Only in the computer security world would I get taken to task for saying the defenses you apply should be directly related to the threats you face. That’s exactly what happened after I posted “The No. 1 problem with computer security” last week. Several readers wrote to tell me how stupid I was for not […]
I’ve been in the computer security field for nearly three decades. During that time, I’ve watched it go from bad to worse to ugly. Today, the average computer security defense is so bad, we had to invent a new paradigm a few years ago called “assume breach.” This phrase admits that our security controls are […]
Be scared! The Russians are attacking us. If it’s not the Russians, it’s the Chinese — or maybe the North Koreans. Yes, foreign governments are attacking us. But we’re also attacking them. It’s spycraft as usual. The U.S. government and the media’s continued warnings about who is hacking us reminds me of a womanizing cheat […]
A big paradigm shift is under way in the malware world. Less malware is being used in the biggest, most sophisticated attacks. Instead, malicious intruders are using the legitimate tools built into various operating systems to do their dirty work. Legitimate tools, including remote management tools and scripting engines, are far harder to detect than […]
It seems like ancient history now, but in the early decades of the Internet we had huge problem: Our email servers were too friendly. In a nutshell, most email servers allowed anyone to connect to them and send email to anyone else. You didn’t have to be a user of that email server, though sometimes […]
Persistent hackers have a common means of taking over company networks: They compromise one or more enterprise users using social engineering. Either they’ve already compromised a website the user visits or they send a phishing email, which asks for enterprise credentials. If the user visits a compromised website, usually a malicious script will probe the […]
I’m still in shock over the Ashley Madison hack, which exposed more than 37 million users. No, my name and email address are not on the list. No, I’m not morally outraged over the number of people who were either lying to a significant other or hoping to have a liaison with someone lying to […]
This post marks my 10th year writing for InfoWorld magazine. I became a regular writer for InfoWorld by being, shall we say, persistent — I wasn’t a big fan of InfoWorld’s security coverage at the time and suggested I could do better. Eventually, InfoWorld’s editors agreed, and I’ve been posting here ever since. Frequent readers of […]
APTs (advanced persistent threats) are tough to detect and stop. Typically, APT attackers break in, survey all the servers on the network, and take what they’ve come for long before they get noticed … if ever. If only there was a way to prevent that stolen data from being used when it left your network. […]
Behavioral psychiatrists say that virtually all people lie. Most are little white lies to protect the feelings of others. Some lies are acts of commission — a deliberate statement of untruth — whereas others are lies of omission. In the latter case, someone tells an absolutely true fact, but leaves out a very important related […]
Fraudsters are set to hit online advertisers hard this year, costing them $7.2 billion globally as a result of phony web traffic generated by bots, new research has found. The post Phony web traffic to cost advertisers $7.2 billion in 2016 appeared first on We Live Security.
Before you jump into the virtualization migration process, there are a few things to consider, like security, explains ESET’s Miguel Angel Mendoza. The post Managing security in virtualized environments – agent-based or agentless? appeared first on We Live Security.
ESET’s Trends for 2016: (In)Security Everywhere report includes a review of the most important events of last year and outlines trends in cybercriminal activity and cyberthreats for 2016. The post ESET Trends for 2016: Threats keep evolving as security becomes part of our lives appeared first on We Live Security.
People’s choice of passwords continues to be a huge security risk, according to new research. SplashData’s annual Worst Passwords List finds ‘123456’ and ‘password’ continue to be the most common choice. The post Weak passwords continue to pose huge security threat appeared first on We Live Security.
Twitter users across the globe have experienced problems with the social network, which was unavailable for between one to two hours. The post Twitter goes offline across the globe appeared first on We Live Security.
A new survey has revealed that when it comes to making a decision on information sharing and privacy, context plays an important part for many Americans. The post ‘Context’ shapes American attitudes towards privacy appeared first on We Live Security.
Get Safe Online has launched a major new campaign in the UK to help raise awareness of the dangers of social engineering, as figures suggest more needs to be done to inform the public about this growing nuisance. The post Phishing scams spike leads to social engineering campaign appeared first on We Live Security.
Highlights from the past seven days in information security include an analysis of the BlackEnergy trojan and Microsoft’s decision to end support for older versions of Internet Explorer. The post The security review: BlackEnergy, Internet Explorer and Fitbit appeared first on We Live Security.
Firms in the legal sector are at risk of compromising information confidentiality because of poor data practices, according to new research by IS Decisions. The post Legal firms ‘risk compromising data over poor login security’ appeared first on We Live Security.
An attentive and tech-savvy mom, based in Colonie in New York, has been lauded by the police for helping uncover and bring an online predator to justice. The post Online predator busted after being intercepted by tech-savvy mom appeared first on We Live Security.
Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]
The most fun I’ve had as a security guy was getting paid to penetration-test companies and websites. It’s like getting paid to be a gamer. You earn a fat paycheck to hang out with friends and hack away without fear of being arrested. Most large companies today have multiple teams of professional pen testers, often […]
It’s easier than you think to keep your computer malware and hacker free. Believe it or not, most of today’s computers are pretty safe and secure, whether you’re using Microsoft Windows, Apple OS X, Linux, BSD, or Google’s Chrome OS. Mobile devices are equally as safe, as long as you’re downloading apps from an authorized […]
My wife and I recently returned from one of the best vacations of my life, bareboating around the British Virgin Islands with another couple, when I found we were victims of credit card fraud taking place on the other side of the country. It was a lousy way to end a vacation. Worse, I had […]
I’ve said it before: The No. 1 problem with computer security is poor root-cause analysis, where security pros fail to identify and track the ways an environment was exploited, be it malware or human attack. Common root causes include social engineering, password guessing/cracking, unpatched software, misconfiguration, denial of service, and physical attacks. [ Also on […]
I came to love math later in life. In junior high, I hated it so bad I had to take pre-algebra three times and my parents celebrated if I got a D. But I fell in love with it in my first year of college and I consider the A+ I got in my three-hour […]
As much as I love public key infrastructure (PKI) and the mathematical security it can provide, it’s usually horribly implemented in the real world. If done right, like the inventors intended, it would be darn near perfect. It’s mostly broken because admins don’t deploy it right, software doesn’t enforce what needs to be enforced, and […]
It’s been a raucous few months in crypto circles. In a staid, mathematical world long accustomed to incremental changes, new developments are coming as fast as Chrome browser updates. I’m not sure what’s behind the breaks, but crypto cracking suddenly seems to have accelerated. Here’s a quick roundup of what’s been going down — and […]
The writing is on the wall. The future of computers is less application choice — in exchange for a safer overall computing experience. I’m not talking about a draconian security lockdown. I’m referring to the app stores that have emerged not only for mobile but also for desktop operating systems. OS vendors and their stores […]
Most organizations don’t do enough to educate users about computer security. The main purpose of user education programs is to decrease human-factor risk substantially. If they don’t accomplish that, the whole exercise is a waste of resources. Such programs, if they exist at all, consist of a sort of security orientation program for new employees, […]
Google has banned over 780 million so-called ‘bad ads’ in 2015 alone, explaining that these advertisements have breached the terms of their policies. The post Google bans over 780m ‘bad ads’ to protect online experience appeared first on We Live Security.
Hacking Team exploits and new security features in Google Chrome and Microsoft Edge are just a few of the highlights of ESET’s annual Windows exploitation in 2015 report. The post Windows exploitation in 2015 appeared first on We Live Security.
As Tax Identity Theft Awareness Week in the US gets underway, ESET’s Stephen Cobb offers expert advice on how to protect yourself from fraudsters. The post Tax Identity Theft Awareness Week in the US appeared first on We Live Security.
Highlights from the last seven days in information security include ESET’s latest trends report (In)security Everywhere and the ongoing cyberattacks against Ukraine’s electric power industry. The post The security review: ESET’s trends for 2016, more attacks in Ukraine and virtualized security appeared first on We Live Security.
Having in place a ‘cybersecurity response plan’ is vital if hedge fund managers in London are to deal effectively with this threat. The post Hedge fund managers ‘need a cybersecurity response plan’ appeared first on We Live Security.
For too long streaming video gamers have suffered denial-of-service attacks and raids from police SWAT teams, often assisted by Skype leaking private IP addresses. The post Skype finally hides your IP address, to protect against vengeful gamers appeared first on We Live Security.
More and more retailers are investing technology that allows them to track the movement of shoppers through their smartphone, an expert has revealed. The post Retailers ‘capable of tracking shoppers through smartphones’ appeared first on We Live Security.
Nuclear facilities across the world have little or no real security mechanisms in place to deal with cyberattacks, according to new analysis. The post Countries remain unprepared for cyberattacks on nuclear facilities appeared first on We Live Security.
It should have been a great week for the Irish Lottery, with the largest jackpot (12 million euros) for 18 months up for grabs. However, things didn’t run entirely smoothly in the run-up to the Wednesday night draw. The post Irish lottery and ticket terminals knocked offline by DDoS attack appeared first on We Live […]
ESET has discovered a new wave of cyberattacks attacks against Ukraine’s electric power industry. Interesting, the malware that was used is not BlackEnergy. The post New wave of cyberattacks against Ukrainian power industry appeared first on We Live Security.
American consumers are more concerned about not knowing how their personal data is collected online than they are about losing their main source of income, new research has found. The post Americans ‘worry more about online privacy than losing main income” appeared first on We Live Security.
Highlights from the past seven days in information security include ESET’s annual Windows exploitation report, analysis of the Bayrob trojan and beating tax identity fraud. The post The security review: Windows exploitation 2015 and Bayrob trojan appeared first on We Live Security.
HSBC in the UK has revealed via Twitter that its internet banking services were targeted by cybercriminals this morning (January 29th), which it has “successfully defended”. The post HSBC’s online banking services hit with cyberattack appeared first on We Live Security.
Close to half all businesses in the UK are of the opinion that they are safe from cybercrime, according to new research. They believe the risks are minute. The post Businesses ‘still naïve to the risks of cybercrime’ appeared first on We Live Security.
The fast food chain Wendy’s may have been the victim of a data breach, the security expert Brian Krebs has revealed. Unusual activity has been reported. The post Wendy’s launches investigation into possible data breach appeared first on We Live Security.
The ‘Selfie Generation’, which shares every detail of their lives online, doesn’t realize that giving away too much information can have serious consequences. The post Belong to the ‘selfie’ generation? You are probably oversharing appeared first on We Live Security.
In this post, ESET’s Josep Albors analyzes Bayrob, a trojan that has been intensely targeting users across the world since mid-December, 2015. The post ‘Application not compatible’: Bayrob may be stealing your info appeared first on We Live Security.
Cybercriminals are increasingly targeting businesses with ransomware, according to a new report by the Online Trust Alliance. The post Businesses increasingly targeted with ransomware appeared first on We Live Security.
A referendum is to be held on Switzerland’s proposed surveillance law, a decision lauded by supporters of privacy. ESET’s Cameron Camp discusses further. The post Will your Swiss email account stay private (or can the govt take a look)? appeared first on We Live Security.
