Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 423

ISBuzz Team

ISBuzz Team
  • Website

New Malware Families Discovered; Distributed Through Phishing Campaigns From The Necurs Botnet

ISBuzz TeamJanuary 15, 20192 Mins Read

It has been reported today that security researchers have discovered two new malware families distributed through phishing campaigns last year from the Necurs botnet: ServHelper backdoor with two variants and FlawedGrace remote access trojan (RAT). The threat actor continues to target organisations in the financial and retail sectors, the researchers say, using Microsoft Word, Microsoft Publisher, and PDF files pull the malware on the victim computer host. Experts comments below: Boris Cipot, Senior Engineer at Synopsys: “Backdoors and remote access Trojans distributed via botnet aren’t new concepts. Even though this type of attack vector is already well known, it still poses a real threat…

Read More

Multi-Purpose Attack Thingbots Threaten Internet Stability And Human Life

ISBuzz TeamJanuary 15, 20196 Mins Read

News F5 Labs research reveals IoT devices are now hackers’ No.1 target New research from F5 Labs has revealed that IoT devices are now cybercriminals’ top attack target, surpassing web and application services, and email servers. Gartner currently estimates that the number IoT devices will surge to 20,4 billion by 20201, which represents a staggering 143% growth rate over three years. “IoT devices already outnumber people and are multiplying at a rate that far outpaces global population growth. Increasingly, lax security control could endanger lives as, for example, cellular-connected IoT devices providing gateways to critical infrastructures are compromised,” said David…

Read More

Zurich Sued For $100 Million Following NotPetya Attack

ISBuzz TeamJanuary 12, 20192 Mins Read

Following the news that Mondelez, the US food company that owns the Oreo and Cadbury brands, is suing its insurance company, Zurich, for refusing to pay out on a $100m claim for damage caused by the NotPetya cyber attack, please see below comments from Igor Baikalov, chief scientist at Securonix. Igor Baikalov, Chief Scientist at Securonix: “Instead of a war exclusion clause, Zurich should have invoked a gross negligence clause, which is much easier to prove in this case than an attribution to a nation-state, particularly considering Mondelez was hit twice by the same ransomware. The “fool me once” proverb…

Read More

Unprotected MongoDB Exposes Over 200 Million Resumes

ISBuzz TeamJanuary 12, 20192 Mins Read

A huge MongoDB database containing over 200 million records with resumes from job seekers in China was left unprotected for at least one week with anyone able to locate it. The size of the cache weighed 854GB. The information exposed this way, 202,730,434 records in total, includes all the details one would expect to see in a resume: personal information (full name, date of birth, phone number, email address, civil status), professional experience and job expectations. Expert comments below: Jonathan Deveaux, Head of Enterprise Data Protection at Comforte: “In the case of this data breach, or data exposure, the unprotected data was open and available…

Read More

OXO Breach

ISBuzz TeamJanuary 12, 20194 Mins Read

OxoInternational, ahomeware, office supplies, and kitchen utensil manufacturer has disclosed a two-year long breach that exposed customer details in a Magecart like attacks. Experts comments below: Robert Capps, VP and Authentication Strategist at NuData Security: “Once data has been stolen, it’s used in a number of ways, including account takeover and identity fraud. More recently, we’ve seen a change in the value of stolen data as more and more intuitions are implementing user authentication solutions that render stolen data valueless. The loss of credit card data is a worry for all organisations, not just the targeted company. The data lost…

Read More

Security Experts Believe Skills Gap Can Be Bridged – Deloitte Disruption Index

ISBuzz TeamJanuary 11, 20192 Mins Read

Business leaders’ confidence in the digital skills of new entrants to the workplace has improved in the last six months, according to the latest Digital Disruption Index by Big Four accountant Deloitte. A growing number of business leaders think that school leavers and graduates have the right digital skills and experience, according to the new report. Experts comments below: Javvad Malik, Security Advocate at AlienVault: “The skills gap is tough to directly address because of the continued rate of digital change. The challenge for many companies is taking control of the rate and nature of change and mapping out a clear digital…

Read More

Orphaned Accounts: Did The Quora Hack Reveal Hidden Dangers?

ISBuzz TeamJanuary 11, 20193 Mins Read

From watching funny cat videos to checking the latest news, we are all familiar with the exchange of personal data (email address information, and the like) for services. But, could we be becoming dangerously complacent? Studies reveal that 57 per cent of British consumers are concerned about how much personal data they have previously shared online. Often, we’ve even lost track and are unsure of what we have shared, when we have shared it, and most crucially who we have shared it with. Concerningly, this uncertainty around data sharing and user accounts isn’t exclusive to consumers, it is common with…

Read More

Vietnam Says That Facebook Has Violated Controversial Cyber Security Law

ISBuzz TeamJanuary 11, 20191 Min Read

Facebook has violated Vietnam’s new cyber-security law by allowing users to post anti-government comments on the platform, the country’s state media said on Wednesday (Jan 9), days after the controversial legislation took effect in the communist-ruled country. Expert Comments below: Ilia Kolochenko, CEO at High-Tech Bridge: “The problem of many emerging cyber laws is that they may inadvertently, or even purposefully, impact the freedom of speech. Moreover, in developing countries, proper enforcement of such laws will be highly complicated, impractical and expensive both for social networks and the government.  Who will decide and under which standard what is permissible and…

Read More

NCSC Starts Campaign To Help Industry Fight Foreign State Threats

ISBuzz TeamJanuary 11, 20191 Min Read

It has been reported that the National Counterintelligence and Security Center (NCSC) has launched a program aimed at helping U.S. companies protect themselves from cyber-attacks or other threats from foreign nation-state actors. The NCSC is now sharing materials on how firms can guard themselves against threats to the supply chain — or components manufactured outside of the U.S. — spear-phishing campaigns and economic espionage, like the theft of intellectual property. Expert comments below: Paul Bischoff, Privacy Advocate at Comparitech: “Spear phishing, supply chain security, and social media deception are all real and growing risks to US enterprises, but I’m doubtful as to whether…

Read More

Bypassing 2-Factor Authentication

ISBuzz TeamJanuary 11, 20191 Min Read

Phishing attacks can be automated through a new penetration testing tool published by security researcher Piotr Duszyński. Modlishka is the name of the tool and it can bypass login operations for accounts protected by two-factor authentication (2FA). Don Duncan, Security Engineer at NuData Security: “While cybercriminals can get past two-factor authentication (2FA), this should only be one piece in the authentication stack and not the only one. This is why companies are using multi-layered authentication tools that can verify the legitimacy of a transaction from different angles. This way, if one of the layers is fooled by a bad actor, the…

Read More
Previous 1 … 421 422 423 424 425 … 1,258 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}