> TODAY'S SUMMARY (2 articles)
This week in cybersecurity, Cisco issued critical patches for a zero-day vulnerability in its email gateway that had been actively exploited. Additionally, the Revolut data breach came to light, revealing unauthorized access and the impersonation of a government agency as part of the attack. The incident underscores the ongoing threat of social engineering and phishing tactics. Furthermore, the latest Security Affairs newsletter highlighted various security trends and articles, emphasizing the importance of staying updated on emerging threats. Overall, organizations must prioritize patch management and employee training to mitigate risks from both technical vulnerabilities and human factors.
|
// AI-powered summary generated at 12:00
The consumerization of IT is one of the hottest trends of late, leaving many ITsec pros wondering how they can balance the demands of their users with the security of their enterprise networks. It appears that one successful model has been under our noses all along – lurking on college campuses.
IT security in an increasingly complex threat environment needs to be more about management than technology performance, according to Eric Domage, program manager for IDC in Europe.
ISACA has announced that its Information Security and Risk Management Conference – which takes place in Barcelona on November 14 to 16 – will feature cloud computing and PCI DSS guidance at its heart.
The fallout from the hack of the DigiNotar certificate authority in the Netherlands means that SSL certificates can no longer be trusted, says Mark Knight, director of product management with Thales e-Security.
Companies should fix known access vulnerabilities in order to prevent disgruntled former employees from wreaking havoc on their systems, advises Adam Bosnian with Cyber-Ark Software.
Belgian web certificate authority (CA) GlobalSign is back online after investigating claims by the hacker who breached the Dutch DigiNotar CA that its systems had also been breached.
Vacationland Vendors, a Wisconsin-based supplier of arcade equipment and vending machines, said credit and debits cards used in its card processing system over a two and a half year period may have been exposed.
The Russian embassy in London has complained that its website mysteriously crashed over the weekend, after being hit by a DDoS attack. The site downing reportedly coincided with Prime Minister David Cameron's visit to Moscow.
An associate professor in the computer science department of the University of California has developed a proof-of-concept app that uses the smartphone/tablet's on-device accelerometer/gyroscope technology to interpret - and record - users' keystrokes.
The number of botnets running on compromised devices increased in the first half of 2011, despite the recent takedown of a number of high-profile botnets, according to Damballa’s first half 2011 Advanced Threat Report.
Malware for smartphones and tablets is up 273% in the first half of 2011, compared with the same period in 2010, a study from G Data has shown.
Tomer Bitton, a reverse engineering specialist with Imperva, has successfully dissected the operation of the Morto worm, a malware executable that is notable for being the only worm seen to date that exploits Microsoft's remote desktop protocol (RDP).
The arrest of Pavel Vrublevsky, the co-founder of Russia's largest processor of online payments earlier this year, was the result of a bribe by his fellow co-founder, security researcher Brian Krebs has reported.
Over 70% of healthcare providers have suffered patient data breaches within the last 12 months, according to a survey by consulting firm Veriphyr.
An M86 Security researcher has revealed some of the practices of typosquatting - where darker elements of the internet register and populate domains/pages that are similar to high-profile major web portals, either infecting or ripping off users in the process.
Cybercrime costs the world $388 billion per year, according to a new report by Symantec’s Norton unit.
PhoneGuard has announced that its DriveSafe app is now available for free on the Apple iPhone. Amongst other features, the app - which is also available for the Android and BlackBerry platforms - uses GPS tracking to temporarily lock the handset's keyboard when the device moves faster than 10 mph.
The Information Commissioner's Office (ICO) has revealed that the University Hospital of South Manchester NHS Foundation Trust breached the Data Protection Act by losing sensitive personal information relating to the treatment of 87 patients.
As part of an ongoing series of reports into the TDSS botnet, security researcher Brian Krebs has revealed some interesting information on the Russian who “has close ties” to the botnet's operation.
The House Energy and Commerce Committee has identified improving cybersecurity of US critical infrastructure and online privacy as priorities for the fall.