Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 356

ISBuzz Team

ISBuzz Team
  • Website

Marrying The Opportunity Of 5G With Security Considerations

ISBuzz TeamJuly 9, 20195 Mins Read

As we take each new mobile network generation in our stride, it can be easy to forget just how far we’ve come. For instance, both 3G and 4G were digital transformations in their own right. First allowing for multimedia sharing, data downloads and video calls, then providing widespread access to mobile internet services, HD video streaming and reliable roaming. But with Ericsson estimating there will be up to 22.3bn connected devices by 2024, it is 5G that will be required to support the demands of this level of mass connectivity. 5G will be smarter, faster, and more efficient than its…

Read More

Zoom’s Security Flaw Gives Access To Webcams

ISBuzz TeamJuly 9, 20191 Min Read

Today, security researcher Jonathan Leitschuh has publicly disclosed a serious zero-day vulnerability for the Zoom video conferencing app on Macs. He has demonstrated that any website can open up a video-enabled call on a Mac with the Zoom app installed. That’s possible in part because the Zoom app apparently installs a web server on Macs that accepts requests regular browsers wouldn’t. In fact, if you uninstall Zoom, that web server persists and can reinstall Zoom without your intervention.    Jake Moore, Cybersecurity Specialist at ESET:  “With the possibility of malware being able to attack a webcam at any moment without the correct service patch or…

Read More

AI For Fraud Detection To Triple By 2021

ISBuzz TeamJuly 8, 20193 Mins Read

Advanced analytics and biometrics becoming central to anti-fraud programmes, reveWhile only 13 per cent of organisations use artificial intelligence (AI) and machine learning to detect and deter fraud, another 25 per cent plan to adopt such technologies in the next year or two – a nearly 200 per cent increase. Fraud examiners revealed this and other anti-fraud tech trends in a cross-industry, global survey by the Association of Certified Fraud Examiners (ACFE), developed in collaboration with analytics leader SAS.    The inaugural Anti-Fraud Technology Benchmarking Report examines data provided by more than 1,000 ACFE members about their employer organisations’ use of technology to fight fraud. Other notable trends include:    The rise…

Read More

Croatian Government Targeted By Hackers

ISBuzz TeamJuly 8, 20191 Min Read

Government agencies in Croatia have been targeted with never before seen malware payload, named SilentTrinity.   A mysterious hacker group has targeted, and most likely infected, Croatian government employees between February and April this year  Emails contained a link to a remote website with a lookalike URL, where users were asked to download an Excel document.  The document was laced with malicious code packed as a macro script which appeared to have been largely copied off the internet  The macro script, if enabled by the victim, would download and install malware on their systems.   https://twitter.com/buzz_techie/status/1148102070324666369 Javvad Malik, Security Awareness Advocate at…

Read More

Experts Views On British Airways Faces Record £183m Fine

ISBuzz TeamJuly 8, 201926 Mins Read

British Airways is set to be fined more than £183 million over a customer data breach.  The fine relates to the theft of customers’ personal and financial information between June 2018 and September 2018 from the website ba.com and the airline’s mobile app  The airline initially said around 380,000 payment cards had been compromised, however the ICO said in a statement that the personal information of 500,000 customers had been affected  The incident in part involved user traffic to the British Airways website being diverted to a fraudulent site, where customer details were harvested by the attackers  https://twitter.com/SkyNews/status/1148159545971216384 Experts Comments:  Javvad Malik, Security Awareness Advocate at KnowBe4:  “While there is no…

Read More

Met Police’s Facial Recognition Tech Has 81% Error Rate, Independent Report Says

ISBuzz TeamJuly 4, 20192 Mins Read

Four out of five people identified by the Metropolitan Police’s facial recognition technology as possible suspects are innocent, according to an independent report revealed by Sky News and The Guardian.   Researchers found that the controversial system is 81% inaccurate – meaning that, in the vast majority of cases, it flagged up faces to police when they were not on a wanted list.  The report raises “significant concerns” about Scotland Yard’s use of the technology, and calls for the facial recognition programme to be halted.  Expert Comments:  Paul Bischoff, Privacy Advocate at Comparitech.com:  “The Met’s 0.1% error rate figure is calculated by dividing the number of…

Read More

The Real Diagnosis For The Health Of NHS Cybersecurity

ISBuzz TeamJuly 4, 20195 Mins Read

The FDA has warned Americans that hackers could compromise insulin pumps by connecting to them via Wi-Fi. A 2017 study from the Technology and Health Care journal found that the US healthcare industry doesn’t keep up with new cybersecurity precautions, this is despite a 2018 study from medical journal Maturitas found that medical devices — including insulin pumps and pacemakers — are highly vulnerable to cybercrime.   In contrast, a study from Infoblox found that in the UK, the number of security policies in place for new connected devices has increased from 85 to 89 percent, with fewer respondents doubting the effectiveness of these policies (9% in 2019/13%…

Read More

Slack Not Using End-To-End Encryption Puts User’s Personal Data Under Threat

ISBuzz TeamJuly 4, 20192 Mins Read

An online privacy watchdog has issued a stark warning about the risks of using the popular workplace chat app Slack. Gennie Gebhart, who serves as the associate director of research at the Electronic Frontier Foundation, outlined the threat of nation-state attacks using the troves of personal data that Slack stores. In an op-ed in the New York Times, Ms Gebhart cited Slack’s recent filing with the Securities and Exchange Commission, which highlighted threats from “sophisticated organised crime, nation-state, and nation-state supported actors”.   However, Slack has comeback with their thoughts on security but the platform does not use end to end encryption.   Twitter:  https://twitter.com/ReclaimNet/status/1146446349065490433 https://twitter.com/bahree/status/1145786027258179585 Expert Comments:  Jake…

Read More

Outdated And Unsupported Operating Systems Open To Attack

ISBuzz TeamJuly 4, 20192 Mins Read

According to recent research by Alert Logic, discovered 66% of small and midsize businesses (SMB) devices run Microsoft OS versions that have expired or will expire by January 2020, the majority of which are over 10 years old.   The report highlights the challenges SMBs face, reveals a steady increase in attacks and changes in attack methods that target their weaknesses in encryption, workload configuration, limited visibility into vulnerabilities and outdated and unsupported operating systems  66% of SMB devices run Microsoft OS versions that are expired or will expire by January 2020. Shockingly, the majority of devices scanned in the research were running Windows versions…

Read More

First-ever Malware Strain Seen Abusing DoH Protocol

ISBuzz TeamJuly 4, 20192 Mins Read

Security researchers from Netlab – a network threat hunting unit of Chinese cybersecurity giant Qihoo 360 – discovered the first ever malware strain, named Godlua, seen abusing the DNS over HTTPS (DoH) protocol. The Godlua malware is written in Lua to work on Linux Servers. The attackers are using  Confluence exploit (CVE-2019-3396) to infect outdated systems, and early samples uploaded on VirusTotal have mislabeled it as a cryptocurrency miner.   Internet Emgineering Task Force’s (IETF) RFC 8484 provides more details of DoH protocol    Social Media Reaction:   https://twitter.com/GossiTheDog/status/1146138461969244160 https://twitter.com/tc1415/status/1128762647208505344 Experts Comments: Anthony Chadd, SVP, Global Sales at Neustar:   “Whether using common methods such as amplification or flooding, the DNS is often at the heart of…

Read More
Previous 1 … 354 355 356 357 358 … 1,258 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}