An unauthorized set of programming instructions to increase…

An unauthorized set of programming instructions to increase a software developers pay rate by 10% is hidden inside an authorized program.  Once certain conditions are met, the instructions activate and update the payroll file with the pay raise increase.  What type of malware is this computer fraud technique using?

Many of you, if not all of you, have probably experienced a…

Many of you, if not all of you, have probably experienced a phishing email attempt by a ‘hacker’ attempting to gain access to your account.  Other attempts to gain access may include brute-force attempts looking for weak passwords, or targeting dormant accounts, shared accounts, accounts that came embedded in applications or hardware (i.e., service accounts), or trying passwords that have been re-used at other sites and have been comprised.   As a result, companies should use a series of processes, controls, and tools to assign and manage authorization credentials for user accounts, administrator accounts, and service accounts across the company’s assets and software. Companies that utilize such processes, controls, and tools are performing the [CISControl] control in the Center for Internet Security (CIS) v8 framework.