Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Researchers at Trend Micro have discovered a malicious PowerPoint file circulating via email, which if executed, installs a backdoor on the victim’s system. The backdoor is made possible thanks to a vulnerability in Flash Player. The good news, however, is that the vulnerability itself has long since been patched, and malicious attachments are easy to avoid.

In an effort to help organizations develop mobile applications that have security baked-in from the start, IBM has announced a series of static application security testing tools for Android.There are more than 5 billion mobile devices in the world, and according to a recent IBM study, when addressing the BYOD (Bring Your Own Device) phenomenon, 55% of CIOs said that mobile security has become their top concern. It’s just not feasible to ban personal devices in the workplace.

Following drama last month that started when Adobe said it would essentially force users to pay for an upgrade to address security vulnerabilities in some of its most popular graphics applications but later changed its tune, Adobe today rele

Google Two-Factor Authentication Flaw Led to Breach at CloudFlare, Exposed Other Google Apps for Business CustomersLate last week, news broke that web security and performance startup CloudFlare was attacked, resulting in a hacker being able to successfully redirect web traffic of one of the company’s largest clients.

Microsoft has said that it would activate Do Not Track (DNT) by default in Internet Explorer 10 on Windows 8. This announcement caused a bit of a clash between Mozilla – the first to implement DNT – and advertisers.

The group known as SwaggSec, who targeted Foxconn earlier this year, released a collection of files over the weekend, allegedly taken after they compromised China Telecom and Warner Bros.Neither firm has issued a statement on the incident, but according to statements made by SwaggSec, China Telecom attempted to address the breach by relocating their SQL database. The effort was wasted however, as they only changed the IP location.

The secretive Defense Advanced Research Projects Agency (DARPA) is launching a new effort called 'Plan X' to improve its cyber-warfare capabilities, according to the Washington Post.DARPA's mission is to develop technologies for the U.S. military in the name of national security. According to the Washington Post, the effort represents a shift in the priorities of the agency, whose past activities in cyberspace have been more focused on protecting defense department computers. In November, DARPA announced a research initiative to improve...

Earlier this week, SecurityWeek reported that the University of Nebraska was investigating a cyber attack that resulted in a security breach of an information system that houses sensitive data on students and alumni dating back to 1985 that contains personal records for students, alumni and applicants of the university’s four campuses and could affect up to 650,000 individuals.

IPv6 Security Challenges: Experts Offer Advice for Organizations Planning to Deploy IPv6, Starting with Ensuring Visibility and Control.World IPv6 Launch day is scheduled for June 6 with the goal of bringing major Internet Service Providers (ISPs) and Web companies together to jumpstart widespread adoption of IPv6.  But from a security standpoint, companies should follow an old saying: look before you leap.

Earlier this week, SecurityWeek reported on news that Cambridge University researchers discovered a backdoor on a field-programmable gate array (FPGA) chip used by the U.S military. The news originally spread like wildfire, but shortly after, some began to doubt that the story was worth the hype.

Author David Sanger Says President Obama Ordered Wave of Cyberattacks Against IranAccording to a soon-to-be-released book by The New York Times' chief Washington correspondent, David Sanger, President Obama secretly ordered - and decided to accelerate - cyber attacks against systems that powered Iran’s prime nuclear enrichment facility, namely its Natanz plant. The famous attack, as we all know, was Stuxnet.

Apple has released a document that examines the security technology and features implemented within iOS, the platform that operates the consumer market’s most successful line of mobile devices. While none of the information is new or unknown, the guide is noteworthy, if only because it offers an official basic list of best practices to organizations wishing to deploy Apple devices.

CSIS Security Group researchers have discovered what they are calling the "World’s smallest trojan-banker," a piece of malware that proves dangerous things can come in small packages. Given the hype surrounding Flame and its massive size of 20MB, the discovery of something one thousand times smaller, and still quite dangerous, puts things in perspective.

A new report from International Data Corporation (IDC) shows that small and medium business (SMB) spending on security technology continues experience strong growth and is expected to exceed $5.6 billion by 2015 in the United States.While overall SMB IT spending in the U.S. is forecast to grow at a rate of 5-6% per year over the period, IDC says security-specific products and solutions is expected to grow at nearly twice that rate.

FireMon Security Manager 6.0 Delivers Integrated Risk Analysis and Policy and Configuration Management Solution for Network Security FireMon, a provider of security management and risk analysis solutions, this week announced the latest version of its security policy and posture management solution, FireMon Security Manager 6.0.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.