A Chinese-aligned information operation known as Dragonbridge targeted American, Australian, and Canadian rare earth mineral companies in an apparent bid to shore up Chinese market dominance, researchers at Mandiant announced Tuesday.
Despite massive revenues across the sector, pharma companies face similar challenges and pushback from the board on cybersecurity resources — in spite of the high value of intellectual property.
Cryptocurrency wallet providers MetaMask and Phantom have issued advisories warning users regarding the novel Demonic flaw, which could be exploited to compromise their wallets' secret recovery phrases, or seeds, and facilitate the theft of all stored cryptocurrency and NFTs, BleepingComputer reports.
Cybersecurity practices at small and medium-sized businesses continued to be dismal, with only 38% of employees and managers noting more frequent password manager usage, while only 37% and 36% conducted more cybersecurity training sessions and executed new security policies, respectively, reports TechRadar.
Sixty-two percent of security leaders around the world surveyed by Radware reported having at least a third of APIs that are undocumented, even though 92% believed having sufficient API protection, indicating the prevalence of a false sense of security in APIs, according to VentureBeat.
BleepingComputer reports that forced updates have been implemented for WordPress sites leveraging the Ninja Forms plugin, which was discovered by Wordfence researchers to be impacted by a critical code injection flaw that could be exploited to facilitate site takeovers.
On the heels of a White House Cybersecurity Executive Forum, HHS HC3 is urging the healthcare sector to make use of free resources to improve risk assessments and overall cyber resiliency.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.