Damballa report claims 21,000 hours are wasted dealing with fallout from poor security controls
New study claims communication breakdown is harming risk management efforts
We need to do more to protect ourselves. 2014 overflowed with front-page proof: Apple, Target, JPMorgan Chase, etc, etc. The current, vulnerable status quo begs for radical change, an influx of talented people, and substantially better tools. As we look ahead to driving that change in 2015, we’re pr...
The hospitality giant said that it wanted to manage the connections in order to maintain security standards.
The attack took pains to appear to be state-sponsored.
This is part two of a two-part blog post that shows how to use KLEE with mcsema to symbolically execute Linux binaries (see the first post!). This part will cover how to build KLEE, mcsema, and provide a detailed example of using them to symbolically execute an existing binary. The binary we’ll be s...
DHS completely lacks a strategy when it comes to the security of the computers that monitor and control building operations.
UK PM Cameron faces Brussels showdown over plans to ban encrypted comms
At THREADS 2014, I demonstrated a new capability of mcsema that enables the use of KLEE, a symbolic execution framework, on software available only in binary form. In the talk, I described how to use mcsema and KLEE to learn an unknown protocol defined in a binary that has never been seen before. In...
Easy for admins but a controversial update round for Redmond
Dell SecureWorks spots new threat, but it lacks persistence
Thieves with stolen usernames and passwords have broken into customer accounts, booking trips with frequent flier miles.
Twice as many take security more seriously at home than in the office
Top 10 vulnerabilities in web apps and infrastructure revealed
Chinese censors tweak their tactics to counter anti-DNS poisoning tools
Cloud security oversight has shifted from the IT room to the boardroom, with 61% of companies indicating that executives are now involved in such decisions.
In the wake of a 2012 breach that affected 24 million, the online retailer is facing fines and oversight.
Organizations in multiple sectors compromised in new tests
Huffington Post, Yahoo News, AOL, TMZ and many others are affected by the infection, which makes use of the legitimate AOL ad network.
Attackers got sloppy and revealed their true location, Comey claims