Industrial internet of things

New solution helps secure infrastructure across OT and IT environments

Historically, infrastructure systems and operational technology (OT) were designed to work in isolation from IT. But in the modern world these environments are increasingly converged and that can open up new attack routes.

Cyber exposure specialist Tenable is launching a new solution to manage Cyber Exposure holistically across IT and OT systems. This is based on enhancements to the Tenable.io platform and Industrial Security, an asset discovery and vulnerability detection solution for OT systems, delivered in partnership with Siemens.

By Ian Barker -
Donald Trump and Kim Jong-Un

USB fans gifted to reporters at Trump-Kim summit spark security fears

Reporters covering the historic meeting between Donald Trump and Kim Jong-Un in Singapore have been given a gift bag that has security experts concerned.

In addition to bottled water and a local guidebook, the gift bag also contained a USB fan. While on the face of it this would seem to offer a way to combat the Singaporean heat, the fan also sparked warnings that it could be laced with malware.

Mobile apps

Media and entertainment companies have riskier mobile apps

As the world increasingly turns to mobile devices to access the internet and conduct business, so firms are eager to put out their own apps.

But new research from security ratings company BitSight reveals that many companies may be rushing out apps that have vulnerabilities which could lead to data leakage, privilege abuse, unencrypted personally identifiable information (PII), and credential theft.

By Ian Barker -
Holding Bitcoin

Bitcoin plummets after hackers steal $37 million from South Korean cryptocurrency exchange Coinrail

Bitcoin has once again demonstrated its volatility, dropping in value by 10 percent following news of an attack and theft from the South Korean exchange Coinrail.

Coinrail has confirmed that it suffered a "cyber intrusion" and while it did not specify the value of the coins stolen, local news outlet Yonhap News estimated it to be $37.28 million based on a loss of about 30 percent of the coins traded on the exchange.

OnePlus 6 with Never Settle slogan

Fix on the way for OnePlus 6 bootloader security flaw

A security researcher has discovered a vulnerability in the OnePlus 6 bootloader. The flaw makes it possible for someone to boot arbitrary or modified images -- even if the bootloader is locked.

Exploiting the vulnerability requires someone to have physical access to the phone, and after this it is a relatively simple task to restart the handset in fastboot mode. From here is would be possible to load a modified boot image, including one that has root access.

mining-bitcoin

Cryptomining still tops the malware charts for May

Currency miners continue to top the malware charts according to Check Point Software's latest Global Threat Index.

May 2018 marks the fifth consecutive month where cryptomining malware has dominated Check Point's index. The Coinhive cryptominer impacted 22 percent of organizations globally during May -- up from 16 percent in April, an increase of nearly 50 percent.

By Ian Barker -
Ticketfly logo

Ticketfly says hack exposed private data of 27 million accounts

Last week event ticketing company Ticketfly suffered a cyberattack which saw the site taken offline for a number of days. The site is now back up and running, and Ticketfly has revealed the extent and impact of the hack.

The company says that data from 27 million Ticketfly accounts was accessed, including names, addresses, email addresses and phone numbers. Customers are assured that passwords and credit card details remain safe.

Hacking

71 percent of IT pros believe they can hack any organization

Using one of four common attack vectors, 71 percent of surveyed IT professionals believe they could successfully hack any organization.

Based on a survey carried out among attendees to the RSA Conference in April 2018 by vulnerability management specialist Outpost24, 34 percent say that they would use social engineering, 23 percent say they would enter via insecure web applications, 21 percent via mobile devices, while a further 21 percent say they would enter via a public cloud.

By Ian Barker -
cryptocurrency mining

Cryptocurrencies spark cybercrime gold rush

Cybercriminals are increasingly using the dark web to facilitate cryptocurrency theft on a large scale, according to cybersecurity company Carbon Black.

The company’s research has uncovered a total of $1.1 billion in cryptocurrency-related thefts during the past six months and finds there are currently an estimated 12,000 dark web marketplaces selling approximately 34,000 offerings related to crypto theft.

By Ian Barker -
Unhappy laptop user on beach

Keeping your data safe while traveling

As we enter the summer people start to go away on vacations and visit sporting events like this year's World Cup in Russia, potentially exposing their digital devices and data to extra risks.

VPN advice service vpnMentor has produced a report looking at the particular risks travelers face and how they can protect themselves.

By Ian Barker -
VPNFilter

VPNFilter malware infection is much worse than first thought -- is your router affected?

It's just a couple of weeks since we first heard about the VPNFilter malware. Linked to Russia, the malware hit 500,000 routers around the world, but now Cisco's Talos security researchers are warning that the problem is much worse than anyone thought.

Initially thought to only affect SOHO routers and storage devices from Linksys, MikroTik, Netgear, TP-Link, and QNAP , the at-risk list has been extended to include consumer-grade routers from Linksys, MikroTik, Netgear and TP-Link. Researchers have also discovered that the malware is more powerful than initial assessments suggested -- it is now known to be able to bypass SSL encryption and perform man-in-the-middle attacks.

Mobile security

The challenges of securing mobile devices

Mobile devices now account for around half of web traffic and inevitably that makes them more attractive to hackers who see new attack routes via mobile apps.

The Information Security Forum is launching a new paper, Securing Mobile Apps: Embracing Mobile, Balancing Control, describing the security challenges associated with acquiring, using and operating mobile apps, and suggesting actions to manage those challenges, while maintaining the business benefits.

By Ian Barker -
business security

The key challenges for security operations center staff

Security operations centers are understaffed according to 45 percent of professionals who work in them, and of those, 63 percent think they could use anywhere from two to 10 additional employees.

This is among the findings of a new survey from Exabeam released today at Infosecurity Europe. It shows 62 percent of managers and frontline employees see inexperienced staff as a problem, compared to just 21 percent of CIO and CISOs.

By Ian Barker -
MyHeritage

92 million user accounts at risk after genealogy and DNA-testing site MyHeritage is hacked

MyHeritage -- a website that helps people research their family tree and also offers a DNA testing service -- has suffered a "cybersecurity incident". A file containing the usernames and hashed passwords of more than 92 million users was discovered on an external server by a security researcher.

The file was found to be genuine and MyHeritage is now undertaking an investigation to determine what happened. The security breach affects all users who signed up to the site up to October 26, 2017. The company says that it is taking steps to inform the relevant authorities in line with GDPR.

Risky florida

Florida residents have the worst cybersecurity habits in the US

A study by cybersecurity company Webroot in conjunction with the Ponemon Institute finds Florida to be the worst state in the US for cyber-hygiene.

Ponemon surveyed 4,000 people across the US about their cybersecurity knowledge and internet safety practices. Wyoming and Montana come close behind Florida in poor internet habits. The safest online behavior is displayed in New Hampshire, Massachusetts, and Utah.

By Ian Barker -
Load More Articles