Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 440

ISBuzz Team

ISBuzz Team
  • Website

Russian Central Bank Targeted By Phishing Attack

ISBuzz TeamNovember 19, 20181 Min Read

Banks in Russia today were the target of a massive phishing campaign that aimed to deliver a tool used by the Silence group of hackers. The group is believed to have a background in legitimate infosec activities and access to documentation specific to the financial sector. The fraudulent emails purported to come from the Central Bank of Russia (CBR) and contained a malicious attachment. The message body lured the recipients to open the attachment in order to check the latest details on the “standardization of the format of CBR’s electronic communications.” Corin Imai, Senior Security Advisor at DomainTools: “This is an example of a phishing campaign at its…

Read More

More NHS Cyber Attacks Are ‘Inevitable’

ISBuzz TeamNovember 19, 20182 Mins Read

Following the news that some experts have warned that further cyber-attacks on the NHS are ‘inevitable’. Jake Moore, Cyber Security Specialist at ESET UK: “For an organisation like the NHS, keeping your entire systems safe and secure is not an easy task. For most companies it’s a simple case of funds & resource, but sadly in this case it’s not that easy. However it’s not all bad – knowing you need to do more and actively working towards it is a plus. We often hear tales of “attacks” on the NHS, but we need to understand that outbreaks like WannaCry were not direct attacks,…

Read More

Card Fraud On The Rise, Despite National EMV Adoption

ISBuzz TeamNovember 19, 20181 Min Read

A recent report by Gemini Advisory has revealed, three years after the US EMV migration deadline passed, card fraud has continued to rise. Of more than 60 million payment cards stolen in the past 12 months, chip-enabled cards represented a staggering 93%. These results directly reflect the lack of US merchant compliance with the EMV implementation. Simon Armstrong, VP Products at Entersekt: “In the payments space there will always be an arms race between the groups providing and implementing payment systems against those who seek to find vulnerabilities to exploit. The statistics shown here can be seen as evidence that the rate of adoption of new security mechanisms by issuers and merchants is…

Read More

Companies Faltering On Managing 3rd Party Risk

ISBuzz TeamNovember 19, 20182 Mins Read

A new report* by the Opus and the Ponemon Institute reveals that 61 percent of US companies surveyed said they have experienced a data breach caused by one of their vendors or third parties. What is even more alarming is that 22 percent of respondents admitted they didn’t know if they’d had a third-party data breach in the past 12 months and only 37 percent indicate that they have sufficient resources to manage third-party relationships. Chris Olson, CEO at The Media Trust: “Consumer data is money and companies in general have lots of it. That data is also increasingly vulnerable to misuse…

Read More

Voxox Database Misconfiguration Exposes 26M SMS Messages

ISBuzz TeamNovember 19, 20184 Mins Read

The news broke yesterday that Voxox, a San Diego, California-based communications provider, left a database containing at least 26 million text messages, including password reset links, 2FA codes, shipping notifications and more exposed without a password. The exposure to personal information, phone numbers and 2FA codes in near-real-time could have put countless accounts at risk of hijack. Some websites only require a phone number to reset an account to meaning that this process could take just seconds. IT security experts commented below. Jacob Serpa, Product Marketing Manager at Bitglass: “It does not take much for outsiders to find unsecured databases and access…

Read More

Japan’s Cybersecurity Minister Admits He’s ‘Never Used A Computer’

ISBuzz TeamNovember 16, 20182 Mins Read

Japan’s new cybersecurity minister has ‘never used a computer’–claiming to have delegated to staff and secretaries since he was 25. This is especially interesting because his duties include overseeing cyber-defense preparations for the 2020 Olympic Games in Tokyo. In addition, Sakurada allegedly struggled to answer a follow-up question about whether USB drives were in use at the country’s nuclear power stations. With the total cost of cybercrime committed expected to cost global businesses over $2 trillion by 2019, this revelation has raised concern, and the impact could weigh on Japan’s state of cybersecurity. Two cybersecurity experts have commented on the incident below.…

Read More

Nordstrom Data Breach

ISBuzz TeamNovember 15, 20181 Min Read

Following the news that that high-end retailer Nordstrom is in the process of notifying its employees their data may have been compromised in a breach, please see below comments from Martin Jartelius, CSO of Outpost24. Martin Jartelius, CSO at Outpost24: “It looks like this incident relates to a contractor unintentionally, or intentionally, incorrectly handling confidential employee information. This highlights the need for organisations to treat all employees as a potential risk and ensure security steps are taken to minimise the risks when incidents like these happen. There is also a considerable amount of time which has passed from the detection…

Read More

French Film Company Pathe Loses €19m In BEC Scams

ISBuzz TeamNovember 15, 20182 Mins Read

The Dutch branch of the French film production and distribution company Pathé has lost over 19 million euros to BEC scammers, Dutch News reported. Information about how the scammers pulled it off has been gleaned from court documents relating to an unfair dismissal lawsuit brought against Pathé France by Edwin Slutter, the Dutch branch’s former chief financial officer. Commenting on the news and offering advice are the following security professionals: Javvad Malik, Security Advocate at AlienVault: BEC or CEO scams are very common tactics used by criminals. Because there is no malware, it relies purely on tricking the recipient. Therefore, employees should receive training in…

Read More

Researchers Reveal Seven New Spectre And Meltdown Attacks

ISBuzz TeamNovember 15, 20181 Min Read

In response to the news that a team of nine academics has revealed today seven new CPU attacks, which are variations on Meltdown and impact AMD, ARM, and Intel CPUs to various degrees, please see below comments from Cody Brocious, researcher at HackerOne. Cody Brocious, Researcher at HackerOne: “As long as speculative execution is performed in processors, this type of bug will continue to be discovered.  It’s impossible to perform operations without side-effects on a hardware level, and abstractions that pretend such operations are side-effect-free and always going to cause security issues.”

Read More

How To Keep Shadow IT From Costing You In The GDPR Era

ISBuzz TeamNovember 15, 20185 Mins Read

Shadow IT — the use of IT systems within an organization without the knowledge or approval of corporate IT — has long been an issue for businesses across industries. From risking the unauthorized leaking of proprietary information to exposing unintended attack vectors to hackers, shadow IT can subvert the efforts of an IT department to keep a company’s systems secure. Now, with the newly imposed regulations of General Data Protection Regulation (GDPR) and more legislation on the horizon, the fallout of an uncontrolled shadow poses an even greater risk — fines up to four percent of a businesses’ revenue in…

Read More
Previous 1 … 438 439 440 441 442 … 1,258 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}