Latest Posts

76e662e7786bf88946bd6c010c03ac65

Resilience ‒ The way to Survive a Cyber Attack

May 07, 2013 Added by:Jarno Limnéll

In reality, a well-prepared cyber attack does not need to last for 15 minutes to succeed. After preparations it takes only seconds to conduct the attack which may hit targets next door as well as those on the other side of the world.

Comments  (0)

Ffc4103a877b409fd8d6da8f854f617e

Pentagon Ups Cyber Espionage Accusations Against China

May 07, 2013 Added by:InfosecIsland News

A new report from the Pentagon marked the most explicit statement yet from the United States that it believes China's cyber spying is focused on the US government, as well as American corporations.

Comments  (0)

5c549756b3c0b3d5c743158a72ce3809

What Security Risks Do Healthcare Organizations Face?

May 06, 2013 Added by:Michael Fornal

Today, hospitals and healthcare organizations face many risks that they didn’t have to deal with until few years ago. This ever growing list of risks includes social engineering, redundant applications, within a network and keeping patient files secure and confidential but yet available and escalation of privileges.

Comments  (0)

682e0e796084e163c5ca053dd8573b0c

SCADA and ICS Cyber Security - Facing the Facts

May 05, 2013 Added by:Eric Byres

In the past, the main reason for securing a SCADA/ICS network was to protect against inadvertent network incidents or attacks from insiders. The risk of an external malicious cyber-attack was considered minimal.

Comments  (0)

Ffc4103a877b409fd8d6da8f854f617e

Five Questions Boards of Directors Need to Ask About Cloud Governance

May 01, 2013 Added by:InfosecIsland News

ISACA has issued new guidance outlining key questions for boards of directors to ask to ensure their enterprise’s cloud initiative is in line with business objectives and the organization’s risk tolerance.

Comments  (1)

Da3ca2c61c4790bcbd81ebf28318d10a

The Stand Alone Complex and Jihad

May 01, 2013 Added by:Krypt3ia

We have seen Anonymous as a form of SAC and now I think we can make a substantial case for the jihad being one too. If this idea becomes more memetic and resonates with those of a like mind then we will see more of these types of attacks as well as those out there (not only AQ) trying to entice others to action as well.

Comments  (0)

Ffc4103a877b409fd8d6da8f854f617e

Infographic: Staying Safe While Using Public Wi-Fi

May 01, 2013 Added by:InfosecIsland News

To help users avoid online fraud and malware risks, ThreatMetrix provided the following infographic which highlights several scenarios of how cybercriminals can access sensitive transactions over public networks.

Comments  (2)

B3686baa29e6fe1c9c2e3feb0f9ebf99

Why Are We Failing at Software Security?

May 01, 2013 Added by:Nish Bhalla

While there are many granular reasons for software security failures at the institutional, developer or vendor level - there are five industry-wide problems that are fueling the current state of insecurity. These are complicated problems and will not be easy to solve. But until we do, software security will remain at risk.

Comments  (0)

Cc281a493d63c492153ba35b86dcc794

Top 10 Encryption Benefits

April 30, 2013 Added by:Steve Pate

If deployed correctly, encryption does not need to be a headache. Instead, encryption can be an enabler to achieve the flexibility, compliance and data privacy that is required in today’s business environments. Below are top 10 benefits for those considering encryption.

Comments  (0)

76e662e7786bf88946bd6c010c03ac65

The Severe Effects of Syria’s Cybered Conflict

April 29, 2013 Added by:Jarno Limnéll

The conclusion to be drawn from the effects of Syria’s cybered conflict is that using of cyberspace needs to be seen as an integral part of any contemporary and future conflict.

Comments  (0)

219bfe49c4e7e1a3760f307bfecb9954

Takeaways from the 2013 Verizon Data Breach Investigations Report for Software Development Teams

April 29, 2013 Added by:Rohit Sethi

The 2013 Verizon Data Breach Investigations Report has some important data for software development teams, particularly when considering the likelihood of certain threats to your system.

Comments  (0)

B1c4090e84dcfac820a2b8ebe6eee82b

Could the AP Twitter Hack Have Been Prevented?

April 26, 2013 Added by:Gianluca Stringhini

This is the first time that people realize that Tweets can have a large effect on financial institutions. The question that people are asking is: could this compromise have been avoided?

Comments  (0)

D2b743b9ed2d7c357472fa8237d7adaf

Using Least Privilege to Effectively Meet PCI DSS Compliance

April 25, 2013 Added by:Andrew Avanessian

PCI DSS Requirement guidelines certainly reinforce how compliance has hardened from suggestive or advisory directives to true mandates with hefty fines and strict consequences for those failing to take heed.

Comments  (0)

94c7ac665bbf77879483b04272744424

Debit and Credit Card Breach Notifications are Too Little, Too Late

April 25, 2013 Added by:Marc Quibell

I've been reading some interesting articles recently concerning the cyber theft of peoples' credit and debit card data to then be sold and/or for everyday use on the 'net. As usual, by the time the victims figure out what happened, the damage is already done.

Comments  (2)

44a2e0804995faf8d2e3b084a1e2db1d

On Dutch Banking Woes and DDoS Attacks

April 25, 2013 Added by:Don Eijndhoven

If you don't live in the Netherlands or don't happen to have a Dutch bank account, you can certainly be forgiven for not having caught wind of the major banking woes that have been plaguing the Dutch.

Comments  (0)

Af9c34417f8e5e0d240850bb353b5d40

Can You Really Hack An Aircraft?

April 24, 2013 Added by:Keith Mendoza

I was really hesitant to throw myself into this mix; however, as a member of the aviation community (as a lowly private pilot), I feel that I need to do my part to help clear things up and put things in perspective.

Comments  (0)

219bfe49c4e7e1a3760f307bfecb9954

Raising the Bar on Application Security Due Diligence

April 24, 2013 Added by:Rohit Sethi

Many automated scanning solutions are outstanding in their cost effectiveness and ability to find certain classes of vulnerabilities. For example, a properly-configured static analysis solution may help you find every instance of potential SQL injection in your software.

Comments  (0)

5e402abc3fedaf8927900f014ccc031f

Security vs. Personnel and Employment Applications

April 24, 2013 Added by:Allan Pratt, MBA

Does your company use those out-of-date applications where the applicant must provide his or her Social Security number and driver’s license number? If so, throw them out immediately. You could be setting your business up for a potential lawsuit.

Comments  (0)

8a958994958cdf24f0dc051edfe29462

Google: Black Hat or White Hat?

April 23, 2013 Added by:Larry Karisny

Google has a perfect opportunity to be a leader in cybersecurity. Google’s recent network -- and acquisitions and hires -- in Austin, Texas, is an opportunity to do security right the first time.

Comments  (1)

7e364bbac217114a59e547b354e7f7ad

Is Your Scanning Vendor Cheating?

April 22, 2013 Added by:Gary McCully

Is Your Scanning Vendor Cheating? Do Vendors Request Whitelisting just to Inflate Numbers?

Comments  (0)