Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

Know your threats before you deploy defenses

Only in the computer security world would I get taken to task for saying the defenses you apply should be directly related to the threats you face. That’s exactly what happened after I posted “The No. 1 problem with computer security” last week. Several readers wrote to tell me how stupid I was for not […]

The No. 1 problem with computer security

I’ve been in the computer security field for nearly three decades. During that time, I’ve watched it go from bad to worse to ugly. Today, the average computer security defense is so bad, we had to invent a new paradigm a few years ago called “assume breach.” This phrase admits that our security controls are […]

American ingenuity: Why the U.S. has the best hackers

Be scared! The Russians are attacking us. If it’s not the Russians, it’s the Chinese — or maybe the North Koreans. Yes, foreign governments are attacking us. But we’re also attacking them. It’s spycraft as usual. The U.S. government and the media’s continued warnings about who is hacking us reminds me of a womanizing cheat […]

Catch attackers even when they don't use malware

A big paradigm shift is under way in the malware world. Less malware is being used in the biggest, most sophisticated attacks. Instead, malicious intruders are using the legitimate tools built into various operating systems to do their dirty work. Legitimate tools, including remote management tools and scripting engines, are far harder to detect than […]

How to stop your DNS server from being hijacked

It seems like ancient history now, but in the early decades of the Internet we had huge problem: Our email servers were too friendly. In a nutshell, most email servers allowed anyone to connect to them and send email to anyone else. You didn’t have to be a user of that email server, though sometimes […]

Bulletproof admin boxes beat the toughest hackers

Persistent hackers have a common means of taking over company networks: They compromise one or more enterprise users using social engineering. Either they’ve already compromised a website the user visits or they send a phishing email, which asks for enterprise credentials. If the user visits a compromised website, usually a malicious script will probe the […]

9 steps to make you completely anonymous online

I’m still in shock over the Ashley Madison hack, which exposed more than 37 million users. No, my name and email address are not on the list. No, I’m not morally outraged over the number of people who were either lying to a significant other or hoping to have a liaison with someone lying to […]

10 years on: 5 big changes to computer security

This post marks my 10th year writing for InfoWorld magazine. I became a regular writer for InfoWorld by being, shall we say, persistent — I wasn’t a big fan of InfoWorld’s security coverage at the time and suggested I could do better. Eventually, InfoWorld’s editors agreed, and I’ve been posting here ever since. Frequent readers of […]

Make stolen data worthless

APTs (advanced persistent threats) are tough to detect and stop. Typically, APT attackers break in, survey all the servers on the network, and take what they’ve come for long before they get noticed … if ever. If only there was a way to prevent that stolen data from being used when it left your network. […]

Bug-free code: Another computer security lie

Behavioral psychiatrists say that virtually all people lie. Most are little white lies to protect the feelings of others. Some lies are acts of commission — a deliberate statement of untruth — whereas others are lies of omission. In the latter case, someone tells an absolutely true fact, but leaves out a very important related […]

Phony web traffic to cost advertisers $7.2 billion in 2016

Fraudsters are set to hit online advertisers hard this year, costing them $7.2 billion globally as a result of phony web traffic generated by bots, new research has found. The post Phony web traffic to cost advertisers $7.2 billion in 2016 appeared first on We Live Security.

Managing security in virtualized environments – agent-based or agentless?

Before you jump into the virtualization migration process, there are a few things to consider, like security, explains ESET’s Miguel Angel Mendoza. The post Managing security in virtualized environments – agent-based or agentless? appeared first on We Live Security.

ESET Trends for 2016: Threats keep evolving as security becomes part of our lives

ESET’s Trends for 2016: (In)Security Everywhere report includes a review of the most important events of last year and outlines trends in cybercriminal activity and cyberthreats for 2016. The post ESET Trends for 2016: Threats keep evolving as security becomes part of our lives appeared first on We Live Security.

Weak passwords continue to pose huge security threat

People’s choice of passwords continues to be a huge security risk, according to new research. SplashData’s annual Worst Passwords List finds ‘123456’ and ‘password’ continue to be the most common choice. The post Weak passwords continue to pose huge security threat appeared first on We Live Security.

Twitter goes offline across the globe

Twitter users across the globe have experienced problems with the social network, which was unavailable for between one to two hours. The post Twitter goes offline across the globe appeared first on We Live Security.

‘Context’ shapes American attitudes towards privacy

A new survey has revealed that when it comes to making a decision on information sharing and privacy, context plays an important part for many Americans. The post ‘Context’ shapes American attitudes towards privacy appeared first on We Live Security.

Phishing scams spike leads to social engineering campaign

Get Safe Online has launched a major new campaign in the UK to help raise awareness of the dangers of social engineering, as figures suggest more needs to be done to inform the public about this growing nuisance. The post Phishing scams spike leads to social engineering campaign appeared first on We Live Security.

