Catégorie : #SECURITE ENG
L’actualité anglophone de la sécurité informatique et de la cybersécurité, traitant de l’actualité de la sécurité informatique, du hacking et des programmes informatiques à visée malveillante.
Vulnerability Summary for the Week of September 9, 2019
The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available Source : https://www.us-cert.gov/ncas/bulletins/sb19-259 Date : September…
That’s Classified: Why a Deep Understanding of Military Data Protection Delivers DLP for Enterprises Today
When the captain of a Navy ship receives a “Flash command,” he or she has three minutes to deliver a response: “Received, Understood, Actioned.” The commander has to be sure that the correct captain has received the message, Source : https://www.forcepoint.com/blog/insights/thats-classified-why-deep-understanding-military-data-protection-delivers-dlp Date : September 16, 2019 at 02:39PM Tag(s) :…
Emotet, today’s most dangerous botnet, comes back to life
Emotet botnet resumes malspam operations after going silent for nearly four months. Source : https://www.zdnet.com/article/emotet-todays-most-dangerous-botnet-comes-back-to-life/#ftag=RSSbaffb68 Date : September 16, 2019 at 02:06PM Tag(s) : Médias internationaux Share this… Email Facebook Twitter Linkedin Whatsapp Print
Ex White House CIO attacks insurance firms for ‘fuelling ransomware industry’
Theresa Payton argues companies are manipulating victims to avoid paying higher bills Source : https://www.itpro.co.uk/ransomware/34396/ex-white-house-cio-attacks-insurance-firms-for-fuelling-ransomware-industry Date : September 16, 2019 at 11:19AM Tag(s) : Médias spécialisés Share this… Email Facebook Twitter Linkedin Whatsapp Print
#privacy: UK university to lead doctoral training programmes in cyber-security
University of London’s Artificial Intelligence Research Centre (CitAI) and Institute for Cyber Security (ICS) will lead two new Doctoral Training Programs (DTPs), supported by the European digital innovation and entrepreneurial education organisation EIT Digital. Source : https://gdpr.report/news/2019/09/16/privacy-uk-university-to-lead-doctoral-training-programmes-in-cyber-security/ Date : September 16, 2019 at 09:06AM Tag(s) : #RGPD ENG Share this… Email Facebook Twitter Linkedin Whatsapp…
#privacy: New cyber-security enterprise drive comes to Singapore
Multinational cyber-security companies of all sizes which chose Singapore as their base will be able to harness the Republic’s technical expertise, workforce and networks, the city state’s Senior Minister, Teo Chee Hean has said. Source : https://gdpr.report/news/2019/09/16/privacy-new-cyber-security-enterprise-drive-comes-to-singapore/ Date : September 16, 2019 at 10:06AM Tag(s) : #RGPD ENG Share this……
Opinion: Cyber attacks threaten security of 2020 election
Following the 2016 elections, investigators found evidence that Russian hackers successfully infiltrated the computerized voting systems of several states. Hackers also stole data from campaigns and weaponized social media polarizing the electorate against and for certain candidates. Source : https://www.siliconvalley.com/2019/09/15/opinion-cyber-attacks-threaten-security-of-2020-election/ Date : September 15, 2019 at 04:29PM Tag(s) : Fédération…
IoT Cyberattacks Surge 300% in 2019
A new report released by F-Secure notes that cyberattacks have gone up over three hundred percent. The amount of attacks, according to the report, comes in at … Source : https://www.cloudwedge.com/news/iot-cyberattacks-surge-300-in-2019/ Date : September 15, 2019 at 11:42AM Tag(s) : #IOT ENG Share this… Email Facebook Twitter Linkedin Whatsapp Print
Hacking with AWS: incorporating leaky buckets into your OSINT workflow
Penetration testing is often conducted by security researchers to help organizations identify holes in their security and fix them, before cybercriminals have the chance. While there’s no malicious intent for the researcher, part of his job is to think and act like a cybercriminal would when hacking, or attempting to…
Medical manufacturing, IoT cybersecurity, who’s on the move
10 strategies to protect IoT devices; Craig Hahne is Tsugami/Rem Sales’ VP of strategic relationships; Precision ADM expanding manufacturing capacity. Source : https://www.todaysmedicaldevelopments.com/medical-manufacturing-iot-cybersecurity-additive-manufacturing-tsugami-rem.aspx Date : September 14, 2019 at 11:16AM Tag(s) : #IOT ENG Share this… Email Facebook Twitter Linkedin Whatsapp Print
Malicious attack causes Wikipedia to go offline in Europe
The “large scale” attack knocked out Wikipedia access in countries including Germany, the Netherlands, and Poland. Read more… Source : https://mashable.com/video/wikipedia-access-attack-europe/ Date : September 14, 2019 at 12:12PM Tag(s) : Médias internationaux Share this… Email Facebook Twitter Linkedin Whatsapp Print
2019-09-13 – WSHRAT infection from malspam
Source : https://www.malware-traffic-analysis.net/2019/09/13/index.html Date : September 13, 2019 at 10:59PM Tag(s) : #SECURITE ENG Share this… Email Facebook Twitter Linkedin Whatsapp Print
How to Foil the 6 Stages of a Network Intrusion
The cost of a breach is on the rise. A recent report from IBM revealed that the average cost of a data breach had risen 12 percent over the past five years to $3.92 million per incident on average. Additionally, this publication uncovered that data breaches originating from malicious digital…
COBALT DICKENS Launched New Phishing Operation against Universities
The COBALT DICKENS threat group stayed busy over the summer by launching a new global phishing operation targeting universities. In July and August 2019, Secureworks’ Counter Threat Unit (CTU) researchers observed COBALT DICKENS using compromised university resources to send out library-themed phishing emails. Source : https://www.tripwire.com/state-of-security/security-data-protection/cobalt-dickens-launched-new-phishing-operation-against-universities/ Date : September 12,…
Vital infrastructure: emergency services
Organizations in the emergency services sector are there for the public to provide help when situations get out of hand or are too much to handle. Source : https://blog.malwarebytes.com/vital-infrastructure/2019/09/vital-infrastructure-emergency-services/ Date : September 11, 2019 at 10:17PM Tag(s) : #SECURITE ENG Share this… Email Facebook Twitter Linkedin Whatsapp Print
4 things to consider before purchasing a cross domain transfer solution
There are number of factors to consider when procuring any IT product- functionality, flexibility, cost, compliance, the list goes on. And the stakes are even higher when an agency is procuring a secure information sharing Cross Domain Solution as it needs to efficiently and securely support the most critical of…
Policy paper: EU Cyber Security Certification (EU Exit) Call for Views
A call for views on the proposed approach to cyber security certification following the UK’s departure from the EU. Source : https://www.gov.uk/government/publications/eu-cyber-security-certification-eu-exit-call-for-views Date : September 11, 2019 at 03:59PM Tag(s) : UK GOV Share this… Email Facebook Twitter Linkedin Whatsapp Print
VERT Threat Alert: September 2019 Patch Tuesday Analysis
Today’s VERT Alert addresses Microsoft’s September 2019 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-849 on Wednesday, September 11th. In-The-Wild & Disclosed CVEs CVE-2019-1214 An elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver can allow an attacker…
300 shades of gray: a look into free mobile VPN apps
The times, they are a changin’. When users once felt free to browse the Internet anonymously, post about their innermost lives on social media, and download apps with frivolity, folks are playing things a little closer to the vest these days. Source : https://blog.malwarebytes.com/privacy-2/2019/09/300-shades-of-gray-a-look-into-free-mobile-vpn-apps/ Date : September 10, 2019 at…
How to Maximize Threat Intelligence with a Human Touch
DeepSight Intelligence can help organizations deal with the scope of today’s threats and the scarcity of top cyber security talent Source : https://www.symantec.com/blogs/feature-stories/how-maximize-threat-intelligence-human-touch Date : September 10, 2019 at 06:45PM Tag(s) : Sécurité Share this… Email Facebook Twitter Linkedin Whatsapp Print