December, 2014

article thumbnail

Find the Next Heartbleed-like Vulnerability

NopSec

Heartbleed (CVE-2014-0160) is a vulnerability with a CVSSv2 base score of only 5.0/10.0. Though its CVSS score is relatively low, Heartbleed has definitely been one of the most severe security events the Internet has never seen. It is found in the Open SSL cryptographic software library, which is omnipresent on the Internet, and it exploits a buffer over-read weakness in the library, a situation where more data can be read than should be allowed ( [link] ).

Risk 52
article thumbnail

Privacy Politics at IAPP, Brussels!

Privacy and Cybersecurity Law

The recent IAPP Congress in Brussels provided a platform to bring out the “big guns” on privacy. Needless to say, […].

40
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Security Doom Scenarios….OK….name your passwords’ directory “Password”

NopSec

Usually I am not particularly a big fan of security doom scenarios, but looking at this week’s security news and the usual New Year’s security predictions I have to admit that I grew a bit concerned about the overall info security outlook. Here is the canvas: Sabotage attacks from Iran targeting US industrial control systems and critical infrastructure modeled after Stuxnet, Duqu, and Wiper are growing in frequency.

article thumbnail

Canada’s Anti-Spam Law (CASL) applies to Software January 15

Privacy and Cybersecurity Law

Earlier this year we told you that Canada’s Anti-Spam Law (CASL) is not just for Canadians. CASL is also not just […].

article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

New EU Guidelines on “Google Spain”: Right to be Forgotten

Privacy and Cybersecurity Law

The Article 29 Working Party published new Guidelines on the Right to be Forgotten on 26 November 2014. This is […].

40