a post by Dan Patterson for c|net [with thanks to Tara at ResearchBuzz: Firehose]
We asked cybersecurity experts to scour the dark web for our personal information. What they found was disturbing.
What do Dunkin' Donuts, Fortnite, Sprint and the Dow Jones company all have in common? They've all suffered from massive hacks in 2019 alone.
After every data breach, victim data often surfaces on the encrypted "hidden" internet known as the dark web, a network of sites that can only be accessed with special security software. Dark web markets operate like the ecommerce websites we shop on every day, but often trade in illicit goods like drugs, weapons and stolen data.
Because so many companies now capture and store personal information, hacking has become a profitable profession, said Terbium Labs vice president of research Emily Wilson. One hacker known as Gnosticplayers has allegedly leaked over 840 million user records. His most recent dump of 26.42 million records was listed for 1.2431 bitcoin, or about $4,940.
Continue reading
Showing posts with label data_breaches. Show all posts
Showing posts with label data_breaches. Show all posts
Wednesday, 10 April 2019
Wednesday, 15 November 2017
Enterprise data breach: causes, challenges, prevention, and future directions
an article by Long Cheng,Fang Liu and Danfeng (Daphne) Yao (Virginia Tech, USA) published in WIREs Data Mining and Knowledge Discovery Volume 7 Issue 5 (September/October 2017)
Abstract
A data breach is the intentional or inadvertent exposure of confidential information to unauthorized parties.
In the digital era, data has become one of the most critical components of an enterprise. Data leakage poses serious threats to organizations, including significant reputational damage and financial losses. As the volume of data is growing exponentially and data breaches are happening more frequently than ever before, detecting and preventing data loss has become one of the most pressing security concerns for enterprises.
Despite a plethora of research efforts on safeguarding sensitive information from being leaked, it remains an active research problem.
This review helps interested readers to learn about enterprise data leak threats, recent data leak incidents, various state-of-the-art prevention and detection techniques, new challenges, and promising solutions and exciting opportunities.
Full text (PDF 14pp)
I did not understand much of the text but the images provided made this whole area of unseen attacks clearer.
Abstract
A data breach is the intentional or inadvertent exposure of confidential information to unauthorized parties.
In the digital era, data has become one of the most critical components of an enterprise. Data leakage poses serious threats to organizations, including significant reputational damage and financial losses. As the volume of data is growing exponentially and data breaches are happening more frequently than ever before, detecting and preventing data loss has become one of the most pressing security concerns for enterprises.
Despite a plethora of research efforts on safeguarding sensitive information from being leaked, it remains an active research problem.
This review helps interested readers to learn about enterprise data leak threats, recent data leak incidents, various state-of-the-art prevention and detection techniques, new challenges, and promising solutions and exciting opportunities.
Full text (PDF 14pp)
I did not understand much of the text but the images provided made this whole area of unseen attacks clearer.
Tuesday, 11 April 2017
If You Want to Stop Big Data Breaches, Start With Databases
an article by Lily Hay Newman published in WIRED on 29 March 2017
Thanks to Research Buzz for the link
Over the past few years, large-scale data breaches have become so common that even tens of millions of records leaking feels unremarkable. One frequent culprit that gets buried beneath the headlines? Poorly secured databases that connect directly to the internet.
While companies commonly use these databases to store tempting troves of customer and financial data, they often do so with outdated and weak default security configurations. And while any type of database can be left open or unprotected, a string of breaches over the last few years have all centered around one type in particular: open-source “NoSQL” databases, particularly those using the popular MongoDB database program. Of course there are many types of hacks that can ultimately lead to data breaches, like using spear phishing to gain access to a network, but securing exposed databases is a relatively easy and concrete step organizations can take to strengthen their data defense.
Continue reading
Thanks to Research Buzz for the link
Over the past few years, large-scale data breaches have become so common that even tens of millions of records leaking feels unremarkable. One frequent culprit that gets buried beneath the headlines? Poorly secured databases that connect directly to the internet.
While companies commonly use these databases to store tempting troves of customer and financial data, they often do so with outdated and weak default security configurations. And while any type of database can be left open or unprotected, a string of breaches over the last few years have all centered around one type in particular: open-source “NoSQL” databases, particularly those using the popular MongoDB database program. Of course there are many types of hacks that can ultimately lead to data breaches, like using spear phishing to gain access to a network, but securing exposed databases is a relatively easy and concrete step organizations can take to strengthen their data defense.
Continue reading
Subscribe to:
Posts (Atom)