Tens of millions in losses later, the MGM and Caesars systems are back online following dual cyberattacks by the same threat actor — here's what experts say about their incident responses.
| LATEST SECURITY NEWS & COMMENTARY | MGM, Caesars Cyberattack Responses Required Brutal Choices Tens of millions in losses later, the MGM and Caesars systems are back online following dual cyberattacks by the same threat actor — here's what experts say about their incident responses. How the Okta Cross-Tenant Impersonation Attacks Succeeded Sophisticated attacks on MGM and Caesars underscore the reality that even robust identity and access management may not be enough to protect you. Researchers Release Details of New RCE Exploit Chain for SharePoint One of the already-patched flaws enables elevation of privilege, while the other enables remote code execution. Amid MGM, Caesars Incidents, Attackers Focus on Luxury Hotels A fast-growing cyber campaign solely takes aim at luxury hotel and resort chains, using security-disruptive tactics to spread info-stealing malware. China APT Cracks Cisco Firmware in Attacks Against the US and Japan Sophisticated hackers are rewriting router firmware in real time and hiding their footprints, leaving defenders with hardly a fighting chance. MOVEit Flaw Leads to 900 University Data Breaches National Student Clearinghouse, a nonprofit serving thousands of universities with enrollment services, exposes more than 900 schools within its MOVEit environment. 'Gold Melody' Access Broker Plays on Unpatched Servers' Strings A financially motivated threat actor uses known vulnerabilities, ordinary TTPs, and off-the-shelf tools to exploit the unprepared, highlighting the fact that many organizations still don't focus on the security basics. Suspicious New Ransomware Group Claims Sony Hack A deceitful threat actor claims its biggest haul yet. But what, if any, Sony data does it actually have? Xenomorph Android Malware Targets Customers of 30 US Banks The Trojan had mainly been infecting banks in Europe since it first surfaced more than one year ago. Akira Ransomware Mutates to Target Linux Systems The newly emerged ransomware actively targets both Windows and Linux systems with a double-extortion approach. Cisco Moves Into SIEM With $28B Deal to Acquire Splunk Cisco's surprise agreement could reshape secure information and event management (SIEM) and extended detection and response (XDR) markets. Proactive Security: What It Means for Enterprise Security Strategy Proactive Security holds the elusive promise of helping enterprises finally get ahead of threats, but CISOs must come to grips with the technological and philosophical change that it brings. 4 Pillars for Building a Responsible Cybersecurity Disclosure Program Responsible disclosure must strike a balance between the immediate need to protect users and the broader security implications for the entire community. MORE NEWS / MORE COMMENTARY | |
|
Dark Reading Weekly -- Published By Dark Reading Informa Tech Holdings LLC | Registered in the United States with number 7418737 | 605 Third Ave., 22nd Floor, New York, New York 10158, USA
| To opt-out of any future Dark Reading Weekly Newsletter emails, please respond here. | Thoughts about this newsletter? Give us feedback. |
Keep This Newsletter Out Of Your SPAM Folder Don't let future editions go missing. Take a moment to add the newsletter's address to your anti-spam white list: | If you're not sure how to do that, ask your administrator or ISP. Or check your anti-spam utility's documentation. | We take your privacy very seriously. Please review our Privacy Statement. |
|
|