The security review: BlackEnergy, Internet Explorer and Fitbit

Highlights from the past seven days in information security include an analysis of the BlackEnergy trojan and Microsoft’s decision to end support for older versions of Internet Explorer. The post The security review: BlackEnergy, Internet Explorer and Fitbit appeared first on We Live Security.

Legal firms ‘risk compromising data over poor login security’

Firms in the legal sector are at risk of compromising information confidentiality because of poor data practices, according to new research by IS Decisions. The post Legal firms ‘risk compromising data over poor login security’ appeared first on We Live Security.

Online predator busted after being intercepted by tech-savvy mom

An attentive and tech-savvy mom, based in Colonie in New York, has been lauded by the police for helping uncover and bring an online predator to justice. The post Online predator busted after being intercepted by tech-savvy mom appeared first on We Live Security.

Why identity is the new security

Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]

Attention, 'red team' hackers: Stay on target

The most fun I’ve had as a security guy was getting paid to penetration-test companies and websites. It’s like getting paid to be a gamer. You earn a fat paycheck to hang out with friends and hack away without fear of being arrested. Most large companies today have multiple teams of professional pen testers, often […]

4 do's and don'ts for safer holiday computing

It’s easier than you think to keep your computer malware and hacker free. Believe it or not, most of today’s computers are pretty safe and secure, whether you’re using Microsoft Windows, Apple OS X, Linux, BSD, or Google’s Chrome OS. Mobile devices are equally as safe, as long as you’re downloading apps from an authorized […]

To catch a thief: Cyber sleuth edition

My wife and I recently returned from one of the best vacations of my life, bareboating around the British Virgin Islands with another couple, when I found we were victims of credit card fraud taking place on the other side of the country. It was a lousy way to end a vacation. Worse, I had […]

7 keys to better risk assessment

I’ve said it before: The No. 1 problem with computer security is poor root-cause analysis, where security pros fail to identify and track the ways an environment was exploited, be it malware or human attack. Common root causes include social engineering, password guessing/cracking, unpatched software, misconfiguration, denial of service, and physical attacks. [ Also on […]

Math to the rescue! Try this novel hacking defense

I came to love math later in life. In junior high, I hated it so bad I had to take pre-algebra three times and my parents celebrated if I got a D. But I fell in love with it in my first year of college and I consider the A+ I got in my three-hour […]

The sorry state of certificate revocation

As much as I love public key infrastructure (PKI) and the mathematical security it can provide, it’s usually horribly implemented in the real world. If done right, like the inventors intended, it would be darn near perfect. It’s mostly broken because admins don’t deploy it right, software doesn’t enforce what needs to be enforced, and […]

Encryption is under siege. Move to SHA-2 now!

It’s been a raucous few months in crypto circles. In a staid, mathematical world long accustomed to incremental changes, new developments are coming as fast as Chrome browser updates. I’m not sure what’s behind the breaks, but crypto cracking suddenly seems to have accelerated. Here’s a quick roundup of what’s been going down — and […]

Freedom or security? Most users have chosen

The writing is on the wall. The future of computers is less application choice — in exchange for a safer overall computing experience. I’m not talking about a draconian security lockdown. I’m referring to the app stores that have emerged not only for mobile but also for desktop operating systems. OS vendors and their stores […]

The most important security question to ask users

Most organizations don’t do enough to educate users about computer security. The main purpose of user education programs is to decrease human-factor risk substantially. If they don’t accomplish that, the whole exercise is a waste of resources. Such programs, if they exist at all, consist of a sort of security orientation program for new employees, […]

Google bans over 780m ‘bad ads’ to protect online experience

Google has banned over 780 million so-called ‘bad ads’ in 2015 alone, explaining that these advertisements have breached the terms of their policies. The post Google bans over 780m ‘bad ads’ to protect online experience appeared first on We Live Security.

Windows exploitation in 2015

Hacking Team exploits and new security features in Google Chrome and Microsoft Edge are just a few of the highlights of ESET’s annual Windows exploitation in 2015 report. The post Windows exploitation in 2015 appeared first on We Live Security.

Tax Identity Theft Awareness Week in the US

As Tax Identity Theft Awareness Week in the US gets underway, ESET’s Stephen Cobb offers expert advice on how to protect yourself from fraudsters. The post Tax Identity Theft Awareness Week in the US appeared first on We Live Security.

The security review: ESET’s trends for 2016, more attacks in Ukraine and virtualized security

Highlights from the last seven days in information security include ESET’s latest trends report (In)security Everywhere and the ongoing cyberattacks against Ukraine’s electric power industry. The post The security review: ESET’s trends for 2016, more attacks in Ukraine and virtualized security appeared first on We Live Security.

