Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 764

ISBuzz Team

ISBuzz Team
  • Website

Webcam Maker Recalls Devices After Friday’s Internet Outage

ISBuzz TeamOctober 25, 20167 Mins Read

Chinese electronics firm Xiongmai is initiating a product recall after the enormous hacking attack that took down much of the internet on the eastcoast of the US and also affected Europe on Friday. The root of the attack, was a network of hacked “Internet of Things” devices, such as webcams and digital recorders, many of which were made by Xiongmai. IT security experts from  Redscan, ESET, AlienVault, prpl Foundation and NSFOCUS commented below. Robert Page, Lead Penetration Tester at Redscan: “In the interests of keeping up with competitors and making IoT devices easier to use, hardware manufacturers routinely compromise the security of customers. By…

Read More

What Really Happened In The OPM Breach

ISBuzz TeamOctober 25, 20163 Mins Read

In April 2015, 21.5 million Americans were affected by the breach of the Office of Personnel Management’s (OPM) systems which exposed over four million records of current and former government employees. But how did this happen? What can we learn from this when it comes to strengthening access security? According to the Committee on Oversight and Government Reform, there were five fundamental failures that contributed to the breach: The OPM failed to prioritise funding for cyber security; its $7 million security budget put them last when compared to other agencies. It lacked the effective leadership and managerial structure to implement…

Read More

Chinese Manufacturer Recalling IoT Webcams Blamed For DDoS Attack

ISBuzz TeamOctober 25, 20162 Mins Read

Following the news that, a Chinese manufacturing firm admitted its hacked DVRs and cameras were behind the attack and are now recalling their webcams, IT security experts from Cigital, Xively by LogMeIn and Tripwire commented below. Jim Ivers, CMO at Cigital: “This attack is illustrative of the problem with connected devices, specifically the ability to infiltrate, corrupt, and subsequently use these devices for malicious activity. Because computers are hardened and monitored, connected devices provide attackers a much easier path. Given that these devices have sufficient computing power, it is clear that once infiltrated attackers can use them the same way they would use a laptop. The…

Read More

Regulators Tell Big Banks To Toughen Cyber Security

ISBuzz TeamOctober 25, 20162 Mins Read

Following the news that Regulators tell big banks to toughen cyber security, Balázs Scheidler co-founder and CTO of BalaBit commented below. Balázs Scheidler, Co-Founder and CTO at BalaBit: “Tough regulations are coming to the financial sectors, requiring a recovery time of a maximum of two hours after a breach. In order to achieve these numbers, one needs a combination of two things: forensic grade monitoring in order to acquire information/details about the breach, and automation in how we provision and manage our systems. The first will give us the clue and background on the scope of the breach, the second…

Read More

IoT DDoS Attack On DYN

ISBuzz TeamOctober 25, 20162 Mins Read

Following the news of the DDoS attack on Dyn, Jeremiah Grossman, Chief of Security Strategy at SentinelOne and Mike Hanley, Director at Duo Labs commented below. Jeremiah Grossman, Chief of Security Strategy at SentinelOne:  “Because DNS is vital to every person, business and website across the entire internet for system stability and performance, online businesses commonly outsource DNS management to third-party providers who have better and more reliable infrastructures to operate on behalf of their customers. Historically, this has worked to everyone’s benefit. However, what we’re now seeing is that in light of the way the infrastructure works in the security landscape, they are attractive…

Read More

The DDoS Attack On Dyn – A Recap From Imperva

ISBuzz TeamOctober 24, 20167 Mins Read

DNS provider Dyn was knocked offline for much of the day, causing disruption to several well-known SaaS applications and internet sites, including Amazon, Twitter, GitHub and The Boston Globe. The company later that day confirmed that the cause was a large DDoS attack, and that it was an internet of things (IoT) attack using the newly-discovered Mirai botnet. The Imperva Incapsula product team has years of experience dealing with bots and DDoS attacks. Below is a summary of our relevant research and measurement. We have been watching the growth of IoT botnets – what we call “the botnet of things…

Read More

WiFi On Trains Could Leave Commuters Vulnerable To Hackers

ISBuzz TeamOctober 24, 20162 Mins Read

From 2017 free WiFi will be rolled out across a number of UK train operators, thanks to the Department for Transport’s £50 million initiative to increase WiFi on trains. Raj Samani, CTO EMEA at Intel Security: “While this will hugely benefit a number of commuters, who can work remotely during their journey to and from work, this also comes with significant security risks if the right precautions are not implemented,” A Freedom of Information Request (FOI) uncovered that the DfT “has not linked receiving funding for the on-train Wi-Fi with including a specific cyber security strategy.” While the department will…

Read More

Discord VoIP Chat Servers To Host Malware

ISBuzz TeamOctober 24, 20162 Mins Read

Following the news that Discord, a free VoIP service designed for gaming communities, has had its chat servers abused to host malware, Troy Gill, manager of security research at AppRiver commented below. Troy Gill, Manager of Security Research at AppRiver: “This is a case of attackers leveraging an existing services infrastructure to host and distribute their own malicious software. It appears that since the gaming community is the main consumer of this service, they are in turn the ones being targeted. However, this attack vector poses a risk to corporate networks as well given that it leads to a malware install…

Read More

‘Dirty Cow’ Linux Vulnerability

ISBuzz TeamOctober 24, 20162 Mins Read

What is ‘Dirty Cow’ Linux vulnerability and will it impact you. Black Duck’s open source software cybersecurity team of value explain it below. According to Tim MacKey, at Black Duck Software, which helps firms locate, manage and secure their open source software, Dirty COW is a marketing name given to CVE-2016-5195. It describes a bug which allows a malicious actor to increase their level of privilege in a Linux environment up to and including ‘root’. The bug itself is an exploitable race condition. A race condition occurs when two different threads of execution are able to modify the state of the program…

Read More

Huge DDoS Attack Brings Down Twitter, Spotify And AirBnB

ISBuzz TeamOctober 24, 20167 Mins Read

Following the news that Discord, a free VoIP service designed for gaming communities, has had its chat servers abused to host malware, security experts from MWR Infosecurity, Imperva, FireMon, Plixer, Synopsys and Tripwire  commented below. Adam Horsewood, Senior Security Consultant at MWR Infosecurity: “The attack on DYN could well be a form of advertising. DYN provide a DDOS defense service, protecting clients from the very same sort of attacks that they are now suffering. DDOS attacks can be provided as a service, allowing people to rent the ability to perform an attack with no upfront cost, or skill requirements.  Service providers…

Read More
Previous 1 … 762 763 764 765 766 … 1,258 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}