Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Daily news digest – 1st October 2013

by The Gurus
October 1, 2013
in Opinions & Analysis
Share on FacebookShare on Twitter

Today marks the start of the inaugural European Cyber Security Month, a continent-wide scheme intended to raise awareness of security, privacy and information issues.

Organised by the European Union agency for network and information security (ENISA), the campaign for the UK will include poster competitions, an awareness week on behaviour, ethical hacking, viruses and malware, advice on using your home computer as well as social media and email awareness campaigns. Following the various UK-based day and week-long campaigns, and the US cyber security awareness campaign, which also traditionally takes place in the same month in the United States, to make sure no-one misses the point.
I’ve asked in the past what impact awareness days have on the general public and with a prolonged campaign this time, is there going to be sufficient media attention and public awareness of a campaign to actually drive change in behaviour? As a first effort I hope this is successful, but the issue is divided between personal and businesses, and people cross that divide to affect both. I suppose if one person is actually affected then this is a success to an extent, but there will need to be more for this to be carried over into 2014.
Another story which I found to be very amusing this week was in regard to a bug bounty payment by Yahoo of only $12.50 (£7.70) to researchers at High-Tech Bridge. The company said that it was paying the bounty, in the form of a voucher that could be spent in the Yahoo store only, for three cross-site scripting (XSS) vulnerabilities affecting the ecom.yahoo.com and adserver.yahoo.com domains, which would allow an attacker to compromise any @yahoo.com email account.
According to the researchers, after some wrangling over originality of reporting, Yahoo eventually acknowledged the research and offered the paltry bounty. Ilia Kolochenko, CEO of High-Tech Bridge CEO, said: “Yahoo should probably revise their relations with security researchers. Paying several dollars per vulnerability is a bad joke and won’t motivate people to report security vulnerabilities to them, especially when such vulnerabilities can be easily sold on the black market for a much higher price.”
Considering the likes of Google pay up to $5,000 (£3,000) for a bug, this is a severe slap in the face for original security research especially after the crowd-sourced payment for the breaking of Apple’s Touch ID last week. Also unfortunately for Yahoo, is not going to encourage others to work with them if they are paying such comical amounts for original research. After all if you are a penetration tester, are you going to spend your unpaid time working on something that gives a return of only a few pounds, ask yourself if it is worth it? Then ask how Yahoo will patch those bugs if no-one is out and actively finding them.
Also, last week I attended a roundtable hosted by Silent Circle on the concept of anonymity and a lack
of it online. Following the revelations about Prism from this summer, there was a suggestion that this has destroyed online anonymity, something that we in Europe are “obsessed with”. Speaking to the Guardian, former Microsoft chief privacy adviser Caspar Bowden said that he does not have faith in the security of the software company’s technology and he now only uses open source software where he can examine the underlying code and has not carried a mobile phone for two years.
Some may call this attitude paranoia, others will realise that you have more options than putting tin foil on your head and you can actively live off the grid. Although it depends on what they know about you already as sometimes, we are not all anonymous.
ShareTweet
Previous Post

Kids Are Coding

Next Post

Daily news digest – 3rd October 2013

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol