Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 383

ISBuzz Team

ISBuzz Team
  • Website

Why Ephemeral Certificates Are The Ideal Option For Secure IT Access

ISBuzz TeamApril 15, 20195 Mins Read

Password managers, long heralded as the gold standard for consumer password safety, have been shown to have vulnerabilities. Research shows that password managers can leak login credentials to the PC’s memory, making them vulnerable to hacking. In light of this research, it’s certainly time for consumers to examine their password management best practices. Consumers should move towards more secure authentication methods, like multi-factor authentication, dedicated authenticator devices (like YubiKey), or enabling more secure authentication protocols (WebAuthn). But, what about businesses and access to their critical IT infrastructure in particular? Is it also time to rethink password and access management –…

Read More

Biometrics Adoption

ISBuzz TeamApril 15, 20191 Min Read

A panel of industry experts at the 2019 ISC West conference in Las Vegas are predicting that biometrics are going mainstream with the mobile sector leading the way to adoption.  Robert Capps, VP and Authentication Strategist at NuData Security: “Biometrics technology is increasingly implemented across the market, including the financial and ecommerce industries. Today, passive biometrics is an option to verify users online that doesn’t require an additional step up and it’s widely used to identify customers by their inherent behavior. The benefit of this type of technology is that it is seamless – customers don’t have to take an additional step to identify themselves.…

Read More

Automation Will Improve Security Function, Say UKprofessionals In New Global Survey

ISBuzz TeamApril 15, 20193 Mins Read

Security professionals reveal the reasons and concerns behind the adoption of automation and AI as security tools in the 2019 Ponemon Institute and DomainTools survey  DomainTools, a leader in domain name and DNS-based cyber threat intelligence, today announced the results of the study “Staffing the IT Security Function in the Age of Automation”, conducted in conjunction with the Ponemon Institute. More than 1,400 security professionals based across the US, the UK and APAC provided answers on the impact that automation and artificial intelligence (AI) will have on the staffing of IT security functions. All respondents participate in attracting, hiring, promoting and retaining IT security personnel within their organizations.    Results clearly indicated a…

Read More

Reaction On Bounty Fined £400,000 By ICO

ISBuzz TeamApril 15, 20193 Mins Read

It has been reported that pregnancy club Bounty UK has been given a £400,000 fine by the ICO for illegally sharing the personal information of more than 14 million people.  Experts Commets: Anjola Adeniyi, Technical Leader for EMEA at Securonix: “With this kind of illegal data sharing, mothers and babies may be unable to tell if they have suffered a data breach with one of Bounty’s third parties. The fine may have been greater if it wasn’t that the breach happened before GDPR came into effect. Hopefully the wider market can learn from Bounty’s experience, and avoid such misconducts.”  .…

Read More

Vulnerabilities Discovered In WPA3

ISBuzz TeamApril 15, 20192 Mins Read

It has been reported that ‘Dragonblood’ vulnerabilities seep into WPA3 secure Wifi handshake. The research identified vulnerabilities in  early implementations of WPA3™-Personal, where those devices allow collection of side channel information on a device running an attacker’s software, do not properly implement certain cryptographic operations, or use unsuitable cryptographic elements. An attacker within range of a victim can still recover the password of the Wi-Fi network.  Gavin Millard, VP of Intelligence at Tenable, has provided the following comment on the vulnerabilities. Gavin Millard, VP of Intelligence at Tenable: “WPA3 hasn’t even been rolled out fully yet but, as is to be expected, there are numerous interested parties lined up ready to…

Read More

Increased Internet Regulations in The U.K.

ISBuzz TeamApril 13, 20194 Mins Read

Making the internet safer, especially for children and vulnerable individuals, is a decidedly noble pursuit. Doing so, however, would certainly be a considerable undertaking, and not without significant ethical, legal, and societal concerns. In an ambitious effort to make the internet a safer place for people to interact and communicate, the UK government has laid out an extensive framework for how it would go about executing its vision for a safer internet through increased regulations. These regulations would be aimed at companies that operate online and would require them to take responsibility for protecting their users from certain “online harms”…

Read More

Home Office Apologises For EU Citizen Data Breach

ISBuzz TeamApril 13, 20191 Min Read

The Home Office has apologised to hundreds of EU citizens seeking settled status in the UK after accidentally sharing their details.  It blamed an “administrative error” for sending an email that revealed 240 personal email addresses – a likely breach of the Data Protection Act.  The Home Office sent the email on Sunday 7 April asking applicants, who had already struggled with technical problems, to resubmit their information. But it failed to use the “blind CC” box on the email, revealing the details of other applicants.  https://twitter.com/LwFcmMGDs2MpVsZ/status/1116682924609421312 Expert Comments:  Shlohmie Liberow, Technical Program Manager at HackerOne:  “Whilst it is important to ensure staff are appropriately…

Read More

Office 365 Phishing Report Findings

ISBuzz TeamApril 13, 20192 Mins Read

Avanan’s report found that a quarter of phishing emails bypass default Office 365 security.   https://twitter.com/sikur/status/1009789323963699208 Dr. Simon Wiseman, CTO at Deep Secure:  While some vendors may jump on these results to point the finger at Office 365’s solution specifically, as a means of promoting their own detection solution, what this really shows is how cybercriminals tactics have become sophisticated to the point that they can completely circumvent ‘detect and protect’ cybersecurity solutions identify malware – in both phishing attacks and other attack vectors. Anti-virus, quarantine and sandboxing solutions can all be circumvented, whether that’s because threats lie dormant for a number of days until the…

Read More

‘MuddyWater’ APT Spotted Attacking Android

ISBuzz TeamApril 11, 20191 Min Read

It has been reported that a cyber espionage group believed to be out of Iran and known for targeting telecommunications providers and government bodies in the Middle East has added to its arsenal malware for targeting Android devices. The so-called MuddyWater hacking group, which has been in action since at least 2017, also has created new backdoor malware for spying on its targets, and has been spotted employing false flag tactics to throw off researchers and investigators, according to security researchers at Trend Micro, who here today shared the details of the Iranian hacking team’s latest activities.  Tom Davison, EMEA Director at Lookout: “This is another example of a potential…

Read More

Hacker Breached Minnesota State Agency E-mail, Placing Data Of 11,000 At Risk

ISBuzz TeamApril 11, 20192 Mins Read

This was reported by local Minneapolis news yesterday afternoon:    A data breach last year at the Minnesota agency that oversees the state’s health and welfare programs may have exposed the personal information of approximately 11,000 individuals. The state Department of Human Services (DHS) notified lawmakers Tuesday that an employee’s e-mail account was compromised as a result of a cyberattack on or about March 26, 2018. A hacker unlawfully logged into a state e-mail account of a DHS employee and used it to send two e-mails to one of the employee’s co-workers, asking that co-worker to pay an “invoice” by wiring money.…

Read More
Previous 1 … 381 382 383 384 385 … 1,258 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}