Articles about Security

Security testing: Essential or simply supplemental?

A 2019 study on the effectiveness of enterprise security strategies found that 53 percent of enterprises are clueless if their security tools are working. This means that they do not undertake security testing. If they have anything that has the guise of security validation, it is likely inconclusive or conducted in an unsystematic manner.

However, a more recent study found that around 70 percent of organizations perform penetration tests as a way of preventing cyber breaches. Many already acknowledge the importance of testing their security controls. This finding coincides with a report that says that the global security testing market is huge and rapidly accelerating.

Continue reading

3.8 billion combined Clubhouse and Facebook records for sale on the dark web

hack money

Data combined from the July 24 Clubhouse breach and Facebook user profiles has been used to compile a database of 3.8 billion entries and it could be yours for $100,000 -- though the seller is willing to split it up if you're strapped for cash.

The CyberNews research team uncovered a hacker forum posting from September 4 offering the data for sale. The poster claims the records include names, phone numbers, Clubhouse ranks, and Facebook profile links.

Continue reading

How banks are strengthening their cybersecurity posture [Q&A]

online banking

Cyberattacks and data breaches affect all kinds of organizations, but banks and financial services firms are at particular risk.

The shift to using mobile devices to carry out financial transactions has changed the threat landscape in recent years too. We spoke to Will LaSala, director of security solutions and security evangelist at OneSpan to find out more about what banks can do to bolster their security.

Continue reading

APT group uses Exchange vulnerability to spy on hotels, businesses and governments

Snooping

Cybersecurity company ESET has released new research into FamousSparrow, a cyberespionage group attacking hotels worldwide, as well as governments, international organizations, engineering companies and law firms.

The Advanced Persistent Threat (APT) group FamousSparrow has been exploiting the Microsoft Exchange vulnerability known as ProxyLogon, which allows hackers to take control of Exchange servers.

Continue reading

Divide between developer and security teams widens

New research by Forrester for VMWare reveals a growing gulf between security and development teams.

Over half of developers surveyed (52.4 percent) say they feel that security policies stifle their innovation, and only 22 percent strongly agree that they understand which security policies they are expected to comply with.

Continue reading

Ransomware dominates attacks and new malware targets Unix systems

ransomware laptop

Ransomware now accounts for 69 percent of all attacks involving malware, according to the latest threatscape report from Positive Technologies.

The researchers have also identified a growing pattern of new malware specifically designed to penetrate Unix systems.

Continue reading

SIEM, SOAR and their role in improving cloud security [Q&A]

Cloud data security

It's increasingly common for enterprise systems to be in the cloud rather than in-house, but that throws up a whole range of new challenges when it comes to securing them.

We spoke to Dario Forte, vice president and general manager, security orchestration, at cloud management specialist Sumo Logic to find out more about what's involved in cloud security and how automation can help.

Continue reading

Home security service Home8 is currently down, blames AWS [Update: Back up now]

These days a lot of us have home security systems to one degree or another. You may simply control your locks and perhaps a light; or you may be a little more invested in the technology, adding motion sensors, cameras, leak sensors and other little toys. 

The thing you need most with all of this is an operational system keeping an eye on everything when you can’t. You rely on this for protection for yourself, your family and your property.  

Continue reading

Cybersecurity 'ripple events' lead to 26x greater losses

A new report by the Cyentia Institute, sponsored by risk management company RiskRecon has analyzed over 800 cyber incidents and their impact on multiple downstream organizations.

It finds that multi-party loss events that impact thousands of downstream organizations, otherwise known as 'ripple events', can result in 26x larger financial losses than traditional single-party incidents.

Continue reading

Education sector sees more security incidents and longer fix times

A new report from NTT Application Security shows that last year the education sector saw 408 publicly-disclosed school incidents, including student and staff data breaches, ransomware and other malware outbreaks, phishing attacks and other social engineering scams, plus a wide variety of other incidents.

This is 18 percent more incidents than were publicly-disclosed during the previous calendar year and equates to more than two incidents a day. The sector also has lower remediation rates and a higher than average time to fix.

Continue reading

First half DDoS attacks up 11 percent over last year

DDoS attack

In the first half of 2021, cybercriminals launched approximately 5.4 million DDoS attacks, representing an 11 percent increase over the same period in 2020.

The latest threat intelligence report from NETSCOUT shows that in the first half of the year cybercriminals weaponized and exploited seven new reflection/amplification DDoS attack vectors putting organizations at greater risk.

Continue reading

September is for raising awareness of insider threats

web threats

If you haven't been paying attention you may not have noticed that September is Insider Threat Awareness month, with the aim of educating individuals and organizations on the dangers of insider threats and the forms they can take.

Almost half of organizations say they find it difficult to prevent insider attacks according to a recent study, which means it's more important than ever to understand the risk. We've gathered comments from a number of industry experts on the nature of the threat and how to tackle it.

Continue reading

Why quantum computing is a security threat and how to defend against it [Q&A]

quantum computing

Quantum computing offers incredible computing power and is set to transform many areas such as research. However, it also represents a threat to current security systems as cracking passwords and encryption keys becomes much easier.

So quantum is a security threat, but is there a solution to making systems safer? We spoke to David Williams, CEO of symmetric encryption specialist Arqit, to find out.

Continue reading

AMD issues warning about CPU vulnerability and releases a chipset patch

Security researchers have discovered a vulnerability in the AMD Platform Security Processor (PSP) chipset driver for multiple CPU architectures. Tracked as CVE-2021-26333, the security flaw is comparable with the likes of Spectre and Meltdown.

The vulnerability, found by ZeroPeril Ltd, can be exploited to grab data such as password from memory, and it affects a wide range of AMD processors. AMD has issued a patch which users are advised to install as soon as possible.

Continue reading

Office workers understand cyber risk but still don't change their behavior

risk jigsaw piece

Nearly a quarter (24 percent) of office workers have experienced a data breach, yet 12 percent say nothing will make them take cyber security more seriously, and a third won't take extra precautions.

A survey of over 2,000 UK office staff from BlueFort Security finds 34 percent believe cybersecurity awareness is the biggest issue when it comes to hybrid working, and 33 percent cite personal use of company devices as another significant risk.

Continue reading

© 1998-2021 BetaNews, Inc. All Rights Reserved. Privacy Policy - Cookie Policy.