Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISB Editorial Staff - Page 5

ISB Editorial Staff

ISB Editorial Staff
  • Website

Expert Advice on Attackers bypassing Microsoft RDP

ISB Editorial StaffJune 5, 20194 Mins Read

On June 4, 2019, the CERT Coordination Centre (CERT/CC) Carnegie Mellon’s Computer Emergency Response Team released an advisory regarding discovered behaviour in the Microsoft Windows Remote Desktop Protocol (RDP), which can allow an attacker to bypass the lock screen on some remote sessions. Microsoft was notified of this finding and has stated that the “behaviour does not meet the Microsoft Security Servicing Criteria for Windows,” meaning there will be no patch available at least for the time being. It is understandable that many organisations still scrambling to ensure their systems are not vulnerable to the recent (“BlueKeep”RDP wormable vulnerability) would not be…

Read More

IMAP Attacks

ISB Editorial StaffMarch 18, 20192 Mins Read

Cybercriminals are leveraging Internet Message Access Protocol (IMAP) for password-spray attacks to compromise cloud-based accounts according to Proofpoint. Justin Jett, Director of Audit and Compliance at Plixer: “Password-spraying attacks are extremely dangerous because they often allow hackers to brute force attacks without being locked out or triggering an alert to the IT team. Two-factor authentication inherently can’t work with IMAP, and so it is automatically bypassed when authenticating. Additionally, IT teams should be sure they have network traffic analytics enabled across their network to spot credential misuse. Because password-spraying attacks don’t generate an alarm or lock out a user account,…

Read More

Another short blog for Christmas

ISB Editorial StaffDecember 20, 20181 Min Read

Given it is again that time of the year when we may be giving, and/or receiving gifts, we will be mentally tuned to anticipation of a gift arriving in the post, and as such our guard may be down. To that end, those Cyber Criminals and other such persistent threat actors also see the season of good will as an increased opportunity to just keep on giving, which is why I guess I am seeing a higher volume than usual of unsolicited communications arriving in my inbox to inform me that I may track my package, or that I need…

Read More

Publicly Available Tools Seen in Cyber Incidents Worldwide

ISB Editorial StaffOctober 15, 20183 Mins Read

According to the US-CERT, tools and techniques for exploiting networks and the data they hold are by no means the preserve of nation states or criminals on the dark web. Today, malicious tools with a variety of functions are widely and freely available for use by everyone from skilled penetration testers, hostile state actors and organised criminals, to amateur cyber criminals. Commenting on this, Ross Rustici, senior director, threat intelligence at Cybereason, said “This report is like a greatest hits album for a struggling record company. Everything is old, well known, and generally elicits a sense of nostalgia mixed with loathing. Mimikatz, the the elder…

Read More

Industry Leaders Reaction on Recent Facebook Hack

ISB Editorial StaffSeptember 29, 201815 Mins Read

It is being reported that Facebook said an attack on its computer network led to the exposure of information from nearly 50 million of its users. The company discovered the breach earlier this week, finding that attackers had exploited a feature in Facebook’s code that allowed them to take over user accounts. Facebook fixed the vulnerability and notified law enforcement officials. More than 90 million of Facebook’s users were forced to log out of their accounts Friday morning, a common safety measure for compromised accounts. Facebook said it did not know the origin or identity of the attackers, nor had it fully assessed the scope of the attack. The company…

Read More

How can I secure my IoT devices at home and at work?

ISB Editorial StaffJune 1, 20183 Mins Read

With every day that goes by more IoT (Internet of Things) devices are becoming a part of our normal everyday life both at home and on the job. In recent years it has become evident that IoT devices pose a security risk for any network. While IoT manufacturers are working diligently to make things more convenient for us, privacy and security have been overlooked. Leaving these devices unsecured is like leaving your door closed but unlocked. It might look secure, but it is actually easy to open. Gartner research estimates that there will be over 20 billion connected IoT devices…

Read More

Tulin’s CyberSec Talk – Privacy By Design

ISB Editorial StaffMay 25, 20181 Min Read

This is second video of Tulin’s CyberSec Talk series. In this video, Tulin discusses the seven foundation principles of Privacy by Design. These principles are: Principle 1: Proactive and not reactive Principle 2: Privacy as the default setting Principle 3: Privacy embedded into design Principle 4: Full functionality: positive-sum, not zero-sum Principle 5: End to end security: full lifecycle protection Principle 6: Visibility and transparency Principle 7: Respect for user privacy. [su_youtube url=”https://youtu.be/c2apEJnpKL8″] [su_spacer]

Read More

Fines and Penalties in GDPR Per Articles

ISB Editorial StaffMay 21, 20182 Mins Read

The GDPR (General Data Protection Regulation) is designed to protect the privacy of all EU citizens and this will change the way the organizations store and use EU citizens’ data. Failure to meet the requirements of GDPR could also turn out to be an expensive expense. Here is summary of the penalty as it applied to articles in GDPR. Penalty: Maximum penalty up to 4% of annual global turnover or €20 million, whichever is greater Articles in GDPR: 5 – Principles relating to processing of personal data 6 – Lawfulness of processing 7 – Conditions for consent 9 – Processing…

Read More

NHS ransomware attack update – Patch available for XP and other custom support platforms

ISB Editorial StaffMay 13, 20173 Mins Read

Microsoft has been working to issue patches in light of the large scale ransomware attack that affected some 99 countries yesterday.  Blog here: https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/ Commenting on the move is security expert Andrew Clarke, EMEA director for One Identity: “This is an unusual move by Microsoft and serves to demonstrate the seriousness of this type of attack.  In an update blog Microsoft declared, “Given the potential impact to customers and their businesses, we made the decision to make the Security Update for platforms in custom support only, Windows XP, Windows 8, and Windows Server 2003.”   IT teams with these type of…

Read More

Security Challenges in Next Generation 5G Mobile Networks

ISB Editorial StaffApril 6, 20174 Mins Read

5G technology is the next step in the development of mobile communication. 5G will not only provide voice and data communication but also provide capabilities for new technologies such as Internet of Things. 5G is no longer confined to provide faster mobile services for voice and data communication but instead it will serve vertical industries, which will foster a new form of services. The new networking technologies such as such as Software Defined Network (SDN)/Network Functions Virtualisation (NFV) will further enhance the 5G capability to provide an effective platform for new services/businesses to flourish. These new technologies also bring new…

Read More
Previous 1 … 3 4 5 6 7 … 41 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}