Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 378

ISBuzz Team

ISBuzz Team
  • Website

Atlassian Confluence Server Vulnerability

ISBuzz TeamApril 30, 20192 Mins Read

 Trend Micro and Alert Logic are speaking about a critical Atlassian Confluence Server vulnerability that is being remotely exploited by attackers to compromise both Linux and Windows servers, allowing them to drop GandCrab ransomware and the Dofloo (aka AES.DDoS, Mr. Black) Trojan.   https://twitter.com/Veracode/status/1122927329037160448 https://twitter.com/TrendMicroRSRCH/status/1122817810152001536 Experts Comments:  Mounir Hahad, Head of the Juniper Threat Labs at Juniper Networks:   “Atlassian uses two different deployment models: some customers use their cloud SaaS business model and some deploy an in-house instance of the popular collaboration tool. The danger lies on the in-house deployments. Even then, most collaboration tools are internal to their organizations and present no public interface on the internet. Those…

Read More

Exposed Database Reveals Details Over 80 Million US Households

ISBuzz TeamApril 30, 20194 Mins Read

It has been reported that the addresses and demographic details of more than 80 million US households are listed on an unsecured database stored in the cloud. The details listed include names, ages and genders as well as income levels and marital status. The researchers have been unable to identify the owner of the database, which is still online and requires no password to access. Some of the information is coded, like gender, marital status and income level. Names, ages and addresses are not coded.  https://twitter.com/gastronomy/status/1123129462621659137 https://twitter.com/Kobotic/status/1123170673306656769 Experts Comments:    Ryan Wilk, Vice President at NuData Security:  “It does not matter where in…

Read More

Majority Of Businesses Vulnerable To ‘Island Hopping’ Cyberattacks

ISBuzz TeamApril 30, 20193 Mins Read

China and Japan amongst those with least knowledge about their partners’ security practices, with the US and Germany amongst those at the top    New research from Accenture’s Technology Vision 2019 report has found that 7 in 10 businesses may be particularly vulnerable to malicious attacks through their ecosystem. Just 29% of business and IT executives globally know how diligently their partners are working regarding security, with 56% relying on trust alone.   This comes despite the fact that this tactic, known as ‘Island Hopping’, is steadily increasing. Indirect attacks of this nature could account for nearly a quarter of the total…

Read More

How Will AI Affect Wireless Networks And Cybersecurity In 2019 And Beyond?

ISBuzz TeamApril 30, 20195 Mins Read

Artificial intelligence (AI) has huge potential for wireless networks and for the people that must protect — as well as those who try to attack — them. It’s a rapidly changing landscape, and in this article, I explain how our industry is most likely to be affected by AI this year and what’s shaping up for the future. Defining AI In our context, AI is the development of computer systems and software that can replicate processes usually requiring human intelligence. In other words, AI imitates fundamental human behaviours using predictive intelligence based on big data  such as, movement (robotics), hearing…

Read More

$1.75 Million Stolen By Crooks In Church BEC Attack

ISBuzz TeamApril 30, 20191 Min Read

Hackers have stolen $1.75 million from the Saint Ambrose Catholic Parish following a successful BEC (Business Email Compromise) attack which was discovered on April 17 after payments related to the church’s Vision 2020 project were not received by a contractor.  Corin Imai, Senior Security Advisor at DomainTools: “This incident shows that no organisation which represents a significant financial opportunity is safe from cybercriminals. BEC scams are more readily associated with the corporate world, with hackers impersonating members of finance departments or the C-Suite in order to trick subordinates into making fraudulent transfers to a contractor or associated business, but this comes as a welcome reminder that…

Read More

Microsoft’s Latest Password Policy Announcement Is A Step In The Right Direction

ISBuzz TeamApril 29, 20192 Mins Read

Microsoft has admitted that having passwords expire is not a useful security measure. The company announced that it will be dropping its Windows policy that requires users to periodically change their login password as a result. You can see the full story here.    https://twitter.com/ericserno/status/1121772052384403457 Expert Comments:    Rachael Stockton, Senior Director Product Marketing, LastPass by LogMeIn:    “We’ve long advised against too frequent password changes, so we are pleased to see Microsoft’s new proposal to eliminate its password expiration policy.    Security doesn’t have to create more hurdles for employees. For years, security professionals have recommended changing passwords every 30, 60 or 90 days and in offices worldwide, IT policies…

Read More

Spyware In The IoT – This Year’s Biggest Security Threat

ISBuzz TeamApril 29, 20199 Mins Read

Malware is everywhere, infecting nearly one third of all computers in the world today. It’s ready to do damage to you, your computer or your data in ways that seem to be limited only by the dark ingenuity of hackers. Ransomware, a form of malware, can lock your files or allow hackers to threaten and steal your data if you don’t pay them. Cryptojacking attacks can install software on your device that co-opts its computing power to mine cryptocurrency for hackers without your knowledge. Viruses and worms can damage and corrupt your files; and Trojans can wreak havoc by sneaking…

Read More

UK Businesses Bullish With Data Governance

ISBuzz TeamApril 29, 20194 Mins Read

In the world of data governance, the only certainty is uncertainty. Headline regulations such as GDPR have been keeping CEOs up at night since 25th May 2018. However, while all are bound by GDPR’s legislation – none are more scared of ICOs wielding their newfound power than biggest organisations. Arguably these have more to lose, 55% of large companies said GDPR unequivocally dominated their data governance programmes. This contrasts heavily with 31% of respondents with smaller companies. With fines of up to 4% of global turnover – non-compliance could be business-ending. UK data leaders dominated by GDPR Preparing for GDPR…

Read More

Expert Thoughts On The Rise of Beapy Cryptojacking Malware

ISBuzz TeamApril 29, 20193 Mins Read

Researchers have discovered a spike in Beapy, a variant of malware that is using leaked National Security Agency (NSA) exploits to spread across corporate networks and force computers to run its cryptocurrency mining capabilities. The malware was first discovered in January and it has currently infected 12,000 devices across 732 organisations.    Beapy relies on an employee opening a malicious email that will therefore allow the malware to create a persistent backdoor on the computer, it then uses the NSA’s EternalBlue exploit to spread laterally throughout the network; very similar to how WannaCry spread in 2017. Beapy also boasts open-source credential stealing capabilities in order to collect…

Read More

Cybercriminals Moving From Consumers To Businesses

ISBuzz TeamApril 29, 20191 Min Read

Malwarebytes has published a Q1 report finding that cybercriminals have switched tactics to focus on business targets, moving away from directly targeting consumers. Overall threats to businesses rose by 200% year-on-year, with detections of Emotet targeting organisations rising 200% since Q4.  https://twitter.com/cobwebsolutions/status/1096337052117942272 Fraser Kyne, EMEA CTO at Bromium: “Hackers have become much more resourceful, investing time and money to develop new tactics to bypass enterprise defences. A classic example of this is Emotet, which has remained a thorn in the side of security teams because of hackers ability to rapidly change tactics, whether that’s by applying polymorphic wrapping or checking if its IP address is already on the spam list. This type of continuous…

Read More
Previous 1 … 376 377 378 379 380 … 1,258 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}