Articles about Security

Most companies not putting adequate investment into application security

open digital lock

According to a new survey from Arxan, only 25 percent of respondents say their organization is making a significant investment in solutions to prevent application attacks.

This is despite awareness of the negative impact of malicious activity. A worrying 65 percent of companies say they would be spurred to increase application protection measures only after an end user or customer was negatively affected.

Continue reading

Data breach activity declines sharply in 2018

data breach

The number of data breaches disclosed in the first three months of this year fell to 686 compared to 1,444 breaches reported in the same period of 2017, according to a new report.

This still represents the exposure of some 1.4 billion records, although this figure too is down from 3.4 billion in the same quarter last year.

Continue reading

Younger generations lack understanding of cybersecurity careers

Red and blue security padlock

It's been accepted wisdom for some time that an injection of extra talent is needed to solve the cybersecurity skills shortage.

Further confirmation of this comes in the form of a report from ProtectWise looking at the survey responses of 524 technology-savvy millennials and post-millennials in the US, conducted by Enterprise Strategy Group (ESG), to see if there were potential answers to the security skills shortage.

Continue reading

Microsoft's Meltdown patch for Windows 10 has a 'fatal flaw'

Spectre and Meltdown 3D renders

If you've not updated to Windows 10 April 2018 Update but you have installed Microsoft's Meltdown patches from a few months ago, your computer is vulnerable to a "fatal flaw".

This is not the first time a patch for the Meltdown vulnerability has led to problems with Windows, but previously it was Windows 7 and Windows Server 2008 that were affected. A security researcher found that Microsoft's patch for Windows 10 "undermined the mitigation", and while the problem has been fixed in the April 2018, the company is still working on backporting an updated patch for older versions of Windows 10.

Continue reading

Twitter warns all users to change passwords after 'bug' left credentials stored in plaintext

Twitter security logos and fingerprints

Twitter has issued a warning to its 330 million users, urging them to change their passwords. The security announcement comes after the company discovered a bug that left passwords stored in unencrypted form in internal logs.

While Twitter says that the bug has been fixed and that the plaintext logs have been deleted, it is encouraging the password change out of "an abundance of caution".

Continue reading

73 percent of industrial networks are vulnerable to hackers

refinery industry

The industrial control systems (ICS) used to run equipment in manufacturing, energy, and other sectors are secured differently from office networks. Vulnerabilities often go unpatched, because organizations are afraid to make changes that might cause downtime.

To minimize the chances of exploitation of vulnerabilities, measures put in place include placing ICS components on a separate network, isolating them, or air-gapping them entirely from Internet-connected corporate systems. However, penetration testing performed by Positive Technologies has shown that such measures often fall short in practice, leaving attackers plenty of opportunity to access critical equipment.

Continue reading

The poor password habits of IT professionals

password note

It's World Password Day and we've already looked at tips for safe password use, but a new survey from identity management company SailPoint reveals that IT professionals aren't practising what they preach when it comes to password use.

In partnership with research company Vanson Bourne, SailPoint surveyed 400 IT decision makers about their password habits and came up with some worrying results.

Continue reading

Ransomware attacks up 400 percent in 2017 mainly due to WannaCry

Ransomware skull

Ransomware attacks grew by 400 percent last year, largely down to the success of the WannaCry attack. It’s perhaps not surprising that other variants slowed down, but this signals a shift in the way ransomware is being used.

A new report from F-Secure shows WannaCry accounted for nine out of every 10 ransomware detection reports by the end of the year.

Continue reading

Top tips for World Password Day

Written passwords

We're constantly being told that the password's days are numbered. No less a figure than Bill Gates predicted the end of the password as far back as 2004. Yet we still rely on them to protect many of our day-to-day activities.

To mark today’s World Password Day, Raj Samani, chief scientist and fellow at McAfee, has produced a set of tips that people can follow to make the best use of passwords.

Continue reading

Most popular travel sites have unsafe password practices

Online travel booking

A new study of password and account security on 55 of the world's most popular travel-related sites reveals that 89 percent leave their users' accounts potentially exposed to hackers due to unsafe password practices.

The research by password management company Dashlane tested each website on five critical password and account security criteria. A site received a point for each criterion it met, for a maximum score of 5/5. Any score below 4/5 was considered failing and not meeting the minimum threshold for good password security.

Continue reading

Critical vulnerability found in infrastructure and manufacturing applications

industrial skyline

A critical remote code execution vulnerability has been discovered in two Schneider Electric applications heavily used in manufacturing, oil and gas, water, automation and wind and solar power facilities.

The vulnerability, discovered by cyber exposure company Tenable, could, if exploited, give cyber criminals complete control of the underlying system.

Continue reading

Phishing and drive-by downloads lead infection methods

Phishing

The most common infection vectors are still email phishing and drive-by downloads according to the latest threat report from AI security specialist Cylance.

The report provides a real-world glimpse into major cyber threats that affected Cylance’s customer base in 2017. Along with industry trends and analysis, and data from thousands of government entities and organizations of all sizes across 160 countries that have adopted a prevention-first approach to security.

Continue reading

North Korean antivirus software uses decade old pirated scan engine

Virus web

With a name like 'SiliVaccine' you could be forgiven it's something your doctor would give you if you were worried about turning into a clown. But in fact this is North Korea's home grown antivirus product.

Check Point Software has obtained and analyzed a rare copy of the software and discovered key components of its source code to be identical to a 10-year old copy of Trend Micro's AV software.

Continue reading

81 percent of organizations see an increase in cyber security challenges

security threats

A new study from IT solutions provider US Signal reveals that businesses are seeing a greater number of security challenges.

The survey of security experts from a cross-section of organizations also shows 40 percent of respondents experienced at least one security incident in the last year, and 13 percent didn't know if they had.

Continue reading

Amazon now offers a smart home security installation service

Amazon Smart Home Security installation

Earlier today, we revealed that Amazon is bumping up the price of a Prime subscription by 20 percent, but this is not the only news coming from the online giant. A newly discovered and little-advertised portal on the Amazon site finds the company offering smart home security installation services.

Ranging in price from $240 to $840, the Smart Home Services packages include the cost of both hardware and installation. In all, there are five packages to choose from, covering everything from simple smart lighting, to full-home security systems.

Continue reading

© 1998-2025 BetaNews, Inc. All Rights Reserved. About Us - Privacy Policy - Cookie Policy - Sitemap.