Evernote offers two-factor verification in wake of hack
A posting from NBS News in there Technology Section: Popular media-saving service Evernote has stepped up its security after a recent breach in which users' emails and passwords were leaked. The company is now offering two-factor verification to its premium users to make sure that when someone signs into your account, it's really you. The hack, in March, did not […]
'NetTraveler' Cyberespionage Campaign Uncovered
An intrstuing article from Dark Reading: A less sophisticated but long-running cyberspying program out of China aimed at high-profile targets in government, embassies, oil and gas, military contractors, activists, and universities has infected hundreds of targets across 40 nations. The so-called NetTraveler campaign revealed today by Kaspersky Lab comes from a midsize APT group out […]
Are Businesses Knowingly Infecting Their Web Visitors?
A posting from Dark reading in there Vulnerability and Threat section: As cybercriminals have shifted their techniques to get the most efficiency out of their attack campaigns, some of their favorite methods involve two-pronged attacks to first compromise legitimate Web servers and then use them to, in turn, infect unsuspecting visitors to seemingly innocuous sites. While much […]
End user security requires layers of tools and training as employees use more devices and apps
A posting from Dark Reading in there Endpoint security section: When Meritrust Credit Union wanted to improve its endpoint security to comply with financial regulations, information security officer Brian Meyer needed to go beyond antivirus. The commonly used endpoint security typically doesn't provide a way of tracking whether employees' devices -- the laptops, tablets and […]
LinkedIn flips the two-factor authentication switch
A posting from Naked Security on LinkedIn authentication: Happy anniversary of getting the bejeezus hacked out of you, LinkedIn! Maybe the timing is just a coincidence, but the career-toned social networking site got savagely hacked on 5 June 2012. Cybercrooks stole about 6.5 million passwords, over 60% of which were cracked within the span of […]
Not good enough, Oracle - promises to secure Java are too little, too late
An interesting article from Naked security: Oracle has promised to work harder to make Java more secure. Given the constant flood of high-profile, heavily-exploited vulnerabilities, are Oracle's new ideas going to be enough to save this piece of software from drowning in bad vibes? In a lengthy blog post last week, the head of Java […]
Social Engineering: Tips to Protecting Yourself
In the world of information security, ‘social engineering’ is a term that describes a non-technical way of hacking that relies on the hacker to collect information to bypass normal security controls. It is the art of manipulating users into performing actions or divulging confidential information.
GovSec - The SecurityOrb Show: Interview with Curtis KS Levinson about GovSec
GovSec - The SecurityOrb Show: Interview with Curtis KS Levinson about GovSec
APT Attacks Trace To India, Researcher Says
A posting from information week on APT Attacks : A multi-year advanced persistent threat (APT) campaign that targeted the government of Pakistan, as well as global businesses operating in mining, automotive, engineering, military and finance sectors, among others, appears to have been run from India. Organizations targeted for industrial espionage were located in numerous countries, including the United […]
3 Lessons From Layered Defense's Missed Attacks
a posting from Dark Reading in there Vulnerability Management section: Layering security measures typically protects systems better: Research) by three University of Michigan graduate students in 2008, for example, found that using multiple antivirus engines result in much better protection than using a single program. Yet, recent analysis by NSS Labs highlights that layering security devices rarely catches all […]