Sat.Feb 10, 2018 - Fri.Feb 16, 2018

article thumbnail

Internet Security Threats at the Olympics

Schneier on Security

There are a lot : The cybersecurity company McAfee recently uncovered a cyber operation, dubbed Operation GoldDragon, attacking South Korean organizations related to the Winter Olympics. McAfee believes the attack came from a nation state that speaks Korean, although it has no definitive proof that this is a North Korean operation. The victim organizations include ice hockey teams, ski suppliers, ski resorts, tourist organizations in Pyeongchang, and departments organizing the Pyeongchang Olympi

Internet 289
article thumbnail

Weekly Update 74

Troy Hunt

I had plans this week. Monday was going to be full of coding work around Pwned Passwords V2 (and a few other HIBP things) then Texthelp went and got themselves pwned and there went my day writing about the ramifications of that. This is a genuinely important issue and the whole concept of the JavaScript supply chain needs much better thought. We've got the technology, it's just that most people don't know it exists!

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Did Russia Affect the 2016 Election? It’s Now Undeniable

WIRED Threat Level

In the wake of the Mueller indictment of a Russian troll farm, any attempt to claim that the 2016 election wasn’t affected by Russian meddling is laughable.

112
112
article thumbnail

Have We Become Apathetic About Breaches?

Thales Cloud Protection & Licensing

Another day, another breach. It’s sarcastic, it’s comical, but it’s also real. Barely a day goes by where we don’t hear of a data breach. Affecting big companies and small in virtually every vertical and hitting government institutions at the local, state and federal level, sensitive data is routinely exfiltrated, stolen and leveraged with shocking regularity.

article thumbnail

How to Avoid Pitfalls In Automation: Keep Humans In the Loop

Speaker: Erroll Amacker

Automation is transforming finance but without strong financial oversight it can introduce more risk than reward. From missed discrepancies to strained vendor relationships, accounts payable automation needs a human touch to deliver lasting value. This session is your playbook to get automation right. We’ll explore how to balance speed with control, boost decision-making through human-machine collaboration, and unlock ROI with fewer errors, stronger fraud prevention, and smoother operations.

article thumbnail

Can Consumers' Online Data Be Protected?

Schneier on Security

Everything online is hackable. This is true for Equifax's data and the federal Office of Personal Management's data, which was hacked in 2015. If information is on a computer connected to the Internet, it is vulnerable. But just because everything is hackable doesn't mean everything will be hacked. The difference between the two is complex, and filled with defensive technologies, security best practices, consumer awareness, the motivation and skill of the hacker and the desirability of the data.

Internet 179
article thumbnail

3 Tips to Keep Cybersecurity Front & Center

Dark Reading

In today's environment, a focus on cybersecurity isn't a luxury. It's a necessity, and making sure that focus is achieved starts with the company's culture.

LifeWorks

More Trending

article thumbnail

9 Top Secure Web Gateway Vendors

eSecurity Planet

A look at top vendors in the market for web security gateway solutions, a critical tool for defending against web threats.

article thumbnail

Jumping Air Gaps

Schneier on Security

Nice profile of Mordechai Guri, who researches a variety of clever ways to steal data over air-gapped computers. Guri and his fellow Ben-Gurion researchers have shown, for instance, that it's possible to trick a fully offline computer into leaking data to another nearby device via the noise its internal fan generates , by changing air temperatures in patterns that the receiving computer can detect with thermal sensors , or even by blinking out a stream of information from a computer hard dr

article thumbnail

Fileless Malware: Not Just a Threat, but a Super-Threat

Dark Reading

Exploits are getting more sophisticated by the day, and cybersecurity technology just isn't keeping up.

Malware 68
article thumbnail

Facebook's Onavo Protect VPN Offers Less Privacy Protection Than Other Apps

WIRED Threat Level

The "Protect" menu item in Facebook's mobile apps refers users to the company's Onavo Protect VPN, but the tool falls short of basic privacy standards.

VPN 111
article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

2018 is the Year for POPI in South Africa

Thales Cloud Protection & Licensing

As data breaches continue to plague organisations worldwide, South Africa is taking extra measures to protect its citizens by rolling out new legislation. The country’s Protection of Personal Information (POPI) Act imposes requirements on holders of personal data to guard against unauthorised access and, in the event of a breach, mandates that the organisation notify the Regulator and the impacted data subjects.

article thumbnail

Election Security

Schneier on Security

Good Washington Post op-ed on the need to use voter-verifiable paper ballots to secure elections, as well as risk-limiting audits.

Risk 163
article thumbnail

Apple Rushes Fix for Latest ‘Text Bomb’ Bug As Abuse Spreads

Threatpost

Apple said it is working on a fix for the latest text bomb bug that crashes a number of iOS and Mac apps that display specific Telugu language characters. .

