July, 2016

article thumbnail

Hillary Clinton's infamous email server: 6 things you need to know

Tech Republic Security

Hillary Clinton's use of a private email server when she served as US secretary of state has been a major issue for the 2016 presidential candidate. Here are the six most critical facts about it.

153
153
article thumbnail

5 useful tips to bulletproof your credit cards against identity theft

Elie

Here are the 5 ways I bulletproof my credit cards against identity theft, and you can use them yourself very easily. As a bonus, at the end of the post I have added an experimental step to defend against the recent chip downgrading attack.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Why CGC Matters to Me

ForAllSecure

By David Brumley. In 2008 I started as a new assistant professor at CMU. I sat down, thought hard about what I had learned from graduate school, and tried to figure out what to do next. My advisor in graduate school was Dawn Song , one of the top scholars in computer security. She would go on to win a MacArthur "Genius" Award in 2010. She's a hard act to follow.

article thumbnail

Hacking with Kali at Black Hat USA 2016

Kali Linux

Kali Linux Dojo, BlackHat 2016 - Las Vegas We have really enjoyed doing the Dojo at Black Hat the last few years. It’s been a great opportunity to show off some of the lesser known (but oh so useful) features of Kali Linux as well as interact with the user base. But one of the limitations of the previous structure was that while this was a hands-on exercise, many attendees moved at different paces from each other.

Hacking 52
article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

NopSec Cloud Security Module

NopSec

Most organizations are currently migrating their computing infrastructure into the public cloud (AWS, Google, Azure) usually embracing a mixed private / public cloud model. Most SaaS solutions, including NopSec, already base their entire computing infrastructure on public clouds. This creates a unique challenge in terms of setting up proper vulnerability management processes to address the cloud environment’s peculiarities.

article thumbnail

CRTC ENFORCEMENT ADVISORY: REMEMBER, YOU MUST HAVE RECORDS TO PROVE CONSENT

Privacy and Cybersecurity Law

The Canadian Radio-television and Telecommunications Commission (CRTC) issued an enforcement advisory to both businesses and individuals that send commercial electronic […].

More Trending

article thumbnail

How to Avoid Ransomware in Google Workspace?

Spinone

Let’s explore how to avoid ransomware in Google Workspace. Ransomware has been a consistent threat to your cloud security. It can corrupt your computer files and files you store with the cloud service providers. There are many ways to spread such malware. How G Suite Ransomware May Spread Emails are frequently used way. You receive […] The post How to Avoid Ransomware in Google Workspace?

article thumbnail

Why CGC Matters To Me

ForAllSecure

In 2008 I started as a new assistant professor at CMU. I sat down, thought hard about what I had learned from graduate school, and tried to figure out what to do next. My advisor in graduate school was Dawn Song , one of the top scholars in computer security. She would go on to win a MacArthur "Genius" Award in 2010. She's a hard act to follow. I was constantly reminded of this because, by some weird twist of fate, I was given her office when she moved from CMU to Berkeley.

article thumbnail

Kali Linux Dojo at Black Hat Vegas 2016

Kali Linux

The folks at Black Hat have been kind enough to invite us once again to deliver a Kali Dojo in Las Vegas this year. The event will be held on the 4th of August at the Mandalay Bay hotel, and will be open to all Black Hat pass types. This year our Dojo will be set up differently, allowing for a larger crowd and much more interaction. We are going to hold a full day event, featuring several main activity areas : Area 1: Customising Kali ISOs using live-build One to the most important aspects of Ka

article thumbnail

NopSec Report Finds Organizations Use Inadequate Risk Evaluation Scoring System

NopSec

NopSec released a featured annual report, “2016 State of Vulnerability Risk Management.” The report reveals key security threats by industry, cross-industry remediation developments, malware-based vulnerabilities, and the rising correlation of social media and security threats. Conducted by the NopSec Labs research team, the report analyzes over a million unique vulnerabilities and more than 76,000 vulnerabilities contained in the National Vulnerability Database over a 20-year period.

