NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Newsfeeds
Help Net Security
  • Week in review: Lure10 attack, DoublePulsar exploit proliferation

    Here’s an overview of some of last week’s most interesting news and articles: BrickerBot bricked 2 million IoT devices, its author claims The author of BrickerBot, which “bricks” IoT devices by rewriting the flash storage space and wiping files, has emerged to explain that the malware first attempts to secure the units without damaging them. Security improvements primary reason for Windows 10 migration Migration to Windows 10 is expected to be faster than previous OS … More

    click to view

  • IT service providers, many other orgs targeted in long-standing attack campaign

    US-CERT has released an alert warning about a sophisticated attack campaign using multiple malware implants and targeting organizations in the IT, Energy, Healthcare and Public Health, Communications, and Critical Manufacturing sectors. “According to preliminary analysis, threat actors appear to be leveraging stolen administrative credentials (local and domain) and certificates, along with placing sophisticated malware implants on critical systems,” the alert says. “Some of the campaign victims have been IT service providers, where credential compromises could … More

    click to view

  • Will fileless malware push the antivirus industry into oblivion?

    The death of antivirus has been prophesied for years now, but the AV industry is still alive and kicking. SentinelOne, though, believes that in-memory resident attacks, i.e. fileless malware, just might be the thing that pushes it into oblivion. They base their conjecture on the results of the attack detections made through over a million of SentinelOne Endpoint Protection Platform agents, deployed in enterprise environments across the world. These detections are made at the endpoint, … More

    click to view

  • How to securely deploy medical devices within a healthcare facility

    The risks insecure medical devices pose to patient safety are no longer just theoretical, and compromised electronic health records may haunt patients forever. A surgical robot, pacemaker, or other life critical device being rendered non-functional would give a whole new, and wholly undesirable, meaning to denial of service. Malware like MEDJACK has been used to infect medical devices and use them as staging grounds to attack medical records systems. IoT ransomware is on the rise … More

    click to view

  • Industry reactions to the Verizon 2017 Data Breach Investigations Report

    Nearly 2,000 breaches were analyzed in this year’s Verizon 2017 Data Breach Investigations Report and more than 300 were espionage-related. Here are some of the comments Help Net Security received on the report. John Madelin, CEO at Reliance acsn Today’s report highlights that businesses must rethink their protection strategies to guard against cyber attacks. The fact that 88% of breaches identified in the report fall into patterns first identified in 2014 is an illustration of … More

    click to view

  • Employees increasingly allowed to move data onto personal mobile devices

    Corporate data governance programs are difficult to establish and enforce. For the most part, these programs lack the necessary people, processes and technology to effectively fend off security threats, data breaches, regulatory fines and lawsuits. The two weakest links in a company’s data governance program are uncontrolled user access to data (53 percent) and managing where data is stored (43 percent), according to a new research study released by Blancco Technology Group. Data protection and … More

    click to view

  • New infosec products of the week​: April 28, 2017

    Cyberbit EDR uses adaptive behavioral analysis to detect fileless, signature-less attacks Cyberbit announced a new version of its adaptive Endpoint Detection and Response (EDR) platform, which now provides semi-automated threat hunting, centralized response capabilities, and an improved SDK for detection customization. Originally developed to meet requirements of high-risk organizations, Cyberbit’s new EDR enhancements help customers decrease threat detection and response times while minimizing false positives, improving cyberattack countermeasures and cutting distractions for security teams. Elcomsoft … More

    click to view

  • IT teams struggle with digital transformation skills

    New research conducted by Vanson Bourne aims to uncover how well-placed global IT leaders consider themselves and their teams to be in terms of meeting current and future business demands. Of the six markets surveyed, Germany was found to be the best prepared to meet its digital transformation goals, closely followed by the U.S., while the UK lagged well behind its counterparts. The research, which surveyed 630 IT leaders in the U.S., UK, France, Germany, … More

    click to view

  • How secure are mobile banking apps?

    Do banking institutions have a good handle on the things they need to remediate and new control layers they need to adopt to keep users secure? To answer those questions, Accenture and NowSecure have performed vulnerability assessments of customer-facing mobile banking apps of 15 banking institutions in the North American market. They have tested the iOS and Android app versions of each of these banks, and found that every app they tested had at least … More

    click to view

  • Executive spotlight: iovation’s new Vice President of Product

    Last week iovation announced that Dwayne Melancon was leaving Tripwire after 17 years and joining the company as the new Vice President of Product, so we decided to get in touch and see what are his future plans. “My experience at Tripwire ran the gamut – I served in a range of roles, from CTO to product management to head of R&D – but my ultimate goal was to create products that offered both a … More

    click to view

| Date published: Mon, 01 May 2017 01:56:12 +0000
Back to newsfeed list
Translate to: {GOOGLETRANS}
Google Ads




Headlines

»CVE-2016-7815
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote at ...
»CVE-2016-7839
Cross-site scripting vulnerability in Olive Blog allows remote attackers to inject arbitrary web scr ...
»CVE-2016-7840
Cross-site scripting vulnerability in WEB SCHEDULE allows remote attackers to inject arbitrary web s ...
»CVE-2016-7841
Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web ...
»CVE-2016-7842
Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows ...
»CVE-2016-7843
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 a ...
»CVE-2016-8030
A memory corruption vulnerability in Scriptscan COM Object in McAfee VirusScan Enterprise 8.8 Patch ...
»CVE-2016-8584
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which ...
»CVE-2016-8585
admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote au ...
»CVE-2016-8586
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows ...
»CVE-2016-8587
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote ...
»CVE-2016-8588
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote ...
»CVE-2016-8589
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote aut ...
»CVE-2016-8590
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote aut ...
»CVE-2016-8591
log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authent ...


