Pretnje
18 direktnih pogodaka-
№ 073
Model theft / extraction Model theft and extraction means an attacker obtains a model an organization trained, bought or adapted to its own needs. That can be direct theft of the files, …pretnja · AI / ML
-
№ 018
Token Theft … you do not have to type the password again. Token theft is the taking of that proof. With it in hand, the attacker presents themselves as you — without your pas …pretnja · identity
-
№ 042
API Abuse API abuse arises when an attacker uses a programming interface in a way the application did not anticipate or did not restrict enough. An API is not merely a technical add-on to the application. It is often the main entrance to the data, the users, the orders, the payments and the administration.pretnja · applications
-
№ 063
Contractor Abuse The risk is not only deliberate theft. A private laptop with no protection is enough, or keeping data for the next project, or sharing an account inside the sup …pretnja · trust
-
№ 013
Cryptominer A cryptominer steals what we rarely think of as a target: our computing power and our electricity. In the background it uses our processors and graphics cards to mine cryptocurrency for the attacker while we pay the bill. It has no interest in our data, only in our resources and how much of them there is.pretnja · malware
-
№ 012
Infostealer An infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.pretnja · malware
-
№ 058
Insider Threat An insider threat comes from a person who has, or once had, legitimate access to an organization's systems, data or premises. That can be an employee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized to begin with.pretnja · trust
-
№ 071
Physical Access Attack … in behind an employee through an automatic door, theft of equipment, access to the server room, planting a keylogger, booting from external media, photographin …pretnja · physical / IoT
-
№ 061
Privilege Misuse Privilege misuse arises when somebody uses rights they genuinely hold for actions they have no business reason to take. Unlike privilege escalation, the attacker or insider here does not have to acquire new authority. The trouble is that the existing authority is enough to do damage.pretnja · trust
-
№ 039
SQL Injection SQL injection usually arises when a web application passes user input blindly to the database on the web server. Instead of ordinary text, the attacker can put part of an SQL command into a login, search or filter field. If the application does not stop it, the database can execute something the designer never had in mind, and certainly never intended.pretnja · applications
-
№ 021
Account Takeover … came before: phishing, credential stuffing, token theft.pretnja · identity
-
№ 040
Cross-Site Scripting … ried out in the right place, it can cause session theft, account takeover or a covert way into a business application.pretnja · applications
-
№ 049
Distributed Denial of Service / DDoS … until the server is blocked. The aim is not data theft but choking the service into unavailability.pretnja · availability
-
№ 068
Evil Twin … ttacker can watch the traffic, attempt credential theft, present a fake captive portal, redirect the user, or run an attack as a man in the middle. In public pl …pretnja · physical / IoT
-
№ 038
Remote Code Execution … t execution come a web shell, further tools, data theft, lateral movement and an attempt to keep the unauthorized access alive. RCE is therefore not treated as …pretnja · applications
-
№ 070
SCADA/OT Attack In attacks like these the aim is not always theft. It can be a halt in production, a change of parameters, damage to equipment, pressure on the operators, or sa …pretnja · physical / IoT
-
№ 019
Session Hijacking … r is obtained in several ways. The most common is theft of the session cookie — by intercepting traffic on an unprotected connection, through a flaw on the site …pretnja · identity
-
№ 066
Typosquatting … ar site but ends up on a fake page for credential theft, malware distribution or advertising. With software packages, a developer installs a package whose name …pretnja · trust
Odbrane
4 direktna pogotka-
№ 024
Backup & Recovery Backup and recovery encompasses the processes and technologies for regularly creating copies of data and systems, storing them securely, and enabling reliable restoration in the event of loss, corruption, or destruction of original data.odbrana · resilience
-
№ 009
Identity & Access Management Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.odbrana · identity / access
-
№ 005
Mobile Device Security … ects against mobile phishing, malware, and device theft.odbrana · endpoints
-
№ 036
Virtual Private Network A VPN (virtual private network) creates an encrypted tunnel between a device and the network it connects to. For an organization this primarily means controlled remote access to internal resources — from home, on the road, in the field. Traffic inside the tunnel cannot be read in transit, even on hotel Wi-Fi.odbrana · resilience