Articles about Security

Insiders cause more than half of data breaches

web threats

Most companies consider hacker attacks to be the most dangerous threat, but according to a new report, insiders cause the majority of security incidents by either malicious or accidental actions.

The study from threat detection specialist Netwrix looks at the experiences and plans over 1500 organizations have in addressing IT risks. The insider threat is underlined by the fact that 44 percent of respondents either don't know or are unsure what their employees are doing with sensitive data.

Continue reading

Data theft malware targets Fortnite players

Fortnite logo

It's no surprise that the release of a new season of Fortnite has led to a rise in scammers keen to exploit gamers who are eager to sample the new software.

Among a rash of supposed free passes and free Android versions of the game that hide surveys and other nuisances, researchers at Malwarebytes have uncovered a malicious program seeking to steal data and Bitcoins.

Continue reading

67 percent of organizations believe hackers can penetrate their network

Network security

Around two-thirds of executives and IT professionals responding to a new survey believe that hackers would be able to penetrate their networks.

The study from security and application delivery company Radware focused on global companies and reveals that at least 89 percent of respondents have experienced attacks against web applications or web servers of the past year.

Continue reading

Facebook hack update: Attackers did not use stolen tokens to access other sites and apps

Facebook account security

Since the revelation that a "security issue" allowed hackers to steal access tokens to view people's Facebook accounts, the company has provided a further update about the incident. Facebook has already provided one update about the attack, but now the investigation has progressed and the social network is trying to offer reassurances to those who have understandable concerns about security.

The company says that the attackers did not access any apps that make use of Facebook Login, the system that makes it possible to sign into other accounts and services with Facebook credentials.

Continue reading

One in four cyberattacks targets ordinary users

Targeted user

While the majority of cyberattacks are aimed at businesses and other organizations, an increasing number are targeting ordinary users, according to the latest report from Positive Technologies.

The most attractive targets were personal data (30 percent) and credentials (22 percent), especially for online banking. To steal this data, attackers compromised a wide range of websites, including web stores, ticket vendors, and hotel booking services.

Continue reading

Behavioral analysis used to predict cybersecurity threats

Data security watch face

Internet of Things security specialist ZitoVault has patented a new means of predicting upcoming cybersecurity events.

While most existing approaches only address the real-time detection of threats or anomalies based on a limited set of pre-established data points, ZitoVault's latest patent uses a new approach.

Continue reading

Financial services breaches triple since 2016

Broken piggy bank

2018 has seen nearly three times as many breaches at financial services organizations as there were in 2016, according to a new report.

The study by cloud access security broker Bitglass finds there have been 103 breaches in this year’s report compared to just 37 two years ago.

Continue reading

Google is trying to make Chrome extensions safer with new Chrome Web Store review process and permission controls

Chrome icon with a padlock

Extensions are a great way to increase the capabilities of your web browser, but they can also be the source of problems. Malicious extensions can be a serious headache, and this is something that Chrome users know more than most. Now Google is looking to improve security.

The company has already promised that with Chrome 70 it is going to give users more privacy controls, and today it announced that this version of the browser will also introduce permission controls extensions. On top of this Google is introducing a new review process for extensions submitted to the Chrome Web Store, as well as placing a ban on extensions with obfuscated code.

Continue reading

Bigger isn't better when it comes to password security

password

A new study by LogMeIn, the company behind the LastPass password manager shows that size matters in password security, but not in the way that you might think.

Looking at anonymized data from over 43,000 companies, the study produced a security score and a password strength score for each. Businesses with fewer than 25 employees had the highest average security score of 50, but the average drops as company size increases.

Continue reading

Facebook shares more details about its massive security breach -- after blocking people from sharing news about it

Facebook security notifications

The Guardian was among many outlets to write about the huge Facebook vulnerability and attack reported yesterday, and people were understandably keen to share the story on the social network. However, many people found that they were unable to do.

Large numbers of Facebook users who tried to share the Guardian's story -- as well as one published by the Associated Press -- were greeted by a message informing them that the messages was spam and could not be posted. The matter has been addressed, but it led to complaints that Facebook was trying to hush up the story, and renewed calls to #DeleteFacebook. On its blog, Facebook's security team has also given more details about the "security issue" that happened earlier this week,

Continue reading

Facebook hack: 50 million users affected by site code flaw

Facebook shortcut with notification

Facebook has revealed that it discovered a security issue which could have exposed the accounts of 50 million people.

A vulnerability was discovered in Facebook's View As feature on Tuesday, September 25, but the company has not given too many details about how the flaw was exploited or by whom, but it has said that attackers were able to steal access tokens and access other people's accounts. Law enforcement agencies have been informed, and an investigation is under way.

Continue reading

ESET launches cloud-based security management solution for SMBs

SMB laptop

Smaller businesses are not immune to cyber security threats, but they often don't have the budgets or staffing resources to deal with them.

To address this, endpoint security specialist ESET is launching a new cloud-based remote security management solution specifically designed for the IT security challenges faced by SMBs.

Continue reading

Security is developers' top concern for open source components

Developer at work

Developers rate security as their top concern when dealing with open source components, above integration and functionality, according to a new study.

The report from open source security and license compliance management company WhiteSource reveals that an average developer invests 15 hours a month dealing with open source security vulnerabilities, but only a small fraction of that time (25 percent) is devoted to actual remediation.

Continue reading

Schools should offer formal information security classes

Classroom

Digital threats are evolving fast and that leads to increasing demand for security professionals to tackle them. A new report from AI-driven security company Lastline looks at how existing practitioners feel about education in their field.

Among the findings are that 85.5 percent of infosec professionals believe that US schools should offer more formal classes in the field.

Continue reading

Apple's Device Enrollment Program can leak sensitive information about devices and their owners

iPhones on a MacBook

Security researchers have discovered an issue with the Device Enrollment Program used by Apple to allow organizations to manage their MacBooks and iPhones. Duo Security says that using nothing more than a serial number, it is possible to gain access to sensitive data about enrolled devices and their owners.

It is even possible to enroll new devices that can then access Wi-Fi passwords, VPN configurations and more. Apple was alerted to the issue way back in May, but has not done anything about it as the company does not regard it as a vulnerability.

Continue reading

© 1998-2024 BetaNews, Inc. All Rights Reserved. Privacy Policy - Cookie Policy.