Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 471

ISBuzz Team

ISBuzz Team
  • Website

Hakai IoT Botnet Hits D-Link, Huawei, Realtek, Includes Efficient Telnet Scanner

ISBuzz TeamSeptember 6, 20181 Min Read

In response to reports that a New Hakai IoT botnet is taking aim at D-Link, Huawei, and Realtek routers  (link to ZDNet interview with researcher Ankit Anubhav) and that the malware includes efficient Telnet scanner, an expert with Corero Network Security offers perspective. Sean Newman, Director Product Management at Corero Network Security: “It’s possibly no coincidence that, within a matter of weeks of the alleged creator of last year’s infamous Satori botnet being indicted, its likely successor, Hakai, appears to be ramping up.  With Hakai now gaining exploits for some of the same IoT devices previously the domain of Satori, it gives the sense…

Read More

Nearly 3 Million Phishing Incidents Since January In Japan

ISBuzz TeamSeptember 6, 20181 Min Read

It’s being reported that a record 2.9 million people in Japan have been directed through phishing emails to fake websites created to steal sensitive information in the first half of this year. The report by Trend Micro Inc. released Monday said such fraudulent attempts are increasingly aimed at stealing accounts used for shopping, communication and other services with major firms such as Apple Inc., Amazon.com Inc., Rakuten Inc. and Line Corp. Corin Imai, Senior Product Manager at DomainTools: “The fact that close to 3 million people were compromised should be an indicator of how easy it is to mimic credible emails. Bad actors are…

Read More

“Five Eyes” Nations Demand Tech Companies Provide Encryption Backdoors

ISBuzz TeamSeptember 6, 20181 Min Read

Last week, a statement was issued last week by the “Five Eyes” nations – United States, Britain, Australia, New Zealand and Canada – demanding tech companies provide  ‘lawful access’ to encrypted digital content and promising compelled compliance if companies refuse to provide it. An expert with Juniper Networks offers perspective on the demand and the ongoing issue of encryption backdoors. Nick Bilogorskiy, Cybersecurity Strategist at Juniper Networks: “You can’t have a backdoor that’s only for the good guys. Once the encryption protocol has been handicapped and a door has been opened, other bad actors – from hackers to foreign governments – will walk through that…

Read More

Lloyds Debit Card Glitch – Expert Analyses The Latest String Of Software Glitches

ISBuzz TeamSeptember 6, 20182 Mins Read

Thousands of UK consumers were charged twice for debit card payments as a glitch occured in the card terminal run by Cardnet, a joint venture between Lloyds Bank and First Data. This is only latest IT glitch in a very long list: TSB, M&S, Gatwick, recurring NHS glitches to name but a few of the Software glitches affecting customers, travellers and patients in the past three months. CAST, the software intelligence company, is helping financial services organisations such as Fannie Mae, Telefonica, Credit Suisse and ING have reliable and resilient software. Experts at CAST are dedicated to improving Software quality, resilience and security. Lev Lesokhin, EVP of…

Read More

Compliance Challenges With New NY And CO Cybersecurity Laws

ISBuzz TeamSeptember 5, 20182 Mins Read

Complicating the challenges of complying with GDPR and the new CA data privacy law, two additional state cybersecurity laws in NY and CO went into effect over Labor Day weekend.  In particular, the NY State 23 NYCRR 500 Law now requires companies to encrypt non-public info at both rest and in transit. What does this mean for companies doing business in these states?  According to Pravin Kothari, CEO of cloud security vendor CipherCloud: Pravin Kothari, CEO at CipherCloud: “The trend in data privacy and cyber related compliance is not your friend right now or anytime soon. The web of cyber data privacy laws…

Read More

Parental Control Spyware App Family Orbit Hacked, Thousands Of Child Photos Exposed

ISBuzz TeamSeptember 5, 20182 Mins Read

It has been reported that the company that sells the parental control spyware app Family Orbit has been hacked, and the pictures of hundreds of monitored children were left online only protected by a password. According to Motherboard that first reported the news, the Family Orbit spyware left exposed nearly 281 GB of data online. The hacker discovered the huge trove of data that was stored on an unsecured server and reported the discovery to Motherboard. The hacker found the key on the cloud servers of the spyware app. Robert Capps, Vice President at NuData Security: “This is yet another example of the difficulty we…

Read More

Brian Krebs Reports Mobile Spyware Maker mSpy Leaks Millions Of Sensitive Records

ISBuzz TeamSeptember 5, 20182 Mins Read

Brian Krebs reported today that mSpy, the maker of a software-as-a-service product that helps customers spy on the mobile devices of their kids and partners, left an open database on the web that provided access to millions of sensitive records without any authentication required. Pravin Kothari, CEO at CipherCloud: BACKGROUND “mSpy, the provider of a leading parental control application for smartphones, suffered from data exposure when a database was wide open and accessible.  This exposure included the transactions and identity of users that purchased mSpy licenses over the last six months or logged into the mSpy website. This database includes millions…

Read More

Camubot Malware Camouflaged As Bank Security App To Steal Credentials

ISBuzz TeamSeptember 5, 20182 Mins Read

It has been reported that a new banking malware has been discovered that is targeting bank customers in Brazil. Dubbed CamuBot, it is said to be a unique malware because it is disguised as a necessary security module of the bank. The malware can also bypass the biometric authentication feature, which is a disturbing sign. According to IBM X-Force researchers who discovered the malware, previously discovered banking malware and Trojans worked differently. These were designed to steal online credentials by getting deployed on targeted machines and used complex stealth methods to evade detection. However, CamuBot takes a 360-degree turn in the way banking malware work by camouflaging itself…

Read More

New “Cronix” Crytpo Mining Campaign

ISBuzz TeamSeptember 5, 20181 Min Read

F5 Labs just detected a new Monero crypto mining campaign that exploits the latest Apache Struts 2 critical RCE vulnerability. Responsibly disclosed just two weeks ago by Semmle, known threat actors weaponized a PoC exploit published on GitHub and are currently exploiting the vulnerability to deploy “xmrigCC” crypto-miner. Of note, just a year and a half ago, Equifax was hit via a similar vulnerability on its Apache Struts 2 servers (CVE-2017-5638). Key features of the campaign include: CVE-2018-11776 Apache Struts 2 namespace vulnerability allows unauthenticated remote code execution. In this Monero crypto-mining campaign, the injection point is within the URL.…

Read More

Data Breach Reports To The ICO Increase By 75%

ISBuzz TeamSeptember 5, 20183 Mins Read

It has been revealed that data breaches are up 75% in two years, finds a report from the Information Commissioner (ICO). The report, which used data gathered under the Freedom of Information Act, found most data breach cases to be applicable to human error in some way. Offering insight are the following security experts: Bob Egner, VP at Outpost24: “This level of increase comes as no surprise, and correlates well with the security practices we encounter when working with our clients.  The most secure companies we work with today have put a clear focus on creating a “culture of security awareness” that…

Read More
Previous 1 … 469 470 471 472 473 … 1,258 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}