Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 363

ISBuzz Team

ISBuzz Team
  • Website

American Medical Collection Agency Breach – 20 Million Patients’ Records Compromised

ISBuzz TeamJune 13, 20191 Min Read

Maryland Attorney General Brian E. Frosh has warned Marylanders that their medical and other private information may have been compromised by a cyberattack against American Medical Collection Agency, a third-party collection agency for laboratories, hospitals, physician groups, medical providers and others. The known list of those impacted affects over 20 million patients.  https://twitter.com/wjz/status/1138819495290691584 Expert Comments:  Tim Erlin, VP, Product Management and Strategy at Tripwire:    “A criminal with the details about patients’ medical bills is in a good position to fraudulently collect money from those patients. Imagine if you received an email with accurate details about a medical bill you actually have, and a link…

Read More

Experts Comments On Microsoft SymCrypt Vuln Can Bring Down Windows Servers

ISBuzz TeamJune 13, 20192 Mins Read

A Google researcher has discovered a vulnerabiliy in the SymCrypt cryptographic library of Microsoft’s OS that can trigger a DDoS disruption in Windows 8 servers and above, causing a perpetual operation “when calculating the modular inverse on specific bit patterns with bcryptprimitives!SymCryptFdefModInvGeneric.”   https://twitter.com/taviso/status/1138469652571467776 https://twitter.com/vcsjones/status/1123089141481254917 Expert Comments:  Adam Laub, SVP Product Management at STEALTHbits Technologies:  “This finding demonstrates just how important this type of research is in helping organizations mitigate risks no one ever knew existed. The frightening part about this vulnerability and others that can be remedied with a simple patch, however, is that many organizations will have a very difficult time actually implementing the fix. When I first…

Read More

Nozomi Networks-Sponsored SANS Survey Finds Industrial Organizations Are Going All-In To Tackle Growing Threats To OT/ICS Cyber Security

ISBuzz TeamJune 13, 20194 Mins Read

Citrix, a company which works with the likes of the FBI and US military, recently hit the headlines when it fell victim to hackers. The cyber criminals allegedly used a technique called password spraying, which exploits weak passwords. This is just one example of why the traditional username and password combination is no longer fit for purpose, in both our personal and business life.   The problem with traditional password systems is not with the concept of the username and password combination. Rather, it is that the system relies on the weakest part in any infosecurity chain: the human.   Historically, this method has…

Read More

My Voice Is My Ultimate Password – How Biometrics Can Keep Hackers At Bay

ISBuzz TeamJune 13, 20194 Mins Read

Citrix, a company which works with the likes of the FBI and US military, recently hit the headlines when it fell victim to hackers. The cyber criminals allegedly used a technique called password spraying, which exploits weak passwords. This is just one example of why the traditional username and password combination is no longer fit for purpose, in both our personal and business life.   The problem with traditional password systems is not with the concept of the username and password combination. Rather, it is that the system relies on the weakest part in any infosecurity chain: the human.   Historically, this method has…

Read More

Patch Tuesday Commentary

ISBuzz TeamJune 12, 20193 Mins Read

Yesterday, Microsoft published its monthly roll-up of security updates, known as Patch Tuesday. This month, the OS maker has patched 88 vulnerabilities, among which 21 received a rating of “Critical,” the company’s highest severity ranking.  Experts Comments:  Satnam Narang, Senior Research Engineer at Tenable:  “This month’s Patch Tuesday release contains updates for nearly 90 CVEs, including fixes for four zero-day elevation of privilege vulnerabilities: “bearlpe,” “InstallerBypass,” “CVE-2019-0841-BYPASS,” and “sandboxescape,” that werepublicly disclosed by SandboxEscaper in late May.    “CVE-2019-1069, the “bearlpe” flaw, is an elevation of privilege vulnerability in the way the Task Scheduler Service validates file operations.    “CVE-2019-0973, “InstallerBypass,” is an elevation of privilege…

Read More

World’s Top Security Vulnerabilities Revealed – HackerOne

ISBuzz TeamJune 12, 20192 Mins Read

HackerOne is revealing the top 10 most impactful security vulnerabilities which have earned hackers over $54 million in bounties.    Based on the 120,000+ security vulnerabilities that hackers have reported across over 1,400 HackerOne customer programs, the data represents real-world risks that existed in organisations, including technology unicorns, governments, start-ups, financial institutions and open source projects.    HackerOne has launched an interactive site showing the vulnerability types with the highest severity scores, the largest total report volumes and the most reported by industry.    HackerOne’s top 10 security vulnerabilities ranked by total bounties paid on the platform are:  Cross-site Scripting – All Types (dom, reflected, stored, generic)  Improper Authentication – Generic …

Read More

Europe Its Own Biggest Enemy As Cyberattacks Continue To Soar

ISBuzz TeamJune 12, 20198 Mins Read

New threat intelligence from F5 Labs shows that Europe suffers more attacks from within its borders than any other part of the world;  Majority of attacks stem from IP addresses in the Netherlands, followed by the United States, China, Russia, and France    F5 Labs identified top attacking networks and ISPs, as well as most prominently targeted ports from 1 December 2018 to 1 March 2019    Europe endures more cyberattacks from within its own geographic region than any other part of the world, according to new analysis by F5 Labs1.  The discovery was made after studying attack traffic destined for European…

Read More

MI5 ‘Unlawfully’ Handled Bulk Surveillance Data, Lawsuit

ISBuzz TeamJune 12, 20193 Mins Read

UK’s secret service, MI5, may have broken the law by holding large volumes of citizens’ private data without proper protections, according to documents released today in the High Court.   https://twitter.com/MiddleEastEye/status/1138470349337694220 Expert Comments:    Fouad Khalil, VP of Compliance at SecurityScorecard:   “As we consider MI5’s recent privacy violation we confirm that no one and no entity is out of GDPR reach. MI5 seems to have falsely claimed that they had the right to keep personal data and that they had sufficient controls to protect it. We have a situation here where MI5 may have violated many of the laws and regulations enacted for…

Read More

Avast Business Launches New Patch Management

ISBuzz TeamJune 12, 20194 Mins Read

With 55% of installed software on PCs worldwide out of date, Avast’s new service will help small businesses prioritize, manage and deploy critical security updates   Redwood City, California, June 11, 2019 – Avast (LSE:AVST), the world leader in digital security products, has today launched a new Patch Management service to help small and mid-sized businesses manage necessary security updates more easily and efficiently. Around 50% of software vulnerabilities exploited occur within 2-4 weeks of a software update being released, however, the time-intensive evaluation and required testing of patches means businesses on average take 120 days to implement the updates, exposing them to…

Read More

Malware Peddlers Hit Office Users With Old But Reliable Exploit

ISBuzz TeamJune 11, 20191 Min Read

Emails delivering RTF files equipped with an exploit that requires no user interaction (except for opening the booby-trapped file) are hitting European users’ inboxes, Microsoft researchers have warned. Theexploit takes advantage of a vulnerability in an older version of the Office Equation Editor, which was manually patched by Microsoft in November 2017.  https://twitter.com/MsftSecIntel/status/1137118977983897600 https://twitter.com/SecurityMetrics/status/1138127553321791488 Expert Comments:  Roy Rashti, Cybersecurity Expert at Bitdam: “This exploit is still being observed in attacks because, ultimately, it still works. The reason it still works is that people tend to ignore updates and patches, which makes them vulnerable to N-day exploits.  This is the same reason that WannaCry proliferated so…

Read More
Previous 1 … 361 362 363 364 365 … 1,258 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}