Legacy IT has become the dirty little secret of digital transformation. These systems, which include servers, OSes, and applications, are relied on by almost every organization for business-critical activities – and many CISOs struggle to protect them from attackers.
The stack of technologies that 5G uses could allow attacks aimed at operator networks as well as subscribers, launched from international roaming networks, operator networks or even partner networks providing access to services.
Researchers observed a spear phishing campaign that exactly spoofed a Microsoft email domain to trick Office 365 users. This suggests Microsoft’s servers were not enforcing protective DMARC authentication protocols when communications were received – and perhaps still are not.
Manufacturers affected by the 33 vulnerabilities in open-source TCP/IP stacks often buried deep in the supply chain may not immediately know their devices are at risk.
Two popular Baidu apps collect data that can surreptitiously track a user’s location through Stingray devices or intercept phone calls and text messages.
The joint effort reflects the need across organizations to maintain an up-to-date inventory of IoT assets and continually assess the network to ensure patches are pushed and weak or default credentials do not leave systems vulnerable.
On one hand, simulations should mimic real-life phishing campaigns as closely as possible. On the other hand, an insensitive training exercise can place your company in bad standing with employees.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.