Mobile 63
article thumbnail

Mueller Indictment Against Russia Details Efforts to Undermine US Democracy

WIRED Threat Level

Robert Mueller's office has come out with a 37-page indictment that details the extraordinary lengths Russian agents went to influence the 2016 presidential election.

110
110
article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

Why Bug Bounties Matter

eSecurity Planet

Paying security researchers to find vulnerabilities can be a winning formula. Find out more in the first part of this eSecurity Planet series.

63
article thumbnail

New National Academies Report on Crypto Policy

Schneier on Security

The National Academies has just published " Decrypting the Encryption Debate: A Framework for Decision Makers." It looks really good, although I have not read it yet. Not much news or analysis yet. Please post any links you find in the comments, and I will summarize them here.

article thumbnail

Rise of the 'Hivenet': Botnets That Think for Themselves

Dark Reading

These intelligent botnet clusters swarm compromised devices to identify and assault different attack vectors all at once.

61
article thumbnail

Mueller Indictment: Russian Trolls Stole Real US Identities to Fool Facebook

WIRED Threat Level

A new Justice Department indictment alleges Russia's disinformation operations created bank and social media accounts using the stolen identities of real US citizens.

Banking 110
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

A Guide to Secure Web Gateways

eSecurity Planet

A look at top vendors in the market for web security gateway solutions, a critical tool for defending against web threats.

article thumbnail

Word-based Malware Attack Doesn’t Use Macros

Threatpost

Malicious e-mail attachments used in this campaign don’t display any warnings when opened and silently install malware.

Malware 52
article thumbnail

Windows 10 Critical Vulnerability Reports Grew 64% in 2017

Dark Reading

The launch and growth of new operating systems is mirrored by an increase in reported vulnerabilities.

61
article thumbnail

Facebook Notification Spam Has Crossed the Line

WIRED Threat Level

From SMS notifications to an egregious number of emails, the social media company's desperation has gone too far.

Media 109
article thumbnail

Next-Level Fraud Prevention: Strategies for Today’s Threat Landscape

Speaker: Sierre Lindgren

Fraud is a battle that every organization must face – it’s no longer a question of “if” but “when.” Every organization is a potential target for fraud, and the finance department is often the bullseye. From cleverly disguised emails to fraudulent payment requests, the tactics of cybercriminals are advancing rapidly. Drawing insights from real-world cases and industry expertise, we’ll explore the vulnerabilities in your processes and how to fortify them effectively.

article thumbnail

API-based CASB Spinbackup Announces 2017 Results

Spinone

SAN FRANCISCO, CA – January 25, 2018 – Spinbackup, a leading cloud security and cloud-to-cloud backup solutions provider for G Suite, and an API-based CASB (Cloud Access Security Broker) announced today it’s significant growth milestones in 2017, as the company’s customer base exceeded 2,000 SMB’s, educational and enterprise organizations globally. 2017 was another year of continuous progress and achievement for Spinbackup.

Backups 40
article thumbnail

Romance Scams Drive Necurs Botnet Activity in Run Up to Valentine’s Day

Threatpost

Emails try to get recipients to share revealing photos of themselves so scammers can later extort them later.

Scams 47
article thumbnail

Siemens Leads Launch of Global Cybersecurity Initiative

Dark Reading

The new 'Charter of Trust' aims to make security a key element of the digital economy, critical infrastructure.

article thumbnail

'Olympic Destroyer' Malware Hit Pyeongchang Ahead of Opening Ceremony

WIRED Threat Level

Researchers at Cisco Talos detail a new piece of disruptive, highly infectious malware with a clear target: the Pyeongchang Olympics IT infrastructure.

Malware 105
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Cloud-to-Cloud Migration: How to Detect Security Issues

Spinone

The cloud computing boom has brought many benefits to businesses regarding increased productivity and easier accessibility to corporate online systems. Unfortunately, it has also introduced some new security concerns and an increase in the number of data breaches that occur each year. The main reason for this is that cloud services make it much easier to access and share data from outside the organization.

article thumbnail

Researchers Find New Twists In ‘Olympic Destroyer’ Malware

Threatpost

Researchers now believe attackers may have had prior access to networks and that malware was more sophisticated than originally believed.

Malware 47
article thumbnail

13 Russians Indicted for Massive Operation to Sway US Election

Dark Reading

Russian nationals reportedly used stolen American identities and infrastructure to influence the 2016 election outcome.

54
article thumbnail

Cryptojacking Found in Critical Infrastructure Systems Raises Alarms

WIRED Threat Level

Once confined to browsers, hijacking computers to mine cryptocurrency has branched out to dangerous places.

article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!