[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Firms Waste $1.3 Million Each Year on False Positives
Damballa report claims 21,000 hours are wasted dealing with fallout from poor security controls
> KPMG: FTSE 350 Boards Lack Cybersecurity Know-How
New study claims communication breakdown is harming risk management efforts
> The Foundation of 2015: 2014 in Review
We need to do more to protect ourselves. 2014 overflowed with front-page proof: Apple, Target, JPMorgan Chase, etc, etc. The current, vulnerable status quo begs for radical change, an influx of talented people, and substantially better tools. As we look ahead to driving that change in 2015, we’re pr...
> Marriott Won't Block Guest Wi-Fi Devices After All
The hospitality giant said that it wanted to manage the connections in order to maintain security standards.
> Fake BBC News Site Baits Victims with Charlie Hebdo Misinformation
The attack took pains to appear to be state-sponsored.
> Close Encounters with Symbolic Execution (Part 2)
This is part two of a two-part blog post that shows how to use KLEE with mcsema to symbolically execute Linux binaries (see the first post!). This part will cover how to build KLEE, mcsema, and provide a detailed example of using them to symbolically execute an existing binary. The binary we’ll be s...
> Department of Homeland Security Drops the Ball on Access Control
DHS completely lacks a strategy when it comes to the security of the computers that monitor and control building operations.
> EU Security Agency Calls for Stronger Privacy Technology
UK PM Cameron faces Brussels showdown over plans to ban encrypted comms
> Close Encounters with Symbolic Execution
At THREADS 2014, I demonstrated a new capability of mcsema that enables the use of KLEE, a symbolic execution framework, on software available only in binary form. In the talk, I described how to use mcsema and KLEE to learn an unknown protocol defined in a binary that has never been seen before. In...
> Microsoft Kicks Off 2015 with an All-Windows Patch Tuesday
Easy for admins but a controversial update round for Redmond
> Skeleton Key Malware Unlocks Active Directory Authentication
Dell SecureWorks spots new threat, but it lacks persistence
> American, United Airlines Hit By Mileage-Loving Hackers
Thieves with stolen usernames and passwords have broken into customer accounts, booking trips with frequent flier miles.
> Cisco: Complacency and Ignorance Make Staff Major Security Threat
Twice as many take security more seriously at home than in the office
> TechUK in Bid to Boost Security With Best Practice Doc
Top 10 vulnerabilities in web apps and infrastructure revealed
> Great Firewall Upgrade Redirects Users to Adult Sites
Chinese censors tweak their tactics to counter anti-DNS poisoning tools
> CSA: Cloud Security Finally Piques Exec Interest
Cloud security oversight has shifted from the IT room to the boardroom, with 61% of companies indicating that executives are now involved in such decisions.
> Zappos Slapped with Data Breach Settlement
In the wake of a 2012 breach that affected 24 million, the online retailer is facing fines and oversight.
> FireEye: Over a Quarter of Attacks Bypassing Filters are APTs
Organizations in multiple sectors compromised in new tests
> Malvertising Campaign Affects 1.8 Billion
Huffington Post, Yahoo News, AOL, TMZ and many others are affected by the infection, which makes use of the legitimate AOL ad network.
> FBI: Sony Hacker IP Addresses Used ‘Exclusively’ By North Korea
Attackers got sloppy and revealed their true location, Comey claims