Risk 52
article thumbnail

IDC Analyst Report: The Open Source Blind Spot Putting Businesses at Risk

In a recent study, IDC found that 64% of organizations said they were already using open source in software development with a further 25% planning to in the next year. Most organizations are unaware of just how much open-source code is used and underestimate their dependency on it. As enterprises grow the use of open-source software, they face a new challenge: understanding the scope of open-source software that's being used throughout the organization and the corresponding exposure.

article thumbnail

Privacy Shield gets approval: certainty at last??

Privacy and Cybersecurity Law

The European Commission yesterday issued an adequacy decision adopting the EU-US Privacy Shield, which replaces Safe Harbor as a framework […].

40
article thumbnail

Zero Days: Why the disturbing Stuxnet documentary is a must-see

Tech Republic Security

Zero Days is a documentary by Oscar-winning filmmaker Alex Gibney about the cyberwarfare Pandora's Box that was opened with the Stuxnet malware. Find out why Jack Wallen highly recommends the film.

Malware 119
article thumbnail

How to Avoid G Suite Ransomware?

Spinone

Let’s explore how to avoid Ransomware viruses, that are a new very serious threat to your cloud security that can corrupt your computer files and files you store with the cloud service providers. There are many ways to spread such viruses. How G Suite Ransomware May Spread Emails are frequently used way. You receive a message like “I Love You”, then click a link with a virus, and you are done.

article thumbnail

Why CGC Matters To Me

ForAllSecure

In 2008 I started as a new assistant professor at CMU. I sat down, thought hard about what I had learned from graduate school, and tried to figure out what to do next. My advisor in graduate school was Dawn Song , one of the top scholars in computer security. She would go on to win a MacArthur "Genius" Award in 2010. She's a hard act to follow. I was constantly reminded of this because, by some weird twist of fate, I was given her office when she moved from CMU to Berkeley.

article thumbnail

Beware of Pixels & Trackers on U.S. Healthcare Websites

The healthcare industry has massively adopted web tracking tools, including pixels and trackers. Tracking tools on user-authenticated and unauthenticated web pages can access personal health information (PHI) such as IP addresses, medical record numbers, home and email addresses, appointment dates, or other info provided by users on pages and thus can violate HIPAA Rules that govern the Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates.

article thumbnail

Review: 'Down the Deep Dark Web' is a movie every technologist should watch

Tech Republic Security

Documentary filmmaker Yuval Orr interviewed cryptoanarchists, hackers, and security experts about why encryption and privacy are important. His new movie will make you see the Dark Web in a new light.

article thumbnail

Ransomware 2.0 is around the corner and it's a massive threat to the enterprise

Tech Republic Security

The profits from ransomware are making it one of the fastest growing types of malware and new versions could negatively impact entire industries, according to a Cisco report.

article thumbnail

Facebook Messenger boosts privacy with end-to-end encryption, self-destructing messages

Tech Republic Security

In a recent privacy push, Facebook announced that it was rolling out the beta of a new feature called 'secret conversations,' bringing better encryption and ephemeral messaging.

article thumbnail

New US cybersecurity plan makes it easier for businesses to get help after an attack

Tech Republic Security

US President Barack Obama recently published a policy directive for cyber incident coordination, which outlines how the government should respond to cybersecurity attacks.

article thumbnail

Software Composition Analysis: The New Armor for Your Cybersecurity

Speaker: Blackberry, OSS Consultants, & Revenera

Software is complex, which makes threats to the software supply chain more real every day. 64% of organizations have been impacted by a software supply chain attack and 60% of data breaches are due to unpatched software vulnerabilities. In the U.S. alone, cyber losses totaled $10.3 billion in 2022. All of these stats beg the question, “Do you know what’s in your software?

article thumbnail

HummingBad malware infects 10 million Android devices, millions more at risk

Tech Republic Security

A new malware called HummingBad, associated with Chinese cyber criminals Yingmob, has infected millions of devices and brings in millions of dollars of fake ad revenue.

