Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
PR Newswire
CHARLOTTESVILLE, Va., March 25, 2022
CHARLOTTESVILLE, Va., March 25, 2022 /PRNewswire/ -- The string of recent data breaches at major technology companies like Microsoft, Nvidia and Samsung by the Lapsus$ hacking group are an important reminder that all businesses need to have in place strong social engineering defenses that extend throughout the entire organization.
Although several alleged members of Lapsus$ have now been arrested, and the group may no longer pose the threat it once did, the innovative social engineering tactics it utilized are likely to be repeated by other criminal hacking groups.
These tactics may catch many companies off-guard, particularly if they are too focused on conventional tactics like email phishing. Robust monitoring and defense solutions are needed to protect corporate assets against a range of diverse tactics, from insider recruitment to the targeting of help desks and support teams, phone-based social engineering attacks, personal email compromises, SIM jacking, pass-the-cookie session hijacking and more. Groups like Lapsus$ begin with a compromised employee or contractor account and then use this initial access point to escalate privileges inside the targeted organization.
"Social engineering tactics are constantly evolving, and businesses need to be prepared for a wide range of attacks that can exploit a large, and often far-flung, employee and contractor base, with tactics that are increasingly aiming for below-the-radar targets such as personal email accounts, cell phones and digital communications platforms like Slack," said Chris Lehman, CEO of SafeGuard Cyber. "The recent attacks by the Lapsus$ hacking group demonstrate that even the biggest companies in the world can fall victim to social engineering efforts, especially when they target employees and platforms that are of a lower priority for large corporate security programs."
As the world's leading provider of security and compliance solutions for today's communications-based threats, SafeGuard Cyber is issuing important safety advice on what steps companies can take to better defend against these evolving social engineering threats. It is particularly important for organizations to protect their digital communications platforms, as attackers may use these channels to escalate privileges inside the company once they have gained access through an employee's account.
Here are several steps businesses can take to prevent this type of privilege escalation:
For more detailed advice and explanations about this threat, read SafeGuard Cyber's analysis, "Lapsus$ Playbook in the Open, and Companies Are Not Ready," by Director of Intelligence Storm Swendsboe and CRO Mike Campfield.
SafeGuard Cyber's security and compliance solutions enable organizations to manage risks across a wide range of digital communications. The company's platform allows enterprises to:
SafeGuard Cyber has been recognized by several industry groups and publications and was named one of Cybercrime Magazine's "10 Hot Cybersecurity Channels to Watch in 2021." The company also received eight Cybersecurity Excellence awards for 2022 and the "SaaS Security Solution of the Year" award in 2021.
About SafeGuard Cyber
SafeGuard Cyber provides security and compliance for human connections so enterprises can trust modern communications. With patented Natural Language Understanding technology, our security solutions deliver comprehensive visibility, detection and response to threats across the disparate communication methods used by today's digitally enabled businesses. In addition, cloud-based machine learning provides compliance solutions for governance and policy enforcement that empower customers to communicate through modern apps and social networking. Learn more at www.safeguardcyber.com.
View original content to download multimedia:https://www.prnewswire.com/news-releases/safeguard-cyber-provides-security-advice-for-defending-against-lapsus-style-social-engineering-attacks-301510943.html
SOURCE SafeGuard Cyber
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs