Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISBuzz Team - Page 841

ISBuzz Team

ISBuzz Team
  • Website

Weak Bank Password Policies leave 350 Million Vulnerable

ISBuzz TeamMarch 8, 20162 Mins Read

In a study that looked at the password strength required to access website account for Wells Fargo, Capital One and 15 other banks, researchers found that 35 percent had significant weaknesses in their password policies, according to University of New Haven Cyber Forensic Research and Education Group. The crux of UNH’s finding center around the fact all the banks in question had website password policies that do not differentiate between upper and lower-case letters. That, according to the study, is the difference between a “strong” password and a less secure password. Tim Erlin, director of security and product management at…

Read More

Hack the Pentagon Project

ISBuzz TeamMarch 8, 20162 Mins Read

Monzy Merza, chief security evangelist and director of cyber research at Splunk on the Hack the Pentagon project, which invites experts to hack into Pentagon systems to test its security defenses. [su_note note_color=”#ffffcc” text_color=”#00000″]Monzy Merza, Chief security Evangelist and Director of CyberResearch at Splunk: “The DoD already has mature red teams and offensive cyber capabilities. Bug bounty programs are fairly common in the technology industry. This DoD program will strengthen DoD deployments, exercise blue team capabilities, and shine a light on those who build the DoD’s Internet presence. Bug bounty programs typically pay for performance, thus this is a good precedent…

Read More

APT Targeting Indian Diplomatic and Military Resources

ISBuzz TeamMarch 8, 20162 Mins Read

Proofpoint discuss their recent discovery of a new Advanced Persistent Threat (APT) which is targeting Indian diplomatic and military resources. What initially appeared to be a relatively small email campaign sent to Indian embassies in Saudi Arabia and Kazakstan now appears connected to watering hole sites targeting Indian military personnel as well as other campaigns designed to drop a remote access Trojan (RAT), which Proofpoint has dubbed “MSIL/Crimson”. This RAT has a variety of data exfiltration functions, including screen capture and keylogging. [su_note note_color=”#ffffcc” text_color=”#00000″]Researchers at Proofpoint : Proofpoint has released a new paper around its discovery, which can be…

Read More

Cybersecurity Risk Becoming a Mainstay in Annual Audit Plans

ISBuzz TeamMarch 8, 20164 Mins Read

Tenth annual survey also explores evolution of internal auditing over the past decade According to Arriving at Internal Audit’s Tipping Point Amid Business Transformation, the 2016 Internal Audit Capabilities and Needs Survey report released by global consulting firm Protiviti, organisations are more likely than ever to evaluate cybersecurity risk as part of their annual audit plans. Nearly three out of four organisations (73 percent) now include cybersecurity risk in their internal audits, a 20 percent increase year-over-year. While there is a clear need among most internal audit groups to strengthen their ability to address cybersecurity risk, the survey found that…

Read More

Natwest Bank Accounts Raided through Stolen Phones

ISBuzz TeamMarch 8, 20163 Mins Read

Cybercriminals have been able to snatch thousands of pounds from Natwest bank accounts using stolen mobile phones. Natwest has admitted that a serious flaw in its online banking system has allowed criminals to raid accounts. Security experts from Tripwire, ESET and Proofpoint provide advice for users. [su_note note_color=”#ffffcc” text_color=”#00000″]Lamar Bailey, Sr. Director, Security R&D at Tripwire : “The popularity of mobile banking has made it easier for people to keep up with their finances and get alerts in almost real time when abnormalities occur but it has also had an adverse affect on security. Many mobile banking users have reduced…

Read More

Nokia Malware Report

ISBuzz TeamMarch 7, 20162 Mins Read

Nokia has released a report which shows that smartphones now account for 60% of infections in the mobile network with iOS-based malware appearing on the top 20 list for first time with XcodeGhost and FlexiSpy. Android malware more than doubled in last six months of 2015. Craig Young, cybersecurity researcher for Tripwire have the following comments on it. [su_note note_color=”#ffffcc” text_color=”#00000″]Craig Young, Cybersecurity Researcher at Tripwire : “The consolidation of personal data on smartphones has made them a natural target for malware campaigns.  While trusted app stores do a lot to reduce exposure to malware, examples of apps slipping past vendor…

Read More

IRS Warns of Nasty W-2 Phishing Scheme

ISBuzz TeamMarch 7, 20164 Mins Read

The news that the Internal Revenue Service has issued its second major warning about tax scams in a little over a month (this one involving a phishing email scheme that look a like a message from company executive requesting personal information from employees), Jon French, security analyst at AppRiver have the following comments on it. [su_note note_color=”#ffffcc” text_color=”#00000″]Jon French, Security Analyst at AppRiver: Is the spate of IRS scams and data breaches at the moment indicative of major failings at the institution? This current W-2 phishing problem isn’t indicative of any problems with the IRS I’d say (this time). This…

Read More

Security Challenges and Threats – Update 2016

ISBuzz TeamMarch 7, 20166 Mins Read

It was way back in 2011 when I spoke of the key security challenges on the CISO’s radar in the basic forms of: Malware The Insider Threat’s Phishing & Spam Complimented of course by other generic security challenges which appear on a daily basis. Way back in 2011 I did acknowledge that whilst these were nevertheless important in the overall scheme of the Security Mission, wondered if they did consume far too much interactive intervention and security bandwidth with responding to the manifestation of active compromise and security breaches – with much focus on the reactive, rather than the proactive.…

Read More

The SIP Security Fallacy

ISBuzz TeamMarch 7, 20166 Mins Read

There is no such thing as static security – all security products become vulnerable over time as the threat landscape evolves. Any ‘deploy once, update infrequently or never’ security solution is inherently flawed. Which is why every switched on organisation routinely updates its anti-virus and anti-malware solutions, hardens its infrastructure and updates its policies. So why is SIP security still based upon a one off implementation of a Session Border Controller (SBC)? From denial of service attacks to toll fraud, SIP trunking is inherently vulnerable. And in an era of near continuous security breaches, that vulnerability continues to change and…

Read More

What is Data Isolation & Why Does it Matter?

ISBuzz TeamMarch 7, 20163 Mins Read

Nearly one million new malware threats were released every day in 2014, with no signs of slowing down, according to Symantec’s Internet Security Threat Report. Malware, worms and other viruses can spread through a company’s network like wildfire. Getting your system and network back up and running only scratches the surface of expenses. Malware can cause data breaches and compromise customers’ security and hold you liable for damages. According to the 2015 Cost of Data Breach Study’s global analysis, the average total cost of a data breach for participating companies in the study increased 23 percent to $3.79 million. The…

Read More
Previous 1 … 839 840 841 842 843 … 1,258 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}