Around 1000 accounts affected, says UK train operator
ISP claims every firm experienced 600 attempts to infiltrate their network
Welcome to the third post in our series about osquery. So far, we’ve described how five enterprise security teams use osquery and reviewed the issues they’ve encountered. For our third post, we focus on the future of osquery. We asked users, “What do you wish osquery could do?” The answers we receiv...
Firm will face civil penalties if it fails to disclose another breach
In 50% of cases over the past 12 months, organizations had insufficient endpoint or network visibility to respond successfully.
You’ve just approved a security review of your codebase. Do you: Send a copy of the repository and wait for the report, or Take the extra effort to set the project up for success? By the end of the review, the difference between these answers will lead to profoundly disparate results. In the former...
Just 15% of respondents believe that Google's decision to distrust Symantec certificates is a one-time event.
This marks the first time the UK has systematically and persistently attacked an adversary’s online efforts as part of a wider military campaign.
Plenty of static analyzers can perform vulnerability discovery on source code, but what if you only have the binary? How can we model a vulnerability and then check a binary to see if it is vulnerable? The short answer: use Binary Ninja’s MLIL and SSA form. Together, they make it easy to build and s...
CA Veracode claims 71 vulnerabilities are introduced per app
Gemalto study claims accidents led to 76% of compromised data
Two years ago, when we began taking on blockchain security engagements, there were no tools engineered for the work. No static analyzers, fuzzers, or reverse engineering tools for Ethereum. So, we invested significant time and expertise to create what we needed, adapt what we already had, and refine...
More detailed approach will also boost collaboration, says GCHQ body
70% of CISOs say their team is under-resourced and 72% admit to agent and alert fatigue
This is the second half of our blog post on the Meltdown an Spectre vulnerabilities, describing Spectre Variant 1 (V1) and Spectre Variant 2 (V2). If you have not done so already, please review the first blog post for an accessible review of computer architecture fundamentals. This blog post will st...
Redmond fixes 66 bugs in April
Social network CEO faces grilling by senators
Millions to be spent on cybercrime policing
Attacks are enabled by adversaries using unsophisticated means
Zscaler has blocked more than 2.5 billion crypto-mining attempts in the last six months.