Sat.Feb 10, 2018 - Fri.Feb 16, 2018

article thumbnail

Internet Security Threats at the Olympics

Schneier on Security

There are a lot : The cybersecurity company McAfee recently uncovered a cyber operation, dubbed Operation GoldDragon, attacking South Korean organizations related to the Winter Olympics. McAfee believes the attack came from a nation state that speaks Korean, although it has no definitive proof that this is a North Korean operation. The victim organizations include ice hockey teams, ski suppliers, ski resorts, tourist organizations in Pyeongchang, and departments organizing the Pyeongchang Olympi

Internet 231
article thumbnail

Weekly Update 74

Troy Hunt

I had plans this week. Monday was going to be full of coding work around Pwned Passwords V2 (and a few other HIBP things) then Texthelp went and got themselves pwned and there went my day writing about the ramifications of that. This is a genuinely important issue and the whole concept of the JavaScript supply chain needs much better thought. We've got the technology, it's just that most people don't know it exists!

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Did Russia Affect the 2016 Election? It’s Now Undeniable

WIRED Threat Level

In the wake of the Mueller indictment of a Russian troll farm, any attempt to claim that the 2016 election wasn’t affected by Russian meddling is laughable.

112
112
article thumbnail

Have We Become Apathetic About Breaches?

Thales Cloud Protection & Licensing

Another day, another breach. It’s sarcastic, it’s comical, but it’s also real. Barely a day goes by where we don’t hear of a data breach. Affecting big companies and small in virtually every vertical and hitting government institutions at the local, state and federal level, sensitive data is routinely exfiltrated, stolen and leveraged with shocking regularity.

article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

Can Consumers' Online Data Be Protected?

Schneier on Security

Everything online is hackable. This is true for Equifax's data and the federal Office of Personal Management's data, which was hacked in 2015. If information is on a computer connected to the Internet, it is vulnerable. But just because everything is hackable doesn't mean everything will be hacked. The difference between the two is complex, and filled with defensive technologies, security best practices, consumer awareness, the motivation and skill of the hacker and the desirability of the data.

Internet 134
article thumbnail

3 Tips to Keep Cybersecurity Front & Center

Dark Reading

In today's environment, a focus on cybersecurity isn't a luxury. It's a necessity, and making sure that focus is achieved starts with the company's culture.

More Trending

article thumbnail

2018 is the Year for POPI in South Africa

Thales Cloud Protection & Licensing

As data breaches continue to plague organisations worldwide, South Africa is taking extra measures to protect its citizens by rolling out new legislation. The country’s Protection of Personal Information (POPI) Act imposes requirements on holders of personal data to guard against unauthorised access and, in the event of a breach, mandates that the organisation notify the Regulator and the impacted data subjects.

article thumbnail

Jumping Air Gaps

Schneier on Security

Nice profile of Mordechai Guri, who researches a variety of clever ways to steal data over air-gapped computers. Guri and his fellow Ben-Gurion researchers have shown, for instance, that it's possible to trick a fully offline computer into leaking data to another nearby device via the noise its internal fan generates , by changing air temperatures in patterns that the receiving computer can detect with thermal sensors , or even by blinking out a stream of information from a computer hard dr

article thumbnail

Apple Rushes Fix for Latest ‘Text Bomb’ Bug As Abuse Spreads

Threatpost

Apple said it is working on a fix for the latest text bomb bug that crashes a number of iOS and Mac apps that display specific Telugu language characters. .

Mobile 63
article thumbnail

Facebook's Onavo Protect VPN Offers Less Privacy Protection Than Other Apps

WIRED Threat Level

The "Protect" menu item in Facebook's mobile apps refers users to the company's Onavo Protect VPN, but the tool falls short of basic privacy standards.

VPN 111
article thumbnail

IDC Analyst Report: The Open Source Blind Spot Putting Businesses at Risk

In a recent study, IDC found that 64% of organizations said they were already using open source in software development with a further 25% planning to in the next year. Most organizations are unaware of just how much open-source code is used and underestimate their dependency on it. As enterprises grow the use of open-source software, they face a new challenge: understanding the scope of open-source software that's being used throughout the organization and the corresponding exposure.

article thumbnail

Why Bug Bounties Matter

eSecurity Planet

Paying security researchers to find vulnerabilities can be a winning formula. Find out more in the first part of this eSecurity Planet series.

59
article thumbnail

New National Academies Report on Crypto Policy

Schneier on Security

The National Academies has just published " Decrypting the Encryption Debate: A Framework for Decision Makers." It looks really good, although I have not read it yet. Not much news or analysis yet. Please post any links you find in the comments, and I will summarize them here.

article thumbnail

Fileless Malware: Not Just a Threat, but a Super-Threat

Dark Reading

Exploits are getting more sophisticated by the day, and cybersecurity technology just isn't keeping up.

Malware 68
article thumbnail

Mueller Indictment: Russian Trolls Stole Real US Identities to Fool Facebook

WIRED Threat Level

A new Justice Department indictment alleges Russia's disinformation operations created bank and social media accounts using the stolen identities of real US citizens.