Malware 113
article thumbnail

10 tips to avoid ransomware attacks

Tech Republic Security

As ransomware increasingly targets healthcare organizations, schools and government agencies, security experts offer advice to help IT leaders prepare and protect.

article thumbnail

TiaraCon to bring more women into critical, lucrative cybersecurity jobs that are going unfilled

Tech Republic Security

A 2-day mini-conference called TiaraCon aims to connect women interested in the cybersecurity field with job contacts and mentoring to create more inclusive work environments.

article thumbnail

Gmail password compromised? Here are 5 steps to help you secure your account and find the leaks

Tech Republic Security

If your Gmail account credentials ever become public, here are five steps you can take to secure your account and make sure only the right people have access to your account.

article thumbnail

From Complexity to Clarity: Strategies for Effective Compliance and Security Measures

Speaker: Erika R. Bales, Esq.

When we talk about “compliance and security," most companies want to ensure that steps are being taken to protect what they value most – people, data, real or personal property, intellectual property, digital assets, or any other number of other things - and it’s more important than ever that safeguards are in place. Let’s step back and focus on the idea that no matter how complicated the compliance and security regime, it should be able to be distilled down to a checklist.

article thumbnail

Approach IoT security as a system design problem

Tech Republic Security

Don't let IoT security be an afterthought. The National Institute of Science and Technology (NIST) suggests integrating systems security engineering at the start of an IoT project.

IoT 105
article thumbnail

10 mobile security myths that need debunking

Tech Republic Security

Mobile devices have introduced plenty of legitimate concerns, but there are some misconceptions floating around that may lead companies to focus on the wrong issues--or to ignore the real risks.

Mobile 106
article thumbnail

Keep smartphones backdoor free, urges cybersecurity expert Susan Landau

Tech Republic Security

Privacy expert Susan Landau makes the case for keeping smartphones backdoor free, and for the FBI developing 21st century capabilities to conduct electronic surveillance.

article thumbnail

How to work with PGP keys using GnuPG

Tech Republic Security

To encrypt email and files, you need to know how to work with PGP keys. Get up to speed on generating, exporting, and importing encryption keys with GnuPG.

article thumbnail

Successful Change Management with Enterprise Risk Management

Speaker: William Hord, Vice President of ERM Services

A well-defined change management process is critical to minimizing the impact that change has on your organization. Leveraging the data that your ERM program already contains is an effective way to help create and manage the overall change management process within your organization. Your ERM program generally assesses and maintains detailed information related to strategy, operations, and the remediation plans needed to mitigate the impact on the organization.

article thumbnail

Simple security: How Gmail, Mailvelope, and Virtru make encrypted email easier

Tech Republic Security

Encrypting your email is a great step towards more secure communication. Gmail, Mailvelope, and Virtru can help streamline your encrypted email efforts.

article thumbnail

Video: How ForeScout Technologies fends off cyberattacks at the RNC and DNC

Tech Republic Security

TechRepublic's Dan Patterson talked with ForeScout VP Katherine Gronberg about the biggest cyber threats facing the conventions, and what goes on in the command center where those threats are monitored.

article thumbnail

IoT hidden security risks: How businesses and telecommuters can protect themselves

Tech Republic Security

There are a plethora of IoT-connected devices that create a huge security risk for companies, whether at the corporate office, or at an employee's home office.

IoT 107
article thumbnail

Microsoft doesn't have to give US government foreign data, says court

Tech Republic Security

Microsoft recently won an appeal over a US search warrant that aimed to force the company to turn over data that was stored on foreign servers.

article thumbnail

Cybersecurity Predictions for 2024

Within the past few years, ransomware attacks have turned to critical infrastructure, healthcare, and government entities. Attackers have taken advantage of the rapid shift to remote work and new technologies. Add to that hacktivism due to global conflicts and U.S. elections, and an increased focus on AI, and you have the perfect recipe for a knotty and turbulent 2024.