Third-party Cybersecurity Risks Surge: Attackers are increasingly targeting less secure partners and vendors to ultimately gain access to the real target’s internal systems and data. This happened recently — after the announcement of vulnerabilities in MOVEit Transfer, unsuspecting third-parties of victims found themselves affected. The fact that so many organizations continue to fail controls important for sound vulnerability management is cause for concern.
A ransomware attack at top Colombian energy company Empresas Publicas de Medellin (EPM) may damage its credit quality, setting an alarm clock for the critical infrastructure industry to develop efficient mitigation practices and vulnerability management programs, Moody’s said.