Cybersecurity experts should look to be better translators of issues to the board
Welcome to the third post in our series about osquery. So far, we’ve described how five enterprise security teams use osquery and reviewed the issues they’ve encountered. For our third post, we focus on the future of osquery. We asked users, “What do you wish osquery could do?” The answers we receiv...
GCHQ body warns that online attacks continue to rise
Verizon report highlights risk of human error and misuse
You’ve just approved a security review of your codebase. Do you: Send a copy of the repository and wait for the report, or Take the extra effort to set the project up for success? By the end of the review, the difference between these answers will lead to profoundly disparate results. In the former...
The injectors modify HTTP headers on network requests with malicious code; the code then tricks captive portals into connecting to the internet.
More than a quarter (27%) of recipients clicked the link in mock phishing mails.
Plenty of static analyzers can perform vulnerability discovery on source code, but what if you only have the binary? How can we model a vulnerability and then check a binary to see if it is vulnerable? The short answer: use Binary Ninja’s MLIL and SSA form. Together, they make it easy to build and s...
An elaborate fraud is bent on draining the bank accounts of large corporations.
Firms need to up their game ahead of deadline next month
Two years ago, when we began taking on blockchain security engagements, there were no tools engineered for the work. No static analyzers, fuzzers, or reverse engineering tools for Ethereum. So, we invested significant time and expertise to create what we needed, adapt what we already had, and refine...
Malwarebytes sees nefarious mining activity continue to hit users and businesses
Over 160,000 systems remain vulnerable, says Talos
This is the second half of our blog post on the Meltdown an Spectre vulnerabilities, describing Spectre Variant 1 (V1) and Spectre Variant 2 (V2). If you have not done so already, please review the first blog post for an accessible review of computer architecture fundamentals. This blog post will st...
It mines unsuspecting victim machines for Monero and other virtual currencies, but its most unusual characteristic is how cheap it is.
According to PureSec's audit, most vulnerabilities and weaknesses were caused by human error.
The culprit is a cybersecurity breach at third-party software provider, [24]7.ai, which provides online automated chat.
Recorded Future warns of likely IoTroop activity in January
Trend Micro warns of growing attack surface and supply chain risk
Cyber-criminals focused on ransomware in 2017, says IBM