Medical Devices Subject To Cyberattack, FDA Warns
A posting from Dark Reading in there Vulnerability and Threat Section: The Food and Drug Administration last week warned that patient health could be threatened by the introduction of malware into medical equipment or unauthorized access to configuration settings in medical devices and hospital networks. In an alert posted last week, the FDA noted that many medical […]
Thumb Drive Security: Snowden 1, NSA 0
A posting from Information Week in there Security Storage section: NSA investigators now "know how many documents he downloaded and what server he took them from," a government official -- speaking on condition of anonymity -- told the paper. In general, the use of removable USB storage devices is prohibited inside the agency. "Of course, […]
Blackberry releases first security fixes for new Z10 smartphone
Blackberry releases first security fixes for new Z10 smartphone
US charges eight for cybercrime targeting banks, government
An interesting articles from NBC NEWs in there Technology section: Federal prosecutors in New Jersey on Wednesday unveiled criminal charges against eight people accused of trying to steal at least $15 million from U.S. customers in an international cybercrime scheme targeting accounts at 15 financial institutions and government agencies. U.S. Attorney Paul Fishman said the […]
Don't Take Vulnerability Counts At Face Value
A posting from Dark Reading in there Vulnerability Management Section: In 2012, there were 5,291 vulnerabilities documented by security researchers and software firms. Wait, no, make that 8,137. No, 9,184. Well, it could even be 8,168 or 5,281. In reality, the exact number of vulnerabilities reported in different databases each year varies widely--by as much […]
New OWASP Top 10 Reflects Unchanged State Of Web Security
A posting from Dark in there Application Security section: The oft-cited and oft-debated OWASP Top 10 list of the most critical vulnerabilities in Web applications got an update this week with the most prevalent flaw—injection--remaining at the number one slot. Injection, broken authentication and session management, cross-site scripting (XSS), insecure direct object references, security misconfiguration, […]
Best Practices for Creating a Password
Passwords are usually the first line of defense when it comes to protecting computers and information assets. What happens when that first line of defense is not properly created? I think we already know…
A World of Vulnerabilities - InfoSec Institute
Every day, we read about cyber-attacks and data breaches, incidents that represent in many cases a disaster for private companies and governments. Technology plays a significant role in our lives; every component that surrounds us runs a piece of software that could be affected by flaws and exploited by those with ill intentions.
Was Microsoft's takedown of Citadel effective?
A posting from Naked Security: As we mentioned last week, Microsoft recently fought back against more than 1,400 Citadel botnets by sinkholing their Command and Control (C&C) infrastructure. SophosLabs has been monitoring Citadel for some time, including individual botnets such as those targeting Canadian institutions, so I decided to take a closer look at the impact of the […]