Information Security Buzz
  • HOME
  • Domains
    • Data Breach
    • Malware
    • Application Security
    • IoT
    • Cloud Security
    • Privacy
  • InfoSec Deals
  • Companies
  • Security Experts
  • ISB Conference 2021
  • Register
  • Log In
Top Posts
Expert Commentary On 30,000 Macs Infected With New...
Response Comment: Half Of Businesses Suffered A Cyber-Attack...
Expert Reaction On Google’s Password Checkup Feature Expanding...
Expert Comments On Secondary Extortion Attacks
Cybersecurity Expert Shares Top Takeaways Amid SolarWinds Hearing
Experts Reacted On Retail Giant Kroger Data Breach
Security A Glaring Issue For Chatroom App Clubhouse...
Parents Alerted To Nurserycam Security Breach – Experts...
How Can Consumers Better Protect Their Finances From...
Experts Insight On ‘Silent Stealing’ New Cyber Crime...
Information Security Buzz
Connecting Security Experts
  • HOME
  • Domains
    • Data Breach
    • Malware
    • Application Security
    • IoT
    • Cloud Security
    • Privacy
  • InfoSec Deals
  • Companies
  • Security Experts
  • ISB Conference 2021
  • Register
  • Log In
Expert(s): November 30, 2020
Jayant Shukla
CTO and co-founderfeature_status*/ ?>
K2 Cyber Security

Comments Dotted : 3
December 14, 2020

Security Expert Re: Critical Glassdoor Vulnerability Impacts Both Job Seekers And Employers

The discovery of a CSRF vulnerability in the Glassdoor site is a good reminder that CSRF remains a critical web application risk.
The discovery of a CSRF vulnerability in the Glassdoor site is a good reminder that CSRF remains a critical web application risk, and has appeared often on the OWASP Top 10 web application risks list. The fact that CSRF vulnerabilities continue to exist in web sites and applications like Glassdoor shows that not enough organizations test and protect their websites and applications against common web application vulnerabilities. NIST recently updated their SP800-53 Security and Privacy.....Read More
The discovery of a CSRF vulnerability in the Glassdoor site is a good reminder that CSRF remains a critical web application risk, and has appeared often on the OWASP Top 10 web application risks list. The fact that CSRF vulnerabilities continue to exist in web sites and applications like Glassdoor shows that not enough organizations test and protect their websites and applications against common web application vulnerabilities. NIST recently updated their SP800-53 Security and Privacy Framework to add focus on these issues by including RASP (Runtime Application Self-Protection) and IAST (Interactive Application Security Testing). These types of security solutions more effectively target the risks outlined by the current and past OWASP Top 10 lists.  Read Less
Like(0)  (0)

Linkedin Message

@Jayant Shukla, CTO and co-founder, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"The discovery of a CSRF vulnerability in the Glassdoor site is a good reminder that CSRF remains a critical web application risk...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/security-expert-re-critical-glassdoor-vulnerability-impacts-both-job-seekers-and-employers

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Jayant Shukla, CTO and co-founder, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"The discovery of a CSRF vulnerability in the Glassdoor site is a good reminder that CSRF remains a critical web application risk...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/security-expert-re-critical-glassdoor-vulnerability-impacts-both-job-seekers-and-employers

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.
October 21, 2020

NSA Warns Chinese State-sponsored Actors Are Exploiting Known Vulns – Security Expert Perspective

RASP solutions also protect the organization against new and unpatched vulnerabilities.
The new list of top 25 vulnerabilities being exploited by Chinese hacking is a great reminder that the easiest protection against cyber attacks is keeping your operating systems, applications, devices, and software patched and up to date. For organizations that can’t keep up to date or don’t have the resources to keep their software up to date, they should look into virtual patching solutions that protect the application, like the ones offered by RASP (Runtime Application Self-Protection).....Read More
The new list of top 25 vulnerabilities being exploited by Chinese hacking is a great reminder that the easiest protection against cyber attacks is keeping your operating systems, applications, devices, and software patched and up to date. For organizations that can’t keep up to date or don’t have the resources to keep their software up to date, they should look into virtual patching solutions that protect the application, like the ones offered by RASP (Runtime Application Self-Protection) solutions, which are now mandated by the latest version of the NIST SP800-53 Revision 5 Security and Privacy Framework. RASP solutions also protect the organization against new and unpatched vulnerabilities.  Read Less
Like(0)  (0)

Linkedin Message

@Jayant Shukla, CTO and co-founder, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"RASP solutions also protect the organization against new and unpatched vulnerabilities...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/nsa-warns-chinese-state-sponsored-actors-are-exploiting-known-vulns-security-expert-perspective

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Jayant Shukla, CTO and co-founder, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"RASP solutions also protect the organization against new and unpatched vulnerabilities...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/nsa-warns-chinese-state-sponsored-actors-are-exploiting-known-vulns-security-expert-perspective

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.
May 19, 2020

Industry Experts On Verizon DBiR 2020

Companies need to protect web applications that continue to have vulnerabilities that can be exploited.
The 2020 Verizon Breach Incident Report has a lot of good information, and reminds us that checking for malware on systems isn’t enough, as attacks via malware have decreased to only 6.5% of attacks and incidents (down from the peak near 50% in 2016). It’s a good reminder that organizations need to have security in place for phishing, preventing credential theft, and to protect web applications that continue to have vulnerabilities that can be exploited. The other big takeaway for.....Read More
The 2020 Verizon Breach Incident Report has a lot of good information, and reminds us that checking for malware on systems isn’t enough, as attacks via malware have decreased to only 6.5% of attacks and incidents (down from the peak near 50% in 2016). It’s a good reminder that organizations need to have security in place for phishing, preventing credential theft, and to protect web applications that continue to have vulnerabilities that can be exploited. The other big takeaway for organizations is that misconfiguration errors were a big gainer this year (called the best supporting action in the report). We often see at customer sites, where they patched a known vulnerability incorrectly or left it unpatched, leaving them vulnerable, and standard tools like WAF and EDR didn’t detect attacks on that vulnerability.  Read Less
Like(10)  (0)

Linkedin Message

@Jayant Shukla, CTO and co-founder, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Companies need to protect web applications that continue to have vulnerabilities that can be exploited...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/industry-experts-on-verizon-dbir-2020

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Jayant Shukla, CTO and co-founder, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Companies need to protect web applications that continue to have vulnerabilities that can be exploited...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/industry-experts-on-verizon-dbir-2020

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.

SECURELY DOTTED BY

David Kennefick, Solutions Architect, Edgescan

"Mac users are advised to update their operating systems and install an antivirus. "

Expert Commentary On 30,000 Macs Infected With New Silver Sparrow Malware

Lewis Jones, Threat Intelligence Analyst, Talion

"The Silver Sparrow malware comes with a mechanism to completely remove itself, which is usually utilised for high-stealth operations. "

Expert Commentary On 30,000 Macs Infected With New Silver Sparrow Malware

Amit Sharma, Security Engineer , Synopsys Software Integrity Group

"One of the most substantial security challenges organisations currently face is how to manage their legacy products. "

Experts Reacted On Retail Giant Kroger Data Breach

Chris Ross, SVP, Barracuda Networks

"Combatting the issue from a business perspective requires an overhaul of cybersecurity policy. "

Response Comment: Half Of Businesses Suffered A Cyber-Attack In Last 12 Months

Jake Moore, Cybersecurity Specialist, ESET

"Password checking tools are an essential part of account security. "

Expert Reaction On Google’s Password Checkup Feature Expanding For Android Users

Satnam Narang, Senior Research Engineer, Tenable

"Despite the exclusivity of Clubhouse being available on an invite-only basis and limited to iOS devices. "

Security A Glaring Issue For Chatroom App Clubhouse After Conversations Were Breached

Simon Mullis, Director of Technical Account Management, Tanium

"Simple steps can be put in place by any company that experiences a data breach to ensure it doesn’t happen again. "

Parents Alerted To Nurserycam Security Breach – Experts Comments

Stephen Kapp, CTO and Founder, Cortex Insight

"Organisations would be well-advised to embrace secure-by-design practices to avoid similar incidents. "

Parents Alerted To Nurserycam Security Breach – Experts Comments

Jonathan Reiber, Senior Director of Cybersecurity Strategy and Policy, AttackIQ

"ATT&CK provides an inventory for adversary tactics, techniques, and procedures that any organization can adopt. "

Cybersecurity Expert Shares Top Takeaways Amid SolarWinds Hearing

Jake Moore, Cybersecurity Specialist, ESET

"Similar to when Zoom usage went through the roof, Clubhouse is experiencing a huge uptake and learning as it goes. "

Security A Glaring Issue For Chatroom App Clubhouse After Conversations Were Breached

Nick Emanuel, Senior Director of Product , Webroot

"Clubhouse is currently riding a wave of popularity. "

Security A Glaring Issue For Chatroom App Clubhouse After Conversations Were Breached

Greg Foss, Senior Cybersecurity Strategist, VMware Carbon Black

"For opportunistic cybercriminals, secondary extortion is the name of the game. "

Expert Comments On Secondary Extortion Attacks

David Stewart, CEO, CriticalBlue - Approov

"You can't keep scripts and bots out of your business. "

Security A Glaring Issue For Chatroom App Clubhouse After Conversations Were Breached

Saryu Nayyar, CEO, Gurucul

"Unfortunately, cybersecurity is an afterthought for many developers. "

Security A Glaring Issue For Chatroom App Clubhouse After Conversations Were Breached

Martin Jartelius, CSO , Outpost24

"It’s been a month from becoming aware of the breach to this wider disclosure, but it seems it’s been hard to establish who has been affected at all. "

Experts Reacted On Retail Giant Kroger Data Breach

WORKING WITH US

About Us

Advertise With Us

Information Security Companies

Contact Us

ISB CONFERENCE

ISB Conference 2021

THE PAGES

Privacy Policy

Terms & Conditions

RSS Feeds

INFORMATION SECURITY EXPERTS

Information Security Experts: Comments Dotted

Register and Comments

Categories

  • Facebook
  • Twitter

Copyright © 2020 ISBuzz Pty Ltd is a company registered in Australia with company number 605 203 772 whose registered office is 14 Alanvale Street, Harrison, ACT 2914.


Back To Top
Information Security Buzz
  • Home
  • Experts Comments on News
  • Security Articles
  • Vendor News
  • Study & Research
  • ISBuzz Expert Panel