Remote working boosts move to cloud-based security

Secure cloud

New research from security management platform Exabeam reveals that 88 percent of UK security practitioners have accelerated their move to the cloud, driven by the need to support a remote workforce.

Significantly, almost half of respondents (44 percent) are now using cloud-based security products to protect their corporate financial information. This is a sharp increase compared to Exabeam's earlier study where just 12 percent were protecting corporate financial information in this way.

Continue reading

DDoS attacks jump over 540 percent during lockdown

DDoS attack start

In the first quarter of this year, DDoS attacks rose more than 278 percent compared to Q1 2019 and more than 542 percent compared to the previous quarter.

This is among the findings of the Nexusguard Q1 2020 Threat Report. Researchers attribute the sharp rise in incidents to malicious efforts during the COVID-19 pandemic, causing DDoS attacks to interrupt service for large companies and individuals alike.

Continue reading

EaseUS Data Recovery Wizard for Mac is the first and only Mac data recovery app compatible with T2 chips

EaseUS Data Recovery Wizard for Mac

The T2 chip included in more recent Macs helps to boost security in a number of ways. As well as preventing unsigned software from booting, the chip also secures the entire boot process and handles drive encryption.

But T2 chip can also cause headaches for owners of such machines. The security built into the chip forces users to perform some system repairs -- such as the Touch ID sensor -- with Apple rather than a third party. It can also cause huge problems when it comes to data recovery; that is, unless you're using EaseUS Data Recovery Wizard for Mac.

Continue reading

TLS certificates are a top security concern for businesses

security flaw

A new study by machine identity protection specialists Venafi of the opinions of 550 chief information officers (CIOs) from the US, UK, France, Germany and Australia finds that 75 percent name TLS certificates as their top concern.

TLS certificates act as machine identities, safeguarding the flow of sensitive data to trusted machines and, thanks to the acceleration of digital transformation, the number of machine identities is rising.

Continue reading

96 percent of developers believe security harms productivity

Developer at work

In a new survey of over 165 developers, AppSec and DevOps professionals, application security automation company ShiftLeft finds that 96 percent of developers believe the disconnect between developer and security workflows inhibits developer productivity.

When asked to prioritize, application security professionals rank creating developer-friendly security workflows as their top priority, even higher than protecting applications in production environments.

Continue reading

Calendar invites used to hide phishing links

Phishing

The Cofense Phishing Defense Center (PDC) has unearthed a new phishing campaign in multiple enterprise email environments protected by Proofpoint and Microsoft that delivers .ics calendar invite attachments containing phishing links in the body.

The researchers assume that the attackers believe putting the URL inside a calendar invite would help the messages to avoid automated analysis.

Continue reading

1Password launches tool to guard against credential stuffing

Hacker typing username and password

Reuse of the same or similar passwords across accounts makes life easier for cybercriminals as they are able to try multiple servers using credentials exposed in breaches -- so called 'credential stuffing'.

Enterprise password manager 1Password is launching a new reporting tool for its users that allows them to swiftly identify compromised accounts and take action to protect the enterprise by alerting users to create new secure passwords.

Continue reading

Malware incidents decline 23 percent in 2019

declining graph

European managed security services company Orange Cyberdefense today reveals the findings of its inaugural Security Navigator, which shows a 23 percent decline in the number of recorded malware incidents in 2019.

The total number of security events have, however, increased. The company analysed 263,109 events from data obtained from its 10 CyberSOCs and 16 SOCs. Out of these events it identified 11.17 percent as verified security incidents. This represents a 34.4 percent increase over the previous year's rate of 8.31 percent.

Continue reading

Security professionals warn UK government over outdated cybercrime legislation

Union flag keyboard

The UK's Computer Misuse Act came into effect 30 years ago, but security professionals are warning that it is no longer fit for purpose and may even be hindering their efforts.

A coalition of businesses, trade bodies, lawyers and think tanks from across the cybersecurity industry have today taken the unprecedented step of uniting to write a letter to the prime minister urging him to reform the law.

Continue reading

Identifying the security risks and rewards of open source software deployments

Business security

Open source components are now at the core of many applications and a good deal of infrastructure. But what implications does this have for security?

The Information Security Forum has released a new paper, Deploying Open Source Software: Challenges and Rewards, to help security professionals recognize the benefits and perceived challenges of using open source and set up a program of protective measures to effectively manage it.

Continue reading

How IoT devices are putting enterprises at risk

Wireless internet of things

While businesses generally take care to protect desktop and mobile computing devices, the rise in IoT usage has meant that lots of potentially less secure equipment is sneaking onto networks.

Forescout Research Labs has been assessing the risk of over eight million devices across a number of industries via its Forescout Device Cloud, a repository of connected enterprise device data.

Continue reading

New application security analyzer helps prevent breaches across cloud services

Software testing

Most businesses now use web and cloud applications to deliver richer web experiences and better outcomes for customers. But the current generation of web security tools are poorly suited to address the frameworks, APIs and cloud microservices that are the underpinnings of these modern apps.

Now though application security firm Data Theorem is launching Web Secure, a full-stack application security analyzer that provides vulnerability analysis for modern web applications from the web-layer down to its embedded APIs and cloud resources.

Continue reading

Two thirds of malware is invisible without HTTPS inspection

unknown threat

A new report from WatchGuard Technologies shows that 67 percent of all malware in the first quarter of this year was delivered via HTTPS, so organizations without security solutions capable of inspecting encrypted traffic will miss two-thirds of incoming threats.

In addition, 72 percent of encrypted malware was classified as zero day (meaning no antivirus signature exists for it, and it will evade signature-based protections). The findings suggest that HTTPS inspection and advanced behavior-based threat detection and response solutions are now requirements for every security-conscious organization.

Continue reading

Twitter warns users of 'data security incident' involving billing information

Twitter and white wood backrgound

Twitter has emailed an unknown number of users to warn them of a security incident that took place some time prior to May 20 this year.

The company says that personal and billing information of people who used the Ads or Analytics pages on the Twitter site may have been affected. Twitter says that the vulnerability has now been addressed, but has emailed users to explain the circumstances of the incident.

Continue reading

Illumio brings zero trust to the endpoint

endpoint protection

Endpoints are generally the weakest point of a corporate network and the problem is made more acute by the shift to remote working.

Illumio is launching a new endpoint protection solution that reduces the risk of ransomware and malware propagating laterally throughout an organization.

Continue reading

Load More Articles