Hedge fund managers ‘need a cybersecurity response plan’

Having in place a ‘cybersecurity response plan’ is vital if hedge fund managers in London are to deal effectively with this threat. The post Hedge fund managers ‘need a cybersecurity response plan’ appeared first on We Live Security.

Skype finally hides your IP address, to protect against vengeful gamers

For too long streaming video gamers have suffered denial-of-service attacks and raids from police SWAT teams, often assisted by Skype leaking private IP addresses. The post Skype finally hides your IP address, to protect against vengeful gamers appeared first on We Live Security.

Retailers ‘capable of tracking shoppers through smartphones’

More and more retailers are investing technology that allows them to track the movement of shoppers through their smartphone, an expert has revealed. The post Retailers ‘capable of tracking shoppers through smartphones’ appeared first on We Live Security.

Countries remain unprepared for cyberattacks on nuclear facilities

Nuclear facilities across the world have little or no real security mechanisms in place to deal with cyberattacks, according to new analysis. The post Countries remain unprepared for cyberattacks on nuclear facilities appeared first on We Live Security.

Irish lottery and ticket terminals knocked offline by DDoS attack

It should have been a great week for the Irish Lottery, with the largest jackpot (12 million euros) for 18 months up for grabs. However, things didn’t run entirely smoothly in the run-up to the Wednesday night draw. The post Irish lottery and ticket terminals knocked offline by DDoS attack appeared first on We Live […]

New wave of cyberattacks against Ukrainian power industry

ESET has discovered a new wave of cyberattacks attacks against Ukraine’s electric power industry. Interesting, the malware that was used is not BlackEnergy. The post New wave of cyberattacks against Ukrainian power industry appeared first on We Live Security.

Americans ‘worry more about online privacy than losing main income”

American consumers are more concerned about not knowing how their personal data is collected online than they are about losing their main source of income, new research has found. The post Americans ‘worry more about online privacy than losing main income” appeared first on We Live Security.

The security review: Windows exploitation 2015 and Bayrob trojan

Highlights from the past seven days in information security include ESET’s annual Windows exploitation report, analysis of the Bayrob trojan and beating tax identity fraud. The post The security review: Windows exploitation 2015 and Bayrob trojan appeared first on We Live Security.

HSBC’s online banking services hit with cyberattack

HSBC in the UK has revealed via Twitter that its internet banking services were targeted by cybercriminals this morning (January 29th), which it has “successfully defended”. The post HSBC’s online banking services hit with cyberattack appeared first on We Live Security.

Businesses ‘still naïve to the risks of cybercrime’

Close to half all businesses in the UK are of the opinion that they are safe from cybercrime, according to new research. They believe the risks are minute. The post Businesses ‘still naïve to the risks of cybercrime’ appeared first on We Live Security.

Wendy’s launches investigation into possible data breach

The fast food chain Wendy’s may have been the victim of a data breach, the security expert Brian Krebs has revealed. Unusual activity has been reported. The post Wendy’s launches investigation into possible data breach appeared first on We Live Security.

Belong to the ‘selfie’ generation? You are probably oversharing

The ‘Selfie Generation’, which shares every detail of their lives online, doesn’t realize that giving away too much information can have serious consequences. The post Belong to the ‘selfie’ generation? You are probably oversharing appeared first on We Live Security.

‘Application not compatible': Bayrob may be stealing your info

In this post, ESET’s Josep Albors analyzes Bayrob, a trojan that has been intensely targeting users across the world since mid-December, 2015. The post ‘Application not compatible’: Bayrob may be stealing your info appeared first on We Live Security.

Businesses increasingly targeted with ransomware

Cybercriminals are increasingly targeting businesses with ransomware, according to a new report by the Online Trust Alliance. The post Businesses increasingly targeted with ransomware appeared first on We Live Security.

Will your Swiss email account stay private (or can the govt take a look)?

A referendum is to be held on Switzerland’s proposed surveillance law, a decision lauded by supporters of privacy. ESET’s Cameron Camp discusses further. The post Will your Swiss email account stay private (or can the govt take a look)? appeared first on We Live Security.

Why patching is still a problem — and how to fix it
Despite warnings from people like me, unpatched software is the top reason computers get exploited. People aren’t too dumb or lazy to install [...]
Why you don't need an RFID-blocking wallet
Because I’m a computer security guy, I have friends who like to show off their new RFID-blocking wallets and purses. “Look what I got for [...]
Train your users to beat phone scams
As I landed in Dallas returning from my recent visit to China, I picked up my cellphone voicemails. One of them was from my bank, telling me my personal [...]
A better way to move past insecure SHA-1 certs
I’ve written a few times about the pending mini-Y2K issue that is SHA-1 deprecation. In a nutshell, all digital certificates are signed by a hashing [...]
How computer security changed in 2015
You can call me a pundit, I guess, but I don’t like making predictions. Most industry forecasts are horribly inaccurate and miss the stuff people [...]