Date published: 2017-05-01T00:00:01Z
Details

»FTC Releases Announcement on Identity Theft
Original release date: April 27, 2017 The Federal Trade Commission (FTC) recommends that cons ...
»Adobe Releases Security Updates for ColdFusion
Original release date: April 26, 2017 Adobe has released security updates to address a vulner ...
»Pre-Installed Applications Developed with Portrait Displays SDK Contain Critical Vulnerability
Original release date: April 25, 2017 Applications developed using the Portrait Displays soft ...
»IBM Releases Security Update
Original release date: April 25, 2017 IBM has released a security update to address a vulnera ...
»Drupal Releases Security Updates
Original release date: April 19, 2017 Drupal has released an advisory to address a vulnerabil ...
»Cisco Releases Security Updates
Original release date: April 19, 2017 Cisco has released updates to address several high-impa ...
»Mozilla Releases Security Updates
Original release date: April 19, 2017 Mozilla has released security updates to address a vuln ...
»Google Releases Security Updates for Chrome
Original release date: April 19, 2017 Google has released Chrome version 58.0.3029.81 for Win ...
»VMware Releases Security Updates
Original release date: April 18, 2017 VMware has released security updates to address vulnera ...
»Oracle Releases Security Bulletin
Original release date: April 18, 2017 Oracle has released its Critical Patch Update for April ...


Date published: not known
Details

»VB2016 video: Last-minute paper: A malicious OS X cocktail served from a tainted bottle
In a VB2016 last-minute presentation, ESET researchers Peter Kalnai ...
»Consumer spyware: a serious threat with a different threat model
Consumer spyware is a growing issue and one that can have serious c ...
»VB2016 paper: Debugging and monitoring malware network activities with Haka
In their VB2016 paper, Stormshield researchers Benoît Ancel and Meh ...
»VB2017: a wide ranging and international conference programme
We are proud to announce a very broad and very international progra ...
»John Graham-Cumming and Brian Honan to deliver keynote addresses at VB2017
Virus Bulletin is excited to announce John-Graham Cumming and Brian ...
»Virus Bulletin says a fond farewell to John Hawes
As VB's COO John Hawes moves on to new challenges, the team wish hi ...
»VB2016 paper: One-Click Fileless Infection
Symantec researchers Himanshu Anand and Chastine Menrige explain ho ...
»Mostly blocked, but still good enough: Necurs sending pump-and-dump spam
The Necurs botnet has started sending pump-and-dump spam. Almost al ...
»Why the SHA-1 collision means you should stop using the algorithm
Realistically speaking, if your software or system uses the SHA-1 h ...


Date published: not known
Details
Main Menu
· Home
Current Security News
 
US-CERT Current Activity

» FTC Releases Announcement on Identity Theft
[27 Apr 2017 08:55pm]

» Adobe Releases Security Updates for ColdFusion
[26 Apr 2017 07:03am]

» Pre-Installed Applications Developed with Portrait Displays SDK Contain Critical Vulnerability
[25 Apr 2017 04:15pm]

» IBM Releases Security Update
[25 Apr 2017 06:47am]

» Drupal Releases Security Updates
[19 Apr 2017 06:17pm]

» Cisco Releases Security Updates
[19 Apr 2017 06:14pm]

» Mozilla Releases Security Updates
[19 Apr 2017 06:04pm]

» Google Releases Security Updates for Chrome
[19 Apr 2017 06:02pm]

» VMware Releases Security Updates
[18 Apr 2017 02:34pm]

» Oracle Releases Security Bulletin
[18 Apr 2017 02:30pm]

***
US-CERT Alerts

» TA17-117A: Intrusions Affecting Multiple Victims Across Multiple Sectors
[27 Apr 2017 04:50pm]

» TA17-075A: HTTPS Interception Weakens TLS Security
[16 Mar 2017 06:40am]

» TA16-336A: Avalanche (crimeware-as-a-service infrastructure)
[30 Nov 2016 10:00pm]

» TA16-288A: Heightened DDoS Threat Posed by Mirai and Other Botnets
[14 Oct 2016 05:59pm]

» TA16-250A: The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations
[06 Sep 2016 04:29pm]

» TA16-187A: Symantec and Norton Security Products Contain Critical Vulnerabilities
[05 Jul 2016 08:50am]

» TA16-144A: WPAD Name Collision Vulnerability
[23 May 2016 05:38am]

» TA16-132A: Exploitation of SAP Business Applications
[11 May 2016 05:31am]

» TA16-105A: Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced
[14 Apr 2016 01:48pm]

» TA16-091A: Ransomware and Recent Variants
[31 Mar 2016 04:00pm]

***
Computerworld Security

» NSA ends surveillance tactic that pulled in citizens' emails, texts
[30 Apr 2017 08:01am]

» How seven mesh routers deal with Wi-Fi Protected Setup (WPS)
[28 Apr 2017 12:20pm]

» Your car will eventually live-stream video of your driving to the cloud
[28 Apr 2017 11:40am]

» IDG Contributor Network: Book Review: Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems
[27 Apr 2017 12:45pm]

» Ransomware attacks are taking a bigger toll on victims' wallets
[27 Apr 2017 12:26pm]

» BlackBerry KeyOne smartphone to launch in U.S. and Canada in late May
