Top

Tag: Security


Cybersecurity

Security researcher identifies new APT group mentioned in 2017 Shadow Brokers leak

April 22, 2020

Via: ZDnet

Three years and eight days ago, on April 14, 2017, a mysterious group of hackers known as the Shadow Brokers published a collection of hacking tools that ended up changing the internet forever. Known as the “Lost in Translation” dump, […]


Hardware & Software, Tech

Microsoft reports new zero-day vulnerability in Windows that is being actively exploited

March 23, 2020

Via: TechSpot

Microsoft posted a new security advisory today (ADV200006), detailing what it’s calling “Type 1 Font Parsing Remote Code Execution Vulnerability.” They have given the vulnerability a “critical” severity rating, which is the highest severity rating Microsoft gives. The flaw seems […]


Cybersecurity

Why fixing security vulnerabilities in medical devices, IoT is so hard

February 19, 2020

Via: ArsTechnica

When your family opened up that brand-new computer when you were a kid, you didn’t think of all of the third-party work that made typing in that first BASIC program possible. There once was a time when we didn’t have […]


Cybersecurity

Presidential campaigns taking email security more seriously–not so much at the local level

February 10, 2020

Via: CSO Online

The 2020 election season got off to what could be a record-setting rocky start with delays in the reporting of the Iowa caucus results due to a poorly developed app. The failure of the mobile IowaReporterApp developed for the Democratic […]


Cybersecurity

Why hacking must be addressed in digital privacy policymaking

February 7, 2020

Via: CSO Online

Digital privacy is one side of a two-sided policy coin. Virtually all attention to date has been focused on developing legal and regulatory remedies to address this pervasive public concern. But in doing so, they have devoted little attention to […]


Cloud Computing

Infrastructure-as-code templates are the source of many cloud infrastructure weaknesses

February 5, 2020

Via: CSO Online

In the age of cloud computing where infrastructure needs to be extended or deployed rapidly to meet ever-changing organizational needs, the configuration of new servers and nodes is completely automated. This is done using machine-readable definition files, or templates, as […]


Federal, Policy

Recent False Claims Act cases a caution to gov’t contractors that skimp on security

February 4, 2020

Via: CSO Online

The False Claims Act (FCA), otherwise known as the “Lincoln Law,” can cost companies that supply goods or services to the federal government millions of dollars if they fail to provide the digital security protections they promise, as two recent […]


Cybersecurity

Huawei refutes suggestions state support drove its growth

December 26, 2019

Via: ZDnet

Huawei Technologies has lashed out at a US Media report that suggests the tech giant’s success is fuelled by billions of dollars in financial support from the Chinese government, arguing that its ties are no different from any other private […]


Federal, Policy

Justice Dept. charges Russian hacker behind the Dridex malware

December 5, 2019

Via: Tech Crunch

U.S. prosecutors have brought computer hacking and fraud charges against a Russian citizen, Maksim Yakubets, who is accused of developing and distributing Dridex, a notorious banking malware used to allegedly steal more than $100 million from hundreds of banks over […]


Cybersecurity

A bug in Microsoft’s login system put users at risk of account hijacks

December 2, 2019

Via: Tech Crunch

Microsoft has fixed a vulnerability in its login system, which security researchers say could have been used to trick unsuspecting victims into giving over complete access to their online accounts. The bug allowed attackers to quietly steal account tokens, which […]


Cybersecurity

A new era of cyber warfare: Russia’s Sandworm shows “we are all Ukraine” on the internet

November 25, 2019

Via: CSO Online

Speakers at this year’s CyberwarCon conference dissected a new era of cyber warfare, as nation-state actors turn to a host of new advanced persistent threat (APT) strategies, tools and tactics to attack adversaries and spy on domestic dissidents and rivals. […]


Editorial

5G and Smart Cities: A Slippery Slope Towards Mass Surveillance?

November 16, 2019

Via: Michael Boyd

5G technology, the next big revolution in mobile connectivity, aims at providing better mobile broadband connectivity and speed for a wider range of customers. While 5G has the potential to enable fundamentally new applications and dramatically improve the quality of […]


Cybersecurity

What the newly released Checkra1n jailbreak means for iDevice security

November 15, 2019

Via: ArsTechnica

It has been a week since the release of Checkra1n, the world’s first jailbreak for devices running Apple’s iOS 13. Because jailbreaks are so powerful and by definition disable a host of protections built into the OS, many people have […]


Cybersecurity

How EDR stops hackers in their tracks

November 11, 2019

Via: CSO Online

Endpoint detection and response (EDR) is a category of security tools that monitor end-user hardware devices across a network for a range of suspicious activities and behavior, reacting automatically to block perceived threats and saving forensics data for further investigation. […]


Cybersecurity

The scariest hacks and vulnerabilities of 2019

October 28, 2019

Via: ZDnet

Yes, this is one of those end-of-year summaries. And it’s a long one, since 2019 has been a disaster in terms of cyber-security news, with one or more major stories breaking on a weekly basis. Below is a summary for […]


Cybersecurity

Open database leaked 179GB in customer, US government, and military records

October 21, 2019

Via: ZDnet

An open database exposing records containing the sensitive data of hotel customers as well as US military personnel and officials has been disclosed by researchers. On Monday, vpnMentor’s cybersecurity team, led by Noam Rotem and Ran Locar, said the database […]


Cybersecurity

Samsung confirms glaring S10 fingerprint reader flaw, promises fix

October 17, 2019

Via: Tech Crunch

Galaxy S10 users should turn on some alternative security features as Samsung works to address a major flaw with the device’s in-screen fingerprint sensor. The consumer electronics giant noted the issue today after a British user reported the ability to […]


Hardware & Software, Networking & Wireless, Tech

Mozilla: Firefox 70 brings you these new security indicators

October 16, 2019

Via: ZDnet

Firefox 70 is introducing new padlock icon security and identity indicators in the browser that will give less visual prominence to Extended Validation (EV) SSL certificates and draw more attention to sites delivered via the insecure HTTP protocol. Mozilla and […]


Cybersecurity

Thoma Bravo makes $3.9 billion offer to acquire security firm Sophos

October 14, 2019

Via: Tech Crunch

Sophos announced this morning that private equity firm Thoma Bravo, has agreed to buy the British company for £3.1 billion ($3.9 billion USD). The price is based on $7.40 USD per share and the company indicated that the board of […]


Cybersecurity

Why big ISPs aren’t happy about Google’s plans for encrypted DNS

October 1, 2019

Via: ArsTechnica

When you visit a new website, your computer probably submits a request to the domain name system (DNS) to translate the domain name (like arstechnica.com) to an IP address. Currently, most DNS queries are unencrypted, which raises privacy and security […]