International Cyber Expo International Cyber Expo

Editor's News

A survey of “unsafe” applications has found that 85 per cent expose sensitive device data, and a third perform suspicious security actions. The survey of 400,000 mobile applications by Veracode, found that 140,000 were deemed to be unsafe, and a third (37 per cent) checking to see if the device is rooted or jailbroken and another third (35 per cent) retrieve or share personal information about the user such as browser history and calendars. Speaking...

Read moreDetails

Malware that can successfully outwit the CAPTCHA image recognition system has been detected. According to Kaspersky Lab, the Trojan-SMS.AndroidOS.Podec has developed a technique to convince CAPTCHA that it is a person in order to subscribe thousands of infected Android users to premium-rate services. Initially detected in late 2014, Podec automatically forwards CAPTCHA requests to a real-time online human translation service that converts the image to text using an online image-to-text recognition service and within seconds,...

Read moreDetails
patch

Microsoft released 14 patches on its third monthly Update Tuesday, to include critical patches for the FREAK flaw and Internet Explorer. With five critical patches released in total, to address a total of 44 vulnerabilities in all, experts recommended patching MS15-018 first, the bulletin for Internet Explorer. Trustwave's Karl Sigler said that Internet Explorer accounts for fifteen of the vulnerabilities, the majority of which are memory corruption bugs, the worst of which could result in...

Read moreDetails

Private investment firm Bain Capital has announced it is to acquire security vendor Blue Coat Systems in an all-cash transaction valued at approximately $2.4 billion. Blue Coat were acquired by investors Thoma Bravo for $1.3 billion in 2011, and completed the acquisition of Norman Shark in 2013. The transaction is expected to close during the first half of 2015. Gregory S. Clark, chief executive officer, Blue Coat Systems, said: “The world’s most trusted brands use...

Read moreDetails

The enforcement activities of the Information Commissioner’s Office (ICO) have increased over the past three years with a marked shift away from headline grabbing financial penalties in favour of more subtle and sophisticated enforcement tools. According to PwC’s Privacy and Security Enforcement Tracker, the number of enforcement notices have quadrupled in the last two years alone while the number of businesses criminally prosecuted has risen significantly, from seven in 2013 to 18 in 2014. Stewart...

Read moreDetails
apple

The CIA has conducted a sustained effort to break the security of Apple’s iPhones and iPads.   According to top-secret documents obtained by The Intercept, the effort took place over several years where researchers targeted security keys used to encrypt data stored on Apple’s devices, and ultimately penetrate Apple’s encrypted firmware.   The security researchers also claimed they had created a modified version of Apple’s proprietary software development tool, Xcode, which could sneak surveillance backdoors...

Read moreDetails

Whilst wearable technology and Internet of Things (IoT) are popular, security concerns are often ignored for convenience. Speaking to IT Security Guru, Dan Lamorena, senior director of HP Software Enterprise Security Products, admitted that despite there not having been a major incident yet regarding IoT or wearable technology, there are vulnerabilities inside whilst there is plenty of focus on getting products to market. “I am sure this is an area of concern and we are finding...

Read moreDetails

Feminist blog Femsplain.com came under a Distributed Denial-of-Service (DDoS) attack on International Women’s Day. Whilst the opportunity was taken to celebrate women’s achievements and contributions to society, the blog founder Amber Gordon said that the site had suffered DDoS attacks in the past, but never with such severity as the one experienced yesterday, reported Graham Cluley on welivesecurity. “I think it’s because it’s International Women’s Day,” she told The Verge. However Femsplain used the attack to...

Read moreDetails

The US military is looking to hire 3,000 cyber security professionals over the next nine months. In an in order to boost resources at its Cyber Command armed forces infosec unit, the command's leaders recently successfully lobbied the US Government to rubber-stamp the hiring of 3,000 new workers to its 1100-strong workforce, which five years on is still not fully staffed. According to IT News, head of the Cyber Command, Admiral Mike Rogers, told a US House committee last week that...

Read moreDetails

Microsoft has released an advisory relating to the FREAK vulnerability, which affects its Secure Channel and all supported releases of Microsoft Windows. The company said that its investigation has verified that the FREAK (Factoring attack on RSA-EXPORT Keys) vulnerability could allow an attacker to force the downgrading of the cipher suites used in an SSL/TLS connection on a Windows client system. “The vulnerability facilitates exploitation of the publicly disclosed FREAK technique, which is an industry-wide...

Read moreDetails
Page 228 of 319 1 227 228 229 319