Women in security: A guiding force

Women in security: A guiding force

Women in security: A guiding force | 2021-07-14 | Security Magazine This website requires certain cookies to work and uses other cookies to help you have the best experience. By visiting this website, certain cookies have already been set, which you may delete and block. By closing this message or continuing to use our site, you agree to the use of cookies. Visit our updated privacy and cookie policy to learn more. This Website…

Read More

Cloud security should never be a developer issue

Cloud security should never be a developer issue

Cloud security should never be a developer issue | 2021-07-14 | Security Magazine This website requires certain cookies to work and uses other cookies to help you have the best experience. By visiting this website, certain cookies have already been set, which you may delete and block. By closing this message or continuing to use our site, you agree to the use of cookies. Visit our updated privacy and cookie policy to learn more. …

Read More

Microsoft’s July 2021 Patch Tuesday Includes 116 CVEs (CVE-2021-31979, CVE-2021-33771)

Microsoft’s July 2021 Patch Tuesday Includes 116 CVEs (CVE-2021-31979, CVE-2021-33771)

CVE-2021-34464 and CVE-2021-34522 | Microsoft Defender Remote Code Execution Vulnerability CVE-2021-34464 and CVE-2021-34522 are RCE vulnerabilities in the Microsoft Malware Protection Engine. Both of these vulnerabilities received CVSSv3 scores of 7.8 and are rated as “Exploitation Less Likely,” but we chose to highlight them due to in-the-wild exploitation of a similar flaw, CVE-2021-1647, in January. While CVE-2021-1647 was a zero-day, the ubiquity of Microsoft Defender makes this a noteworthy vulnerability. Fortunately, Microsoft Defender…

Read More

PCI SSC Shares Resources for Navigating Changing Payment Environments

PCI SSC Shares Resources for Navigating Changing Payment Environments

  Greetings to our PCI SSC stakeholder community! With 2021 half done, I wanted to take this opportunity to share with you what the PCI Security Standards Council (PCI SSC) is doing to assist the industry as we continue to navigate the changes brought on by the pandemic. The current phase is a hybrid of old and new, and defined by rapid changes including re-openings and continued, or returning, lockdowns.

Read More

Kaseya releases patches for flaws exploited in massive ransomware supply-chain attack

Kaseya releases patches for flaws exploited in massive ransomware supply-chain attack

Kaseya has released a security update to address the VSA zero-day vulnerabilities exploited by REvil gang in the massive ransomware supply chain attack. Software vendor Kaseya has released a security update to fix the zero-day vulnerabilities in its VSA software that were exploited by the REvil ransomware gang in the massive ransomware supply chain attack. The company announced last week that fewer than 60 of its customers and less than 1,500 businesses have been impacted…

Read More

Bad actor offers up for sale data from 600 million LinkedIn members scraped from the site

Bad actor offers up for sale data from 600 million LinkedIn members scraped from the site

Cyber News reports that this is the third time in four months that member information has shown up on a hacker forum. Image: iStock/iBrave A data set including information from 600 million LinkedIn users showed up for sale on a hacker forum this week. That’s the third time in four months that scraped data from the networking site has been offered up for sale, according to a report from Cyber News.  The data is all…

Read More

Docker for Node.js Developers: 5 Things You Need to Know Not to Fail Your Security – Docker Blog

Docker for Node.js Developers: 5 Things You Need to Know Not to Fail Your Security – Docker Blog

Guest post by Liran Tal, Snyk Director of Developer Advocacy  Docker is totalling up to more than 318 billion downloads of container images. With millions of applications available on Docker Hub, container-based applications are popular and make an easy way to consume and publish applications. That being said, the naive way of building your own Docker Node.js web applications may come with many security risks. So, how do we make security an essential part of…

Read More

Iranian Hackers Pose as UK Scholars to Target Experts   

Iranian Hackers Pose as UK Scholars to Target Experts   

WASHINGTON – A notorious group of hackers tied to Iran’s Islamic Revolutionary Guard Corps has waged a covert campaign targeting university professors and other experts based in the U.K. and the U.S. in an attempt to steal their sensitive information, according to research by the cybersecurity firm Proofpoint.    The group, known as TA453 and Charming Kitten, has been masquerading as British scholars at the University of London’s School of Oriental and African Studies (SOAS)…

Read More

Professor Says Being Impersonated by Iranian Hackers Was Stressful But Good For Networking

Professor Says Being Impersonated by Iranian Hackers Was Stressful But Good For Networking

Image: Sobhan Farajvan/Pacific Press/LightRocket via Getty Images Hacking. Disinformation. Surveillance. CYBER is Motherboard’s podcast and reporting on the dark underbelly of the internet. Iranian hackers with links to the country’s Islamic Revolutionary Guard Corps impersonated two academics in an attempt to hack journalists, think tank analysts, and other academics, according to a new report. In early 2021, the hackers—dubbed inside the industry as Charming Kitten or TA453—sent emails to targets pretending to be Dr. Hanns Bjoern…

Read More

Cyber Threat Intelligence (CTI) and MITRE ATT&CK Provides CISOs with Strategic Advantage over Cyber Threats

Cyber Threat Intelligence (CTI) and MITRE ATT&CK Provides CISOs with Strategic Advantage over Cyber Threats

Many security executives have fundamental familiarity with the MITRE ATT&CK framework, although most perceive it within a narrow set of use cases specific to deeply-technical cyber threat intelligence (CTI) analysts. The truth though, is that when integrated into overall security operations, it can produce profound security and risk benefits. What is MITRE ATT&CK? MITRE ATT&CK serves as a global knowledge base for understanding threats across their entire lifecycle. The framework’s differentiator is its focus on…

Read More
1 2,187 2,188 2,189 2,190 2,191 2,588