Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Arbor Networks has been analyzing some of the malware used to launch DDoS attacks, in order to help educate organizations on the nature of code used to create and manage the DDoS botnets.In a series of blog posts, Arbor Networks examines the operational abilities and design of the Armageddon, Khan, and PonyDOS botnets, or rather the malware that establishes them.

It isn’t often that after a data breach involving credit cards, that the public is also given a marker on the exact amount money lost by consumers as a result. Thanks to the FBI however, we now have a better understanding of what 60,000 stolen credit cards translates to financially, as this data was included in their investigation notes while working the Stratfor case.

Ford Testing Firmware Update Program, Encourages Customers to Have a Unique USB for Each Ford They OwnThis month, Ford is borrowing something from the software industry: updates. With a fleet of new cars using the sophisticated infotainment system they developed with Microsoft called SYNC, Ford has the need to update those vehicles—for both features and security reasons. But how do you update the software in thousands of cars?

Google showed a great deal of confidence ahead of the CanSecWest conference this year when it announced plans to offer up to $1 million in rewards for a successful exploit against its Chrome browser. The company even launched its own Pwnium contest.

The National Security Agency/Central Security Service officially opened its new "Georgia Cryptologic Center" this week. Celebrated with a ribbon-cutting ceremony on Monday, the new $286 million, 604,000 square foot complex will provide cryptologic professionals with the latest state-of-the-art tools to conduct signals intelligence operations, train the cryptologic workforce, and enable global communications.

After news of the FBI’s arrest of LulzSec’s leader Sabu became public, including the fact he was a cooperating witness in an ongoing criminal investigation, Panda Labs published a blog post titled “Where is the lulz now?” Not long after that post was made, AntiSec supporters attacked Panda Security, defacing more than 30 sub-domains used by the company.

Defending Against Insider Threats in SCADA Environments Using Context and Correlation[Read Previous Column: "SCADA Mischief Episode 1: A Picture is Worth a Thousand Worms" Before Reading This Column]

Defending Against DDoS Attacks: Do You Have an Action Plan in Place?In my career I have been asked how to respond to a DDoS attack. What do you do? Who do you call? Ghost Busters? What are the options?

Trustwave, a provider of cloud-based compliance and information security solutions, today announced that it has signed a definitive agreement to acquire Irvine, California-based M86 Security, a provider of Web security and anti-malware solutions.

Tacoma, Washington-based IID (Internet Identity), a provider of Internet security technology and services, today said that it has seen a dramatic decrease in Fortune 500 companies and what it considers “major” U.S. federal agencies that are infected with DNSChanger malicious malware.

The human element. It’s something information security professionals lose sleep over and just can’t seem to get under control. But the threat from smartphone carrying, click-happy, and “helpful” (think social engineering) employees to an organization's security posture is not new to any CISO or IT Security professional.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Artificial Intelligence

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.