> TODAY'S SUMMARY (2 articles)
This week in cybersecurity, Cisco issued critical patches for a zero-day vulnerability in its email gateway that had been actively exploited. Additionally, the Revolut data breach came to light, revealing unauthorized access and the impersonation of a government agency as part of the attack. The incident underscores the ongoing threat of social engineering and phishing tactics. Furthermore, the latest Security Affairs newsletter highlighted various security trends and articles, emphasizing the importance of staying updated on emerging threats. Overall, organizations must prioritize patch management and employee training to mitigate risks from both technical vulnerabilities and human factors.
|
// AI-powered summary generated at 12:00
Cybersecurity startups often fail to attract venture capital (VC) because investors want to invest in companies that will makes millions quickly, but not all information security startup are interested in that model, observed Chris Wysopal, founder and chief technology officer with application secur...
The prevalence and intensity of SQL injection attacks are increasing, according to Imperva's Hacker Intelligence Initiative (HII) report.
Two security researchers claim to have found a way of breaking the SSL/TLS encryption that is widely used to guarantee the reliability and privacy of data exchanged between web browsers and servers.
CA Technologies has announced the creation of a European research centre in co-operation with Universitat Politècnica de Catalunya BarcelonaTech (UPC).
Research just released from Check Point claims to show that 42% of UK firms experienced 25 or more social engineering attacks in the last two years, including targeted attacks such as spear phishing.
On the first day of the (ISC)² Congress 2011, (ISC)² announced that it has formed the (ISC)² Foundation - a new charitable organisation dedicated to delivering education and awareness programmes to communities around the globe to make the cyber world a safer place for everyone.
On the opening day of the first (ISC)² Congress, collocated with ASIS 2011 in Orlando, Florida, the information security professional body announced the formation of the (ISC)² chapter programme.
Barracuda Networks has launched its No Limits road show in Europe, allowing clients to meet the security firm's CEO Dean Drako, chief research officer Dr. Paul Judge and the rest of the senior management. The tour will also, says the company, provide end users with best practice information and advi...
A Symantec security expert has spotted a variant of the Morto worm that seems to parse requests through a Chinese online gaming server. The good news – from a UK perspective – is that the game it parses commands through are aimed at the Chinese community in the Far East.
Businesses should consider self-encrypting drives (SEDs) for new installations that hold significant volumes of sensitive data, says Gartner.
A leading IT security researcher says he has observed a rising number of Russian forum sites using Captcha technology to help keep foreigners (i.e., non-Russian security investigators) out of their systems.
Research just published claims to show that companies have a lot to learn when it comes to disposing of old computers and allied kit, both from an ecological and IT security point of view.
A full 76% of British workers whose companies have a policy on software piracy would not report misuse of software, according to a survey by the UK anti-piracy group Federation Against Software Theft (FAST).
Research just released by Symantec claims to show that email is no longer the primary source of information for legal e-discovery requests, meaning that firms must now be prepared to produce information from more sources than ever before.
Fortinet's report of earlier in the month – showing that the infamous Zeus malware as having shot to the number two spot in the malware charts – comes as no surprise, says in-browser security specialist Trusteer.
It looks like the DroidDream malware – which infected hundreds of thousands of Android users earlier in the year – is back with a sting in the tail, as a Trend Micro threat analyst is reporting that a major recode has been spotted.
The FBI is currently investigating over 400 reported cases of corporate banking account takeovers in which cybercriminals have initiated unauthorized automated clearing house (ACH) and wire transfers from US-based organizations, an FBI official told a House panel this week.
Another case of the unauthorized activity of a trader at an investment bank has highlighted the need for real-time monitoring and control in the investment banking sector.
Hackers are flipping filenames to create apparently 'safe' file extensions that in fact contain malware, according to Czech security firm Avast Software.
Roel Schouwenberg, a senior security researcher with Kaspersky Lab, is advising internet users to exercise extreme caution when dealing with online certificates in the wake of the DigiNotar certificate authority (CA) systems hack.