Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 444

ISBuzz Team

ISBuzz Team
  • Website

The Vulnerabilities Of Hardware-Based Disk Encryption

ISBuzz TeamNovember 9, 20182 Mins Read

Bernard Parsons, CEO and Co-Founder of Becrypt:  The security and vulnerability of hardware-based disk encryption of solid-state drives (SSDs) has been forensically probed recently, as the relevance of data breaches continues to increase. Established thinking has pointed to the security offered by hardware-based encryption as being similar to, or superior than, software-based encryption methods. The current reality seems somewhat different, with some iterations of hardware models allowing for relatively easy access to encrypted data by attackers, through a variety of methods. Although full-disk encryption is typically the solution of choice for data at rest protection, software solutions can render devices susceptible…

Read More

Secret Service Warning Regarding USPS’s Mail Scanning Service

ISBuzz TeamNovember 9, 20181 Min Read

The Secret Service has issued a security warning regarding a new service being offered by the U.S Postal service that allows residents to view all scanned images of their mail before it is delivered. While Informed Delivery sounds like a great service, the Secret Service says identity thieves are already using it to steal credit cards and other information. Don Duncan, Security Engineer at NuData Security: “The government or other online companies should alert their customers when they sign up for a service such as Informed Deliver and also allow them to opt out easily if they want to. Customers…

Read More

US Cyber Command Starts Uploading Foreign APT Malware To Virus Total

ISBuzz TeamNovember 9, 20182 Mins Read

It’s been reported that The Cyber National Mission Force in the US is now uploading malware samples it finds to VirusTotal.  IT security experts commented below. Chris Doman, Threat Engineer at AlienVault: “The US Cyber Command has uploaded two malware samples relating to APT28, the Russian group behind the US election hacking. So far, the quantity has been small, but the quality is high. “Hopefully, these additions from the US Cyber Command will be another useful source of malware which will help the industry to defend against it. However, downloading files requires paid access to VirusTotal Enterprise, so this should…

Read More

Skyrocketing Healthcare Breaches And Why?

ISBuzz TeamNovember 8, 20182 Mins Read

4.4 million patient records were compromised in 117 healthcare data breaches in the third quarter of this year alone according to the Protenus Breach Barometer. Justin Jett, Director of Audit and Compliance at Plixer: “Data breaches in healthcare pose a serious risk not only for the organization but also for the patients. Should a hacker get this critical information, they can use it for insurance fraud which turns into a nightmare for the patient as there is no formal process for patients to correct their healthcare records and it could have serious impact if a patient needs a test or…

Read More

HSBC Data Breach And Credential Stuffing

ISBuzz TeamNovember 8, 20181 Min Read

What is the hacking technique known as ‘Credential Stuffing’? Hackers used data stolen from less secure sources to access HSBC customers’ bank accounts. Does this mean all our online profiles now need the same level of security as our online banking credentials? How can consumers really know which websites and connections are secure? Tim Callan, Senior Fellow at Sectigo: “Credential stuffing” attacks are an example of how broadly information theft can be exploited by sophisticated criminals.  Even seemingly innocuous personal details, stolen in a context that appears to be completely devoid of risk for critical information theft, can then be repurposed to gain inappropriate login access somewhere…

Read More

Sim Swap Fraud

ISBuzz TeamNovember 8, 20183 Mins Read

In response to today’s Krebs on Security story Busting SIM Swappers and SIM Swap Myths detailing this intricate type of mobile fraud and how one victim lost $100,000 when his mobile number was hijacked, mobile security experts with OneSpan offer information on how institutions can protect their customers from this threat. Will LaSala, Director Security Solutions, Security Evangelist at OneSpan: “Sim swap fraud is extremely dangerous. Users should be wary by now about using SMS as their primary form of two-factor authentication.  There are many well publicized problems with SMS as a two-factor solution.  From a financial institution standpoint, many have already started…

Read More

HSBC Security Incident – Customer Details Exposed

ISBuzz TeamNovember 7, 20186 Mins Read

News is breaking that banking giant HSBC disclosed a security incident exposing an undisclosed number of customers’ data. This is just the latest security incident reported by HSBC, which experienced DDoS attacks in January 2016 and July 2016, in addition to leaking customer data in April 2015 and March 2010. The security incident appears to fit the characteristics of a credential stuffing attack, also known as brute-force password-guessing attempts. This is when hackers try usernames and password combos leaked in a data breach at other companies. HSBC has confirmed that some of these attacks were successful, and attackers have gained…

Read More

New CHIME Healthcare Survey

ISBuzz TeamNovember 7, 20182 Mins Read

Leon Lerman, CEO of healthcare cybersecurity solution provider Cynerio, commented on the 2018 CHIME HealthCare’s Most Wired survey released last week, in which only 29 percent of healthcare organizations report having a comprehensive cybersecurity program in place. Leon Lerman, CEO at Cynerio: “CHIME HealthCare’s Most Wired survey stated that for most healthcare organizations, establishing a comprehensive cybersecurity program is a work in progress. The components of such a program include organizational aspects such as having a dedicated CISO or a board level committee that the cybersecurity team can report to. Other aspects of the program involve the reporting of security deficiencies, updates and progress. This requires…

Read More

University Researchers Discover Security Flaws In Widely Used Data Storage Devices

ISBuzz TeamNovember 7, 20181 Min Read

It has been reported that researchers at Radboud University in the Netherlands have today released a report detailing their discovery that widely used data storage devices with self-encrypting drives do not provide the expected level of data protection. Gary McGraw, Vice President of Security Technology at Synopsys: “Software design is difficult, especially when it comes to security.  Hardware security design suffers from many of the very same issues.  This design flaw with SSDs percolates up into common disk encryption schemes, showing that in some cases, the flip of a bit means everything.  Our only hope is better security engineering and architecture analysis during system design…

Read More

Magecart Claims Fresh Victim In Electronics Kit Seller Kitronik

ISBuzz TeamNovember 7, 20181 Min Read

Online tech retailer Kitronik said Friday it was the victim of Magecart’s payment card-skimming malware, and that the data breach that is the work of the same group which hacked British Airways and Newegg. Matan Or-El, CEO at Panorays: “Once hackers like Magecart find a technique that works, they will use it for every industry until the gig is up. This time it’s Javascript injection through third-party snippets. The call for action here is for organizations to put processes in place to manage and review their susceptibility to the Magecart threat through third parties. The wake-up call should have been…

Read More
Previous 1 … 442 443 444 445 446 … 1,258 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}