Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 418

ISBuzz Team

ISBuzz Team
  • Website

WordPress PlugIn Was Hacked By Former Employee

ISBuzz TeamJanuary 23, 20192 Mins Read

In a serious case of insider threat, CyberScoop reported that the website of popular WordPress plugin WPML had a former employee exploit an old password and a hidden vulnerability the employee previously inserted into the site to gain access after leaving the company. The employee appeared to use his access to post a message on a website and spam the same message to WPML clients. https://twitter.com/experttheme01/status/1087985706385985537 WPML said the incident caused it to lose client data, forced it to rebuild its server from scratch and prompted it to reset all customers’ passwords. OnTheGoSystems said that the plugin itself was not vulnerable and…

Read More

So, You Wanna Be A Security Star?

ISBuzz TeamJanuary 23, 201916 Mins Read

Well, here’s where you can start and learn the ropes. There are over 350,000 security analyst job openings currently available and many have starting salaries in the six-digits. On top of that, organizations are struggling to find good security analysts due to the shortage of cybersecurity skills. And that will continue to be the case in the coming years. There could be a 1.8 million cybersecurity talent shortage by 2022. (1) So what’s the deal? Why is this happening? Many reasons but most of all, we’re human. We are creative, social beings that need to grow, learn, evolve and have a…

Read More

Five Top Tips For Small Businesses Adopting Encryption

ISBuzz TeamJanuary 22, 20197 Mins Read

Becrypt has been in the disk encryption business for more than 15 years and have carried out extensive work with governments and large enterprises. Today, a lot of what we’re doing is working with small businesses, typically organisations that are looking at adding encryption for the first time, driven by regulation such as GDPR, and those that require encryption as part of the privacy enforcing mechanisms. Based on the experience and feedback that Becrypt has attained, I have summarised the top-five issues that small businesses should think about if they are looking at adopting disk encryption, or if they’re looking…

Read More

Experts Comments On First GDPR Fine Of $57 Million To Google

ISBuzz TeamJanuary 22, 20196 Mins Read

CNIL, the French data protection watchdog, issued its first GDPR fine of $57 million to Google, claiming that they failed to comply with GDPR when new Android users set up a new phone and follow Android’s onboarding process. https://twitter.com/damase/status/1087624060891205632 Experts Comments Below: Anurag Kahol, CTO and Co-founder at Bitglass: “Google being fined for its noncompliance with GDPR will likely pave the way for penalties for other prolific companies that have not yet met the demands of the new law. Until this point, data protection authorities have been incredibly patient with companies – GDPR has been in full effect for nearly a…

Read More

Companies Can Safely Delay Patching The Majority Of Their Vulnerabilities, Kenna Security Report Finds

ISBuzz TeamJanuary 22, 20195 Mins Read

Research conducted by Kenna Security and Cyentia Institute demonstrates companies can be smarter and more efficient in their security efforts  “In our ongoing mission to apply the tenets of data science to cybersecurity, we have begun to benchmark the realities of vulnerability remediation strategies. We’ve found that remediating the riskiest vulnerabilities is within reach for many organizations. Despite recent high-profile data breaches, our findings show that enterprises can and should delay efforts to remediate a majority of vulnerabilities, which often number in the millions. Most vulnerabilities pose little to no danger of being exploited. That means companies can prioritize their…

Read More

108M Records Exposed via Misconfigured ElasticSearch Server

ISBuzz TeamJanuary 22, 20194 Mins Read

ZDNet reported that a password-less ElasticSearch server belonging to a variety of online casinos has compromised the information on over 108 million bets, including customers’ payment card info, full names, home addresses, phone numbers, email addresses, birth dates, site usernames, account balances, IP addresses, browser and OS details, last login information and more. The payment card details indexed in the server were partially redacted however, meaning that they were not exposing each user’s full financial details. The leaky server was found last week and was just taken offline today and is not accessible anymore. https://twitter.com/ZDNet/status/1050386922449731586 https://twitter.com/AIESEC/status/1087491892839940098 Experts Comments Below: Mark Weiner,…

Read More

Brexit May Mean Shortage Of Cyber Talent – We Should Be Looking To Our Own Students

ISBuzz TeamJanuary 21, 20192 Mins Read

Following Theresa May’s defeat in Parliament earlier in the week, the Brexit process looks to be in a state of confusion. With that confusion comes the question of how the cybersecurity industry in the UK will keep its reputation of a world-class workforce when visas and potentially employees not wishing to stay in the UK comes to pass. https://twitter.com/advantexuk/status/1083358549844078592 James Lyne, Head of Research and Development at SANS Institute, and creator of the Cyber Discovery programme, believe that we should be doing far more to nurture homegrown cybersecurity talent in the UK – as it may be the only way…

Read More

BlackRouter Ransomware Promoted As A RaaS By Iranian Developers

ISBuzz TeamJanuary 21, 20192 Mins Read

Ransomware called BlackRouter has been discovered being promoted as a Ransomware-as-a-Service on Telegram by an Iranian developer. This same actor previously distributed another ransomware called Blackheart and promotes other infections such as a RAT. BlackRouter was originally spotted in May 2018 and had its moment of fame when TrendMicro discovered it dropping the AnyDesk remote access program and keyloggers on victim’s computers. https://twitter.com/samh5621/status/1087031297967566850 https://twitter.com/shah_sheikh/status/1087253852569518080 Israel Barak, CISO at Cybereason: “Ransomware is one of the most effective and successful forms of cybercrime, yet attacks have slowed considerably in the past few years. But as long hackers find it simple to construct and deploy, it will be a low-risk,…

Read More

Implications Of No-Deal Brexit On Cross-Border Data Flow

ISBuzz TeamJanuary 21, 20192 Mins Read

Elizabeth Denham, Information Commissioner, has advised businesses to consider “alternative data transfer mechanisms” in the event of a no-deal Brexit, which might have implications on cross-border data flow. https://twitter.com/pyxiGDPRteam/status/1084903868163547136 Ian Smith, founder and CEO of Gospel Technology commented below, whose data security platform harnesses permissioned DLT to allow organisations to securely share critical data with third parties outside their perimeter of control. Ian Smith, CEO at Gospel Technology: Whatever the outcome of the Brexit negotiation, it’s crucial to the ongoing relationship between the UK and its European counterparts that information is able to move across borders seamlessly and securely. If the UK ends…

Read More

Android ES File Explorer Vulnerability Exposes All User Data To Attackers On The Same Network

ISBuzz TeamJanuary 21, 20191 Min Read

A serious vulnerability in a popular Android file has been discovered and exposes all the user’s data to attackers on the same network. In essence, the victim would only need to open the app once. This bug was found by researching Elliot Alderson, who posted about it on Twitter. Expert Comments below: Craig Young, Security Researcher at Tripwire: “The ES File Explorer ‘Open Port’ vulnerability is far more serious than originally reported. The truth is that attackers do not need to be on the same network as the victim phone thanks to DNS rebinding. With this attack model, a web site loaded on…

Read More
Previous 1 … 416 417 418 419 420 … 1,258 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}