Cybersecurity Companies Expose Sensitive Data Online
Tuesday, September 8, 2020
Low risk refers to “mentions of an organization, its IT assets or employees in data leaks, samples or dumps without accompanying sensitive or confidential information,” while medium risk could include encrypted passwords or leaks of “moderately” sensitive data such as source code or internal docs.
ImmuniWeb CEO Ilia Kolochenko warned that third parties like security vendors are an increasingly popular target for attackers.
“In 2020, one need not spend on costly zero-days but rather find several unprotected third parties with privileged access to the ‘Crown Jewels’ and swiftly crack the weakest link,” he added. Read Full Article
BCS, The Chartered Institute for IT: Gone phishing: How COVID-19 has extended the security battlefield
SC Media: NYSE not susceptible to takedown like New Zealand exchange