CVE-2021-45105, rated with a CVSS score of 7.5, and affects all iterations of the tool…

Read MoreApache Releases Third Patch to Address Newly Identified High-Severity Log4j Vulnerability