Global Cyber News Digest

Daily News Digest

Stay current on the global cyber threat landscape and industry developments with CCOE’s daily digest and library of cybersecurity news and articles.

  • Survey Finds Widespread Concern Over Cloud Security Risks During the COVID-19 Crisis
    • As a vast majority of companies make the rapid shift to work-from-home to stem the spread of COVID-19, a significant percentage of IT and cloud professionals are concerned about maintaining the security of their cloud environments during the transition.
    • While cloud providers can educate and alert their customers about potentially risky misconfigurations and good security practices, they can't prevent their customers from making misconfiguration mistakes.

      Security Boulevard - Deb Schalm | April 13, 2020
    securityboulevard.comApril 13, 2020
  • Power to the People
    • A recent survey by the SANS Institute suggests that organizations with operational control systems such as ICS, SCADA, process control, distributed control or facility automation still view people as both the biggest potential weakness and, in certain areas, the greatest asset when it comes to stopping cyber-attacks.
    • A data point uncovered by the SANS survey was that although 75% of respondents have inventoried their workstations and servers, which are considered the higher risk; this number drops to less than half when directly related to OT such as control system devices and software applications.

      infosecurity Magazine - Ilan Barda | April 10, 2020
    infosecurity-magazine.comApril 10, 2020
  • 4 Statistical Reasons Data Security Should Be a Top Priority for Small Businesses
    • Many of the largest corporations in the world spend a significant portion of their resources addressing this issue. But it's not only an issue for only major companies
    • The best way for a small business to protect itself from cyber threats is to be proactive about security. The time and resources spent on strengthening your security methods will pay off in the long run, as you will avoid the crippling costs of a data breach.

      Stamford Advocate - Tom Popomaronis | April 9, 2020
    stamfordadvocate.comApril 9, 2020
  • Working From Home Exposes New Billing Data Security Threats
    • Many employees are not equipped for using at-home computers and other BYOD (bring your own device) equipment that handle sensitive data such as credit card numbers.
    • Billing information always contains PPI and is especially vulnerable to data privacy regulations. Assets used at home must abide by internal policies and external regulations that govern billing information.

      HIT Infrastructure - Samantha McGrail | April 9, 2020
    hitinfrastructure.comApril 9, 2020
  • DoJ Calls for Mandatory Data Breach Reporting to Law Enforcement
    • The purpose of disclosing a data breach to a customer is, in theory, to permit the customer (data subject) to take corrective action to mitigate any harm resulting from the breach.
    • Is mandatory breach disclosure to law enforcement a good idea? It depends on what they are going to do with it.

      Security Boulevard - Mark Rasch | April 9, 2020
    securityboulevard.comApril 9, 2020
  • Social Engineering Attacks: A Look at Social Engineering Examples in Action
    • Social engineering is a commonly used tactic that was used in 33% of data breaches in 2018, according to Verizon's 2019 Data Breach Investigation Report.
    • Social engineering is, hands down, one of the most dangerous threats to businesses and individuals alike.

      Hashed Out - Casey Crane | April 8, 2020
    thesslstore.comApril 8, 2020
  • INTERPOL Confirms Ongoing Cyber Attacks Against Hospitals Fighting COVID-19 Battle
    • As if hospitals didn't already have enough to cope with as they battle to save the lives of COVID-19 patients while also fighting to keep frontline staff safe, it has been confirmed that another enemy is intent on exploiting stretched healthcare resources.
    • INTERPOL has now issued a "purple notice" alert to law enforcement in all 194 member countries to support the global fight against this cybercriminal endeavor.

      Forbes - Davey Winder | April 8, 2020
    forbes.comApril 8, 2020
  • Hackers' new target during pandemic: video conference calls
    • Ceri Weber had just begun to defend her dissertation when the chaos began: Echoes and voices interrupted her. Someone parroted her words. Then Britney Spears music came on, and someone told Weber to shut up. Someone threatened to rape her.
    • Hackers had targeted the meeting on the video conference platform Zoom while Weber was completing the final step of her doctoral degree at Duke University.
    • The harassment lasted 10 minutes - the result of an increasingly common form of cyber attack known as "Zoom bombing."

      6News - REGINA GARCIA CANO and AARON MORRISON | April 7, 2020
    kaaltv.comApril 7, 2020
  • Marriott gets breached again - what can businesses learn?
    • Last week, hotel chain Marriott International announced that it has suffered another data breach involving personal information of 5.2 million guests worldwide.
    • The breach will have done nothing to improve the hotel chain's already damaged reputation.

      TechWire Asia - Emily Wong | April 7, 2020
    techwireasia.comApril 7, 2020
  • New Ransomware Innovations Bring Shame
    • As if ransomware wasn't a big enough problem already, it just evolved from a costly nuisance into a full-fledged data breach designed to shame companies into paying.
    • This new twist on ransomware is being driven by several well-established cybercriminal groups that have upped the stakes by threatening to publish customer data and trade secrets of victims who refuse to pay the ransom.

      Security Boulevard - Marcus Chung | April 7, 2020
    securityboulevard.comApril 7, 2020