International Cyber Expo International Cyber Expo

Editor's News

Websites which run on the Wordpress content management system are at risk of being fully controlled by hackers.   According to Sucuri, the vulnerability affects Custom Contacts Form, a plugin with more than 621,000 downloads. The company claimed that this would allow an attacker to take unauthorised control of a victim’s website without requiring any sort of privileges or accounts beforehand.   It said: “Those familiar with WordPress know that all of the table names and...

Read moreDetails

Microsoft will release nine patches next week, two of which will be rated as critical.   These Updates will be for SQL Server, SharePoint, OneNote, .NET, Microsoft Windows and Internet Explorer. The two critical bulletins and one of the others, rated as important, allow for Remote Code Execution (RCE).   Wolfgang Kandek, CTO of Qualys, said: “The most critical patch is bulletin #1 which affects all versions of Internet Explorer (IE), all the way from...

Read moreDetails

Cryptolocker is dead, the owners are trying to discover what the authorities know and don't be surprised to find more variants out there.   Speaking at the Black Hat conference in Las Vegas, security consultant John Bambenek praised the global effort in taking down the GameOver Zeus, but said that this followed a distinct lack of communication.   He said that at one point, there were four different working group for Cryptolocker and when they...

Read moreDetails

Stuxnet is not an example of war, as the USA and Iran were not at war, but it was an act of sabotage by one Government against another.     Speaking at the Black Hat conference in Las Vegas, Mikko Hypponen, chief research officer at F-Secure said that Stuxnet was an example of a capable army using a tool for their benefit. “The number one benefit is deniability, followed by lack of attribution,” he said....

Read moreDetails

Sharing of threat and viral information has benefited the healthcare industry, so the same can work in cyber security.   Speaking in the opening keynote at the Black Hat conference in Las Vegas, In-Q-Tel CISO Dan Geer said that he believed that cyber security has a dual purpose, for good or evil, but that dual use was inherent in security tools.   Moving on to mandatory reporting, Geer made the analogy between releasing information on...

Read moreDetails

“Choose two from freedom, convenience and security”   Speaking in the opening keynote at the Black Hat conference in Las Vegas, In-Q-Tel CISO Dan Geer covered a ten point policy to improve online security, including convergence, mandatory breach reporting and the right to be forgotten.   Admitting that everyone wishes this was taken as seriously, but admitted that it is taken usefully or corherently, he said “we never been more at the of forefront of...

Read moreDetails

Advances in automobile technology are enabling attacks, but that industry is not ready for security and updates.   Speaking in a well-publicised presentation at the Black Hat conference in Las Vegas, Charlie Miller and Chris Valasek claimed that this time they were able to present at this conference after completing more of a study of automotive technology, and identifying common flaws. Last year's proposed talk was rejected and presented at the Def Con conference instead....

Read moreDetails

Don't be afraid to speak about incidents, and use knowledge and experience to benefit yourself and others.   In his keyote address titled “Beyond good and evil” at BSides Las Vegas, threat modelling author and expert Adam Shostack claimed that there is a danger of security professionals “burning out” due to levels of exhaustion, cynicism and efficacy.   He said: “If we cannot prevent our networks from getting hacked, it seems to me to relate...

Read moreDetails

More searches will uncover more vulnerabilities, as flawed systems are still prevalent.   Speaking at the CodenomiCON 2014 event in Las Vegas, cryptographer and C03 Systems CTO Bruce Schneier and former Presidential advisor and chairman of the board of Codenomicon, Howard Schmidt, said that they believed that the discovery of Heartbleed was one of many and if you kept looking, you would find more flaws.   Schmidt said that as attackers keep stock piling zero-days...

Read moreDetails

Security by design is becoming less of a case, particularly with the enhancement of the internet of things (IoT).   Speaking at the CodenomiCON 2014 event in Las Vegas, cryptographer and C03 Systems CTO Bruce Schneier, and former Presidential cyber security advisor and chairman of board of Codenomicon, Howard Schmidt, said that security is still something everyone can do, but it still works despite scares, risk and identity theft that goes on.   Schneier said...

Read moreDetails
Page 266 of 319 1 265 266 267 319