Blog

Blog

Point of Sale Cyber Crime: The Gift that Keeps on Giving

Image In spite of continuous efforts to improve the security of credit card transactions by both the financial services and retail industries, we see nearly endless headlines about new card data breaches. Banks want to improve security to avoid incurring the expenses associated with fraudulent purchases and investigations efforts....
Blog

Home Network Analysis: DVRs and my Network Interact

Image My last on-topic post pontificated about the dangers and surprise of letting third parties into your house or codebase, where I discussed the addition of a TV DVR system to my home network. In this post, I'm going to go into some details about what I found on the network for the pure pleasure of it – no pontificating about...
Blog

Ransomware Victims Should 'Just Pay the Ransom,' Says the FBI

Image A member of the Federal Bureau of Investigations (FBI) has recommended that ransomware victims "just pay the ransom" if no other option exists and if they need access to their encrypted data. Last Wednesday, during Cyber Security Summit 2015 at Boston's Back Bay Events Center, Joseph Bonavolonta, the Assistant Special Agent in...
Blog

Joomla SQL Injection Flaw Exploited Hours After Disclosure

Image Malicious actors began exploiting a patched critical vulnerability found in Joomla—a popular open-source content management system—just four hours after its details were disclosed. Discovered by researchers at Trustwave, the SQL injection flaw (CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858) found in versions 3.2 through 3.4.4...
Blog

Hacked Shopping Mall CCTV Cameras Are Launching DDoS Attacks

Image If you're running a CCTV surveillance camera in your office, high street store, or at home make sure that you are not unwittingly helping hackers launch denial-of-service attacks. That's the warning that has been issued by the security team at Incapsula, who discovered a botnet of 900 CCTV cameras spread across the globe,...
Blog

Security Nightmare of Driverless Cars

Image The fear of malicious actors taking control of glaring flaws in smart cars is on the rise. This threat is therefore considered to be one of the major technical challenges confronting the automotive industry today. Car Manufacturers Initially, car manufacturers were not very familiar with the cyber security community. From a...
Blog

Security Mentorships and Future Proofing Resource Resilience

Image Everyone always talks about the shortage in cybersecurity talent or their limited cyber resources. However, what I haven’t seen too many folks focus on is the mentoring of the next generation workforce. I recently started volunteering with high school kids, who are mostly all minorities, such as me. I found them, or should I say...
Blog

TalkTalk Investigates Breach that Might Have Exposed 4M Customers' Info

Image TalkTalk, a UK telecommunications company, is an investigating a data breach that might have compromised the personal information of as many as four million customers. On Friday, Trista Harrison, Managing Director (Consumer) of TalkTalk, posted an update on the company's website about the incident: "We are very sorry to tell...
Blog

Launching an Efficient and Cost-Effective Bug Bounty Program

Image Over the last few years, you’ve probably heard a lot about companies launching their own bug bounty programs. Software giants, such as Google, Microsoft, Twitter and Yahoo, as well as hardware-centric companies, such as Tesla, Samsung and even United Airlines, run programs that pay out cash for finding vulnerabilities. As these...
Blog

Takeaways From The 2016 PwC Global State of Information Security Survey

Image Now in its 18th year, The Global State of Information Security® Survey 2016 – a worldwide survey by CIO, CSO and PwC – observes a fundamental shift in the way business leaders are responding to today’s biggest security challenges. Recognizing the rising cyber risks, a growing number of boards and executives are taking action to...
Blog

Email Is Not a File System

Image On Monday, the news buzzed with a story about a high school student who had managed to break into the email accounts of CIA Director John Brennan and DHS Secretary Jeh Johnson. We've seen this scenario played out all too often. The teen used the standard social engineering techniques to find out enough information about the...
Blog

Security Hygiene: Protecting Your Evolving Digital Life

Image This week marks Week 4 in National Cyber Security Awareness Month (NCSAM), a program sponsored by the Department of Homeland Security (DHS) in cooperation with the National Cyber Security Alliance and the Multi-State Information Sharing and Analysis Center. NCSAM emphasizes our shared responsibility in strengthening the cyber...
Blog

Attacking Automobiles: Inside a Connected Car's Points of Vulnerability

Image Hacking cars has made big headlines in recent months. Back in July of this year, security researchers Charlie Miller and Chris Valasek won the attention of the information security community and beyond when they successfully hacked a Jeep Cherokee's computer via its Uconnect infotainment system. The duo was able to rewrite the...