Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 422

ISBuzz Team

ISBuzz Team
  • Website

Iran Blamed For Global DNS Hijacking Campaign

ISBuzz TeamJanuary 17, 20192 Mins Read

Mandiant Incident Response and Intelligence teams have identified a wave of DNS hijacking that has affected dozens of domains belonging to government, telecommunications and internet infrastructure entities across the Middle East and North Africa, Europe and North America. Initial research suggests the actor or actors responsible have a nexus to Iran. This campaign has targeted victims across the globe on an almost unprecedented scale, with a high degree of success. Experts comments below: Craig Young, Computer Security Researcher at Tripwire: “From what I know of this wave of attacks, most of the hijackings have involved compromised credentials being used to directly manipulate DNS…

Read More

Vulnerabilities In Web Hosting Platform

ISBuzz TeamJanuary 17, 20191 Min Read

Bluehost, a popular web hosting platform, has been found to be riddled with vulnerabilities including one that would allow complete account takeover according to independent security researcher Paulos Yibelo. Expert Comments below: Mike Bittner, Digital Security and Operations Manager at The Media Trust: “By paying scant attention to security and privacy, web-hosting platform providers unknowingly enable bad actors to steal consumer information and commit fraud. This lax approach puts platform providers, their customers, and consumers at grave risk as consumer data privacy regulations around the world tighten on the one hand and attacks by malicious actors intensify on the other.…

Read More

Congress’ Stalemate Means The U.S. Will Remain Cybercriminals’ Prime Target

ISBuzz TeamJanuary 17, 20192 Mins Read

Experts comments below: Francis Dinha, CEO at OpenVPN: “With the government shutdown, our country’s cybersecurity is at risk — both in the short term and the long term. The immediate risk is, of course, a higher vulnerability to attack. Without a full support staff, those essential employees still working hard to maintain cybersecurity simply don’t have the resources they need. And while they’re no doubt incredibly skilled at their jobs — and passionate about their work — they’re still human, and expecting them to do the same, or more, work without the support they need is setting us all up for…

Read More

US Gov Shutdown & Cybersecurity

ISBuzz TeamJanuary 17, 20194 Mins Read

Security experts from Juniper Networks issued comments this afternoon about the impact of the US government shutdown, specifically citing how it may affect government IT recruiting and hiring: Nick Bilogorskiy, Cybersecurity Strategist at Juniper Networks: “The biggest impact of the shutdown, in my opinion, is that furloughing cybersecurity analysts creates a vulnerability for government networks. As we all know, the top problem in security today is the shortage of trained cybersecurity professionals, and the cybersecurity skills shortage was already getting worse in 2018 with millions of unfilled cybersecurity jobs. Now, with the shutdown and some staff furloughed, this problem is exacerbated. Attackers…

Read More

Lessons From Some Of The World’s Largest Data Breaches, And The Way Forward

ISBuzz TeamJanuary 16, 20197 Mins Read

“What I did 50 years ago is 4,000 times easier to do today because of technology,” says Frank Abagnale, 70-year-old FBI security consultant and former con man. His exploits as a check forger and impostor in the 1960s were showcased in the 2002 film Catch Me If You Can. Back then, it took a lot of preparation to complete a mission-based, malicious, and catastrophic attack. Today, while we may be better equipped to defend against attacks such as Abagnale’s that were far ahead of their time, we’re now worse off because of the number of vulnerable points a cybercriminal can…

Read More

Ransomware Attempts To Include PayPal Phish With Ransom Note

ISBuzz TeamJanuary 16, 20193 Mins Read

In an evolution of the usual infection, a new ransomware has beendiscoveredthat not only encrypts your files, but also tries to steal your PayPal credentials with an included phishing page. The ransomware itself is nothing special, but the ransom note is clever as it not only tries to steal your money through a normal bitcoin ransom payment, but also offers a choice to pay via PayPal. If a user choosesto pay using PayPal, they will be brought to a phishing site that will then attempt to steal the victim’s PayPal credentials. Expert Comments below: Corin Imai, Senior Security Advisor at DomainTools:…

Read More

Reddit Security Incident

ISBuzz TeamJanuary 15, 20192 Mins Read

Following the news that Reddit has locked user accounts whilst it investigates a potential security incident, Raj Samani, Chief Scientist and McAfee Fellow commented below. Raj Samani, Chief Scientist and McAfee: “Again, 330 million users find themselves grappling with the fact that hackers might have had the potential to access a treasure trove of their data, putting their privacy at risk. Whilst I command Reddit’s honesty and the precautions they are taking to lock accounts, I cannot stress enough that users themselves need to take steps to secure their personal security immediately. It is time for people to wake up to the real threat…

Read More

Sharing Geo-location Information

ISBuzz TeamJanuary 15, 20191 Min Read

An investigative report by Motherboard has uncovered how geo-location data frommobile carriers such as T-Mobile, Sprint and AT&T have been shared with third-party partners who sell the information to unauthorized entities not licensed to possess it. The story focused on a company known as Microbilt, that was found to sell geolocation information without regard to the buyers. Alex Calic, Strategic Technology Partnerships Officer at the Media Trust: “The Microbuilt approach is risky at best and these types of actions could lead to significant fines under new data privacy laws, not to mention puttingT-Mobile, Sprint and AT&T’s reputation at stake.Data scandals…

Read More

Google Search Results Listings Can Be Manipulated For Propaganda

ISBuzz TeamJanuary 15, 20192 Mins Read

The “knowledge panel” on Google’s search engine lets threat actors alter search results in a way that could be used to push political propaganda, oppressive views, or promote fake news. The “knowledge panel” is a box that usually appears at the right side of the search results, usually highlighting the main search result for a very specific query. Wietze Beukema, a member of PwC’s Cyber Threat Detection & Response team, has discovered that you can hijack these knowledge panels and add them to any search query, sometimes in a way that pushes legitimate search results way down the page, highlighting…

Read More

US Government Shutdown Leaves Its Sites With Expired TLS Certificates

ISBuzz TeamJanuary 15, 20192 Mins Read

It has been reported that following a partial U.S. government shutdown caused by a deadlock on the issue of the Mexican border wall between the Democratic Party and Donald Trump, tens of government websites can no longer be accessed or have been marked as using insecure connections because their TLS certificates have not been renewed. The websites of the U.S. Department of Justice, NASA, and the Court of Appeals are some of the ones hit by the government’s failure to extend around 80 TLS certificates used on .gov domains. Expired TLS Certificates can make individuals more susceptible to fraud and Identity theft.…

Read More
Previous 1 … 420 421 422 423 424 … 1,258 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}