Banking 105
article thumbnail

Beware of Pixels & Trackers on U.S. Healthcare Websites

The healthcare industry has massively adopted web tracking tools, including pixels and trackers. Tracking tools on user-authenticated and unauthenticated web pages can access personal health information (PHI) such as IP addresses, medical record numbers, home and email addresses, appointment dates, or other info provided by users on pages and thus can violate HIPAA Rules that govern the Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates.

article thumbnail

9 Top Secure Web Gateway Vendors

eSecurity Planet

A look at top vendors in the market for web security gateway solutions, a critical tool for defending against web threats.

article thumbnail

Election Security

Schneier on Security

Good Washington Post op-ed on the need to use voter-verifiable paper ballots to secure elections, as well as risk-limiting audits.

Risk 125
article thumbnail

Rise of the 'Hivenet': Botnets That Think for Themselves

Dark Reading

These intelligent botnet clusters swarm compromised devices to identify and assault different attack vectors all at once.

61
article thumbnail

Pro-Gun Russian Bots Flood Twitter After Parkland Shooting

WIRED Threat Level

In the wake of Wednesday's Parkland, Florida school shooting Russian bots have taken to Twitter to stoke the gun control debate.

112
112
article thumbnail

Software Composition Analysis: The New Armor for Your Cybersecurity

Speaker: Blackberry, OSS Consultants, & Revenera

Software is complex, which makes threats to the software supply chain more real every day. 64% of organizations have been impacted by a software supply chain attack and 60% of data breaches are due to unpatched software vulnerabilities. In the U.S. alone, cyber losses totaled $10.3 billion in 2022. All of these stats beg the question, “Do you know what’s in your software?

article thumbnail

Word-based Malware Attack Doesn’t Use Macros

Threatpost

Malicious e-mail attachments used in this campaign don’t display any warnings when opened and silently install malware.

Malware 52
article thumbnail

Cloud-to-Cloud Migration: How to Detect Security Issues

Spinone

The cloud computing boom has brought many benefits to businesses regarding increased productivity and easier accessibility to corporate online systems. Unfortunately, it has also introduced some new security concerns and an increase in the number of data breaches that occur each year. The main reason for this is that cloud services make it much easier to access and share data from outside the organization.

article thumbnail

Can Android for Work Redefine Enterprise Mobile Security?

Dark Reading

Google's new mobility management framework makes great strides in addressing security and device management concerns while offering diverse deployment options. Here are the pros and cons.

Mobile 48
article thumbnail

'Olympic Destroyer' Malware Hit Pyeongchang Ahead of Opening Ceremony

WIRED Threat Level

Researchers at Cisco Talos detail a new piece of disruptive, highly infectious malware with a clear target: the Pyeongchang Olympics IT infrastructure.

Malware 94
article thumbnail

Cybersecurity Predictions for 2024

Within the past few years, ransomware attacks have turned to critical infrastructure, healthcare, and government entities. Attackers have taken advantage of the rapid shift to remote work and new technologies. Add to that hacktivism due to global conflicts and U.S. elections, and an increased focus on AI, and you have the perfect recipe for a knotty and turbulent 2024.

article thumbnail

Researchers Find New Twists In ‘Olympic Destroyer’ Malware

Threatpost

Researchers now believe attackers may have had prior access to networks and that malware was more sophisticated than originally believed.

Malware 47
article thumbnail

A Guide to Secure Web Gateways

eSecurity Planet

A look at top vendors in the market for web security gateway solutions, a critical tool for defending against web threats.

article thumbnail

Tracking Bitcoin Wallets as IOCs for Ransomware

Dark Reading

By understanding how cybercriminals use bitcoin, threat analysts can connect the dots between cyber extortion, wallet addresses, shared infrastructure, TTPs, and attribution.

article thumbnail

Facebook Notification Spam Has Crossed the Line

WIRED Threat Level

From SMS notifications to an egregious number of emails, the social media company's desperation has gone too far.

Media 101
article thumbnail

From Complexity to Clarity: Strategies for Effective Compliance and Security Measures

Speaker: Erika R. Bales, Esq.

When we talk about “compliance and security," most companies want to ensure that steps are being taken to protect what they value most – people, data, real or personal property, intellectual property, digital assets, or any other number of other things - and it’s more important than ever that safeguards are in place. Let’s step back and focus on the idea that no matter how complicated the compliance and security regime, it should be able to be distilled down to a checklist.

article thumbnail

U.K. and U.S. Government Websites Among Thousands Infected by Cryptocurrency Miner

Threatpost

The attack could have been averted through a technique called subresource integrity, according to researcher Scott Helme.

article thumbnail

Friday Squid Blogging: Squid Pin

Schneier on Security

There's a squid pin on Kickstarter. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered. Read my blog posting guidelines here.

107
107
article thumbnail

Lazarus Group Attacks Banks, Bitcoin Users in New Campaign

Dark Reading

A new Lazarus Group cyberattack campaign combines spear-phishing techniques with a cryptocurrency scanner designed to scan for Bitcoin wallets.

Banking 50
article thumbnail

Snapchat's Snap Map Will Now Be Available On the Web

WIRED Threat Level

By bringing the Snap Map out of the app and onto the web, Snap hopes to bring Snapchat to the masses like never before.

88
article thumbnail

Successful Change Management with Enterprise Risk Management

Speaker: William Hord, Vice President of ERM Services

A well-defined change management process is critical to minimizing the impact that change has on your organization. Leveraging the data that your ERM program already contains is an effective way to help create and manage the overall change management process within your organization. Your ERM program generally assesses and maintains detailed information related to strategy, operations, and the remediation plans needed to mitigate the impact on the organization.