Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISB Editorial Staff - Page 27

ISB Editorial Staff

ISB Editorial Staff
  • Website

Expert Comments on Badlock Patches and Vulnerability

ISB Editorial StaffApril 15, 20162 Mins Read

Badlock was discovered by the Open Source Samba community and apparently underpins both Samba and Windows Server Message Block (SMB). The malware is significant, because it potentially allows privileged access to Windows and Samba resources through a flaw in the SMB protocol. Steve Donald, CTO at Hexis Commented below. Steve Donald, CTO at Hexis Cyber Solutions: “Its commendable that Microsoft and the Samba community got on top of the bug as soon as it was discovered, a positive benefit for the wider user community. However, one issue that needs investigation is whether or not the bug has been embedded into any of…

Read More

Another Scam Luring Facebook Users into Downloading Malware

ISB Editorial StaffApril 15, 20162 Mins Read

ESET researchers analysed a scam campaign on Facebook that spreads a malicious browser plugin via social engineering techniques. The attack starts by luring a Facebook user into playing a video, most often titled “My first video”, “My video” or “Private video”. After clicking on the link, the victims are directed to a fake YouTube website where, instead of downloading and playing the video, they are requested to install an additional extension: The extension is a malicious version of the otherwise legitimate “Make a GIF” plug-in. ESET detects this threat as JS/Kilim.SO and JS/Kilim.RG and users of ESET security products are protected from it. If the victims install the malicious plug-in,…

Read More

Expert Comments on GDPR Ratified by European Parliament

ISB Editorial StaffApril 15, 20164 Mins Read

Following the announcement that the GDPR has been ratified by the European Parliament, security experts from Micro Focus Thales and Netskope commented below. David Mount, Director Security Solutions, Micro Focus: “The GDPR is going to have a huge impact on any businesses operating in the European Union, and how they store and process data. Throughout the drafting and ratification of the legislation, some elements of the regulation have been more controversial than others and it is interesting to see which measures have made it into the final text. Perhaps one of the more controversial elements is mandatory data breach reporting, since under the GDPR companies…

Read More

What Everybody Should Know About Public Wi-Fi Security

ISB Editorial StaffApril 14, 20164 Mins Read

What could be better than sitting in your favorite café, sipping latte and browsing whatever the drama of the day is on Reddit? I’ll tell you – doing it securely! Although public Wi-Fi networks are useful for staying connected on the go, they’re also notorious for being easy for attackers to spy on and install various malware on your device. So, why are these networks so insecure? What are some of the common ways they get attacked and what can you do to keep yourself safe? Even though public Wi-Fi hotspots have been around since the early 2000s and people…

Read More

Carbon Black United Threat Research Report Reveals How Cyber Attackers Exploit Microsoft PowerShell to Launch Attacks

ISB Editorial StaffApril 14, 20163 Mins Read

Carbon Black®, a leader in Next-Generation Endpoint Security (NGES), today announced the results from its first Unified Threat Research report, which details how PowerShell, a scripting language inherent to Microsoft operating systems, is being exploited by threat actors to launch cyber attacks. The report outlines how the Carbon Black Threat Research Team, in conjunction with more than two dozen managed security services provider (MSSP) and incident response (IR) security partners, has increasingly seen PowerShell exploitation during cyber attacks, supporting a growing industry trend of malware authors creatively attempting to evade detection by exploiting native tools on operating systems. The report…

Read More

Team Effort: Working with Third-Party Partners to Achieve Effective PCI-DSS Compliance

ISB Editorial StaffApril 14, 20166 Mins Read

Every company in the UK that processes and stores customer payment information is ultimately responsible for its own compliance with regulations such as PCI-DSS (Payment Card Industry Data Security Standard). However, what many don’t realise is that they don’t have to go it alone. Outsourcing certain operational responsibilities to third-party experts can save significant time, money and resources, whilst also minimising the risk of a security data breach. But perhaps unsurprisingly, outsourcing comes with a number of unique challenges, meaning an effective due diligence programme must also be in place to ensure success. This article will discuss some of the…

Read More

Proofpoint Stops Impostor Emails with Industry’s Only Dynamic Fraud Protection

ISB Editorial StaffApril 14, 20162 Mins Read

New dynamic classification ensures organizations worldwide are quickly protected from socially-engineered impostor emails, also known as business email compromise (BEC) or CEO fraud Proofpoint, Inc., (NASDAQ: PFPT), a leading next-generation cybersecurity company, today announced the immediate availability of a new impostor email classification to help organizations stop fraudulent messages that trick employees into sending money and confidential information to cybercriminals. Added to the flagship Proofpoint Email Protection product, this dynamic classifier and quarantine functionality allows administrators to quickly see, report and stop this attack technique. According to the FBI, attackers used impostor emails to steal more than two billion dollars over the last…

Read More

High-Tech Bridge Launches Free Web Werver Security Testing Service

ISB Editorial StaffApril 14, 20162 Mins Read

The free online service will enable anyone to test a web server and its configuration for security and reliability based on cybersecurity industry best-practices. High-Tech Bridge, an award-winning web security company, has announced the addition of a webserver security test to its portfolio of free web security services. The new service performs the following security checks: – HTTP headers presence, validity and secure configuration – HTTP methods allowed by the web server – Web server version and other software-related tests Unlike other free services, High-Tech Bridge’s web server security test performs more sophisticated security testing. For example, HTTP headers will not just be tested…

Read More

The Accountability Gap: Cybersecurity and Building a Culture of Responsibility

ISB Editorial StaffApril 13, 20167 Mins Read

Business and government leaders grapple daily with innovation’s double-edged sword: as new technologies introduce unprecedented levels of efficiency, speed, and capability to the world, a new wave of cybersecurity risks immediately follow, threatening that very technology and the people who use it. In many instances, the technology organizations use to protect themselves has dramatically failed to keep pace with the speed and agility of modern threats, creating billions of dollars of damage from data breaches annually. But this is only half the story. Less visible is the widespread lack of personal and organizational accountability for the protection of a company’s…

Read More

Expert Comments on SQL Injection Discovered on Panamanian Lawyers’ Corporate System

ISB Editorial StaffApril 13, 20162 Mins Read

Following the news that an SQL injection has been discovered on one of the corporate systems of the Panamanian lawyers who leaked the Panama papers, Paul Farrington, senior solution architect at Veracode commented below: Paul Farrington, senior solution architect at Veracode “The panama papers hack at Mossack Fonseca proves that security breaches can trigger huge political and financial ramifications for companies, individuals and even Prime Ministers around the world. All major law firms hold large amounts of sensitive information and know the risks posed by hackers, so it’s unacceptable that despite the initial breach, the company has not fully secured its systems and remains…

Read More
Previous 1 … 25 26 27 28 29 … 41 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}