Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - You Are Not Alone
News & Analysis

You Are Not Alone

ISBuzz TeamBy ISBuzz TeamFebruary 26, 2014Updated:July 3, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
alone
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It seems that in the past, security professionals in law-abiding companies may have felt very alone.  There is good reason for that – who could we turn to for affordable, accurate and up-to-date threat information?

It’s one of the ways defenders against attacks have been at a distinct disadvantage.  Criminal attackers have a community – they have long shared information quite successfully to facilitate their exploits.  I’d cite the many hacker forums with detailed “how-to” information, DDoS for hire, and marketplaces for purchasing malware and stolen credit card information as proof.  Couple this with the “attacker’s advantage” of choosing where, when and how to launch attacks, and it is no surprise that collaborative hackers appear to be winning against respected brand companies, despite their generous spending on security protection tools.

Generally speaking, companies being attacked – and that could be any company of any size, anywhere — aren’t well coordinated and are not able to leverage information from others who have been attacked in a similar way.  They are alone and disconnected.  The recent exploits against retailers only came together in the press – there was evidently very little threat sharing or collaboration among retailers before the successful exploit, as the retailers fell like dominoes.  The vast majority of businesses generally are forced to protect and defend themselves in isolation from other businesses and the “lessons learned” by their peers.

There is some threat sharing on the defender side, for those who can afford it, and can find it in their industry.  The CISOs of large financial institutions share threat information across their closed community, for example – but it’s not done in a broad, comprehensive way. What is needed is affordable “threat sharing for the rest of us” – a way to benefit from a broader view across the diverse threat landscape than the limited perspective we get from looking only at the threats coming into our own organizations.

At the most basic level, there’s no “Neighborhood Watch” available in IT.  In the real world, neighbors can work together to better secure their homes, families, and streets by looking out for each other, sharing information, and putting criminals on notice that targeting single victims will not be tolerated.

At AlienVault, we’re providing a sort of Neighborhood Watch for digital neighborhoods on the Internet.  In the digital world, it’s not as easy as looking out your window, or posting a sign on the corner.  You don’t have the visibility and way to share and collaborate without some help. Most organizations – especially those who are in the mid-market – don’t have the security infrastructure with thousands of global collection points or a team of security researchers to analyze it all.

We noticed this problem a few years ago.  To help fix the problem, AlienVault created the crowd-sourced Open Threat Exchange.  Since the launch of OTX two years ago, we have seen substantial growth in participation with more than 8,000 contributing sites across 140 countries—and that’s just from our customer and open source user base.  In addition, we provide analysis and insights on the data we gather and remediation advice from our AlienVault Labs security researchers.

Through a new OTX Partner Program, announced earlier this week, OTX will become even richer through the contributions of threat sharing partners Cegeka,  GoGrid, Netflow Logic, Onsight, Risk I/O and ThreatStop, and conversely, their offerings will be enriched through access to the world’s largest crowd-sourced and collaborative threat exchange.

In addition, the integration of AlienVault’s OTX into Spiceworks IT management platform has already helped IT professionals simplify how they identify and mitigate threats on their networks. In fact, Spiceworks users in nearly 10,000 companies received over 1.4 million threat alerts in January 2014, only one month after the new capabilities were introduced.  Within OTX, you can see a summary, including associated blacklists, associated domains and perpetrator (if known.)  You can then drill down to threat details and see information and recommendations about the malicious activity.

AlienVault OTX provides real-time threat data not only to thousands of companies and government institutions, but also to a rapidly growing community of the world’s premier providers of security products and services. As the custodian of OTX, AlienVault openly shares its threat data repository to qualified partner members at no cost.

AlienVault is providing a way for you to share in threat intelligence with a community of other practitioners and researchers.  There’s no reason you have to face the bad guys alone – join the OTX community and help us all make a difference. It’s simple, AlienVault is taking this step in the spirit of openness and collaboration – we are prepared to continue to offer free services and tools to anyone – you don’t have to be an AlienVault customer or even an OSSIM user to benefit from OTX.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}