Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

An Endpoint Protection Best Practices survey from Symantec, which was conducted last October by Applied Research, shows that organizations following best practices for protecting endpoints are doing a better job protecting critical assets and information. However, when those protections fail, it’s still a costly situation. In short, Symantec is proving that nothing is truly secure.

Klocwork, a company known for its Insight software that performs source code analysis on-the-fly, has released a new version of its flagship product that offers C/C++ developers the same tools that web application developers have been using for some time.

Symantec announced on Monday that it has acquired LiveOffice, a provider of cloud-based email archiving, email compliance, email discovery and email continuity solutions, for approximately $115 million.Symantec says the acquisition will extend its information governance offerings to the cloud and provide customers a choice between on-premise, cloud or hybrid delivery of Symantec solutions.

Fortinet, a provider of network security solutions, today introduced three new appliances to its line of Web application firewalls designed to address the needs of businesses ranging from mid-sized organizations up through large enterprises and service providers.

Security firm Alienvault says that a new variant of the Sykipot family of malware is targeting ActivIdentity’s ActivClient, which is used by the U.S. Department of Defense as a secure means of authentication. Aside from the examination of a sample of the malware itself, it’s unknown what, if any, data the spear-phishing campaign used to launch the attack has made off with.

It’s almost inevitable that a discussion about industrial control system cyber security will touch on a few touchy topics: the ‘air gap’ myth; the ‘a firewall is good enough’ vs. the ‘you must build an anti-cyber-terrorist über bunker’ security measures; the ‘sharing information helps the community’ vs.

CoverItLive, a live-blogging platform owned by Demand Media, has acknowledged that it has been the victim of a cyber attack and that certain information has been accessed without authorization.CoverItLive describes itself as an enterprise-class live blogging platform designed to handle hundreds of thousands of simultaneous readers, and is used by thousands of outlets to cover events as they happen.

24 Million Customers Potentially Exposed After Attackers Breach Internal Systems at Internet RetailerZappos.Com, best-known for selling shoes and clothing online and its top-notch customer service and corporate culture, appears to be the latest victim of a cyber attack resulting in a data breach.

Denis Maslennikov, a mobile security expert from Kaspersky Lab, has discovered what he says is the first IRC bot for Android he has seen.While he wasn’t able to determine how the file is being propagated, he said that after installation, the malicious Android application disguises itself as "MADDEN NFL 12", a mobile version of the popular NFL football video game.

Researchers at Websense uncovered an effort by spammers to target mobile devices using what are known as quick response codes for URLs.Quick response (QR) codes are a type of matrix barcode that are often used by mobile devices to bring people to a particular URL. The codes can be read by any mobile device with a camera and a QR reader.

As a security guy I sometimes have friends and relatives asking me for professional advice, like “I lost my iPhone, can you help me look for it?” or “How do I delete my browser history, you know, in case my wife checks up on me?” It’s not easy being a technical wizard amongst the masses.

Fresh off news that Splunk has filed for an IPO on Thursday, Netherlands-based AVG Technologies today filed an F-1 Registration Statement with the U.S. Securities and Exchange Commission in connection with a proposed initial public offering (IPO). Similar to an S-1, an F-1 is required by foreign companies looking to sell securities in the United States.

In a talk at the 28th Chaos Communication Congress (28C3) entitled “Smart Hacking For Privacy,” researchers Dario Carluccio and Stephan Brinkhaus described their experiences with smart meters from the German energy provider Discovergy. They said they could guess what’s on your digital TV based on unencrypted signals from the smart meters. They could also spoof the energy usage reported from the meter, a far more serious concern.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.