As 2022 draws to a close in a few days, we thought we’d round up the top 10 cybersecurity stories in one article, along with a brief recap. The catastrophic cyberwar against the West that some had predicted never materialized, but the cyber dimension of the Ukrainian conflict continued to dominate the tech news agenda in a year when the return of war to Europe dominated the mainstream news agenda. In addition to Ukraine and the usual high-profile vulnerabilities, some of the year’s biggest topics included open source security. This was due to the Log4Shell Adobe Log4j disclosures in late 2021, which highlighted the dangers of using open source tools. See also: Top apps to easily learn foreign languages

Risk management was, in fact, the top priority for the c-suite in 2022. Key talking points included the growing interest in innovative methods to mitigate the threat of ransomware , as well as new strategies for securing cybersecurity. Here are ComputerWeekly’s top 10 stories for 2022: cybersecurity 1. Backups “are no longer effective” in preventing ransomware attacks. In February, a report from Venafi caught readers’ attention because its data showed that previously effective data backup strategies may be less effective in mitigating and containing a ransomware attack. The report informed us of the rise in double and triple extortion attacks, in which data is stolen as an alternative method of extortion. 2. Apple patches two zero-day vulnerabilities in macOS and iOS There have been many zero-day discoveries in the past 12 months. Without a doubt, two of the Apple vulnerabilities that were made public in August had the biggest impact on ComputerWeekly readers . The problems affected the desktop macOS Monterey operating system, the iOS and iPad operating systems , and the Safari browser . If left unpatched, they could lead to the execution of arbitrary code . 3. European Commission proposes new cybersecurity laws. As a major regional power, the United Kingdom must continue to monitor events in Brussels , even though it has left the European Union (EU). The European Commission proposed new rules in March to establish standard cybersecurity measures and information security for EU institutions. See also: Predator surveillance: This is how they targeted politicians, citizens, and companies!

4. Increased use of Telegram in Russia and Ukraine. Additionally, in March, Check Point researchers revealed how residents of both Russia and Ukraine were using the encrypted, cloud-based messaging service Telegram to organize, raise money for charities, and share news (including propaganda and disinformation). The platform proved particularly popular among Ukrainian hacktivists who were organizing attacks against Russian targets. 5. Kaspersky forced to deny source code leak . Kaspersky , an antivirus company founded in Russia in the 1990s, came under fire from Western governments and hacktivists shortly after the war began. One of those groups, possibly linked to Anonymous , claimed to have access to the company’s source code, a claim Kaspersky quickly denied. 6. Microsoft releases emergency patch after Patch Tuesday. Microsoft was forced to release a rare offline patch shortly after the regular Patch Tuesday update to address an issue that caused server or client authentication failures among users who had already installed the first update. The issue centered on how Domain Controllers handle the pairing of certificates with machine accounts. See also: Google Meet – Translated subtitles: More languages added

7. Lloyds of London ends insurance coverage for state-sponsored cyberattacks . In August, insurance exchange Lloyd’s of London announced that, from March 31, 2023, it would instruct its insurance groups to exclude “catastrophic” nation-state cyberattacks from policy coverage, due to the systemic risk they pose. While it still generally supports cyber insurance, Lloyds believes its members should manage their policies more effectively. 8. 15-year-old Python bug found in 350,000 source code projects. More than 350,000 projects are vulnerable to potential cyberattacks on supply chains as a result of a 15-year-old vulnerability in the open-source Python programming language that Trellix researchers discovered in September. If exploited, it allows a remote attacker with user assistance to replace any random files using a specific filename sequence in a TAR archive, leading to arbitrary code execution or control of the target device. 9. Cozy Bear targets MS 365. environments with new strategies The “Cozy Bear” threat actor known as “APT29,” which has ties to Russian intelligence, was very active in 2022 in support of Russia’s conflict in Ukraine. Mandiant issued a warning in August that the operation was changing its strategies as it targeted organizations in NATO countries, including forging Microsoft 365 licenses for its victims. 10. Prepare for a potentially high-impact OpenSSL flaw today In October, OpenSSL released a critical vulnerability patch—only the second of its kind in the open-source cryptosystem since Heartbleed. Fortunately, it wasn’t as dangerous as most people expected. Source: computerweekly.com
