Managing Threats When Most of the Security Team Is Out of the Office
During holidays and slow weeks, teams thin out and attackers move in. Here are strategies to bridge gaps, stay vigilant, and keep systems secure during those lulls.
Growing hesitancy and challenges in conducting immediate intrusion assessments necessary to avoid penalties from the SEC have led to materiality being detailed in only a tenth of incident disclosures this year.
Crypto heist proceeds exceed $2B amid more attacks
While crypto platforms had already lost $1.5 billion during the first seven months of 2024, cryptocurrency heists have significantly dropped in frequency and size after separate intrusions against DMM Bitcoin and WazirX.
Over 3M Builder.ai records leaked by unprotected database
The misconfigured database also included software development plans, timelines, client interactions, financial records, and communications among Builder.ai's employees.
Details regarding the amount of data stolen from Krispy Kreme have not been provided but Play asserted the theft of the pastry giant's financial information.
Cyberattack hits BeyondTrust Remote Support SaaS implementations
Investigation into the incident, which was initially detected on Dec. 2, revealed that threat actors leveraged a Remote Support SaaS API key to conduct local app account password resets.
OT/ICS Engineering Workstations Face Barrage of Fresh Malware
Cyberattacks against OT/ICS engineering workstations are widely underestimated, according to researchers who discovered malware designed to shut down Siemens workstation engineering processes.
Fortinet has patched CVE-2023-34990 in its Wireless LAN Manager (FortiWLM), which combined with CVE-2023-48782 could allow for unauthenticated remote code execution (RCE) and the ability to read all log files.