Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 206

ISBuzz Team

ISBuzz Team
  • Website

Expert commentary: Razer Gaming Fans Caught Up in Data Leak From misconfigured Elasticsearch

ISBuzz TeamSeptember 14, 20201 Min Read

A cloud misconfiguration at the gaming-gear merchant potentially exposed 100,000 customers to phishing and fraud. Security consultant Bob Diachenko ran across a misconfigured Elasticsearch cloud cluster that exposed a segment of Razer’s infrastructure to the public internet, for anyone to see. Source: https://threatpost.com/razer-gaming-fans-data-leak/159147/

Read More

Tackling SIM Swap Fraud: Time For New, More Robust Verification Methods

ISBuzz TeamSeptember 14, 20204 Mins Read

With T-Mobile recently falling victim to a major SIM swap fraud attack and millions of other consumers still being affected by similar hacks, there is now an urgent need for more robust authentication and verification methods that guard against the ongoing threat posed by SIM swapping. The coronavirus pandemic has seen a large number of cybercriminals and hackers alter their focus, exploiting the uncertainty experienced by billions across the globe. The last few months have seen much of the focus drawn to consumers, who have spent much more time online and on their mobile devices than before. As a result,…

Read More

Expert Reaction On Microsoft Blog On APT Groups: Comment On APT28 From Mandiant

ISBuzz TeamSeptember 11, 20201 Min Read

Microsoft has shared its latest insights into election security intelligence. The advisory mentions three threat actors – including APT28, otherwise known as Fancy Bear. APT28 promotes the political interests of the Russian government, and is known for hacking Democratic National Committee emails to attempt to influence the outcome of the United States 2016 presidential elections.

Read More

Thousands Of Razer Customers Order And Shipping Details Exposed On The Web Without Password

ISBuzz TeamSeptember 11, 20201 Min Read

Security researchers today revealed that Razer, Inc., a global gaming hardware manufacturing company, e-sports and financial services provider, left thousands of customers’ order and shipping details exposed on the web without password via a misconfigured server. The exposed information includes full name, email, phone number, customer internal ID, order number, order details, billing and shipping address. The exact number of affected customers is yet to be assessed as originally it was part of a large log stored on a company’s Elasticsearch cluster misconfigured for public access since August 18th, 2020 and indexed by public search engines. Based on the number…

Read More

Bluetooth Security Flaw Leaves Devices Vulnerable To Hackers

ISBuzz TeamSeptember 11, 20201 Min Read

A new Bluetooth security flaw has been discovered that would potentially allow an attacker to connect to a user device without authentication, according to a statement by the Bluetooth Special Interest Group. The statement says that, for the attack to be successful “an attacking device would need to be within wireless range of a vulnerable Bluetooth device”. While Apple protects against some forms of Bluetooth attack by requiring apps to ask user permission before a connection is initiated, vulnerability to so-called Man-In-The-Middle (MITM) attacks is less clear.

Read More

Expert Insight: Data center giant Equinix discloses ransomware incident

ISBuzz TeamSeptember 11, 20201 Min Read

Equinix, one of the world’s largest providers of on-demand colocation data centers, has disclosed today a security breach. In a short statement published on its website, Equinix said it found ransomware on its internal systems, but that the main core of its customer-facing services remained unaffected. “Our data centers and our service offerings, including managed services, remain fully operational, and the incident has not affected our ability to support our customers,” the company said. Full story: https://www.zdnet.com/article/data-center-giant-equinix-discloses-ransomware-incident/

Read More

Experts On “Giggle” user community exposes womens’ images, location data, and more – ignored vuln. warnings, uses flawed verification

ISBuzz TeamSeptember 11, 20201 Min Read

The new vulnerability report Giggle; laughable security from Digital Interruption reveals that the Giggle user community’s founders ignored warnings of a serious vulnerability that exposed women and teens’ location and other data, exposing them to sharp risk. The report also details the Giggle team’s failure to delete user data when accounts are deleted; and flawed and questionable user verification processes.

Read More

Security expert re: 600,000 WordPress sites attacked due to critical vulnerability (RCE flaw)

ISBuzz TeamSeptember 11, 20201 Min Read

More than 600,000 WordPress sites running vulnerable File Manager plugin versions are being attacked due to a critical remote code execution flaw,  and the attackers have also been seen protecting the sites they compromised from other bad actors’ attacks.

Read More

Cyber flashing and ‘pile on’ harassment targeted in online law reform proposals

ISBuzz TeamSeptember 11, 20201 Min Read

As reported by ITV,  in a bid to stem harmful behavior online, law reforms are now targeting abusive messages, cyber flashing, and “pile on” harassment have been proposed in a bid to stem harmful behavior online. As per the Law Commission, existing safeguards have failed to keep up with changes in how we communicate today. Few definitions: Cyberflashing: when someone sends an unsolicited sexual image to another device nearby. “pile on” harassment – where online harassment is co-ordinated against an individual – have become commonplace on the internet, via apps and across social media platforms. Yet online abuse covered under current communications offenses…

Read More

Experts Comment On Survey That 94% Of IT Professionals Have Experienced A Data Breach And Worry About Insider Threats More Than External Attacks

ISBuzz TeamSeptember 10, 20201 Min Read

A survey of 500 IT professionals by Exonar found that 94% of respondents have experienced a data breach, and 79% were worried their organisation could be next. In terms of what is causing the breaches, 40% of respondents to the Exonar survey said accidental employee incidents were to blame, compared to 21% who said it is external attackers.

Read More
Previous 1 … 204 205 206 207 208 … 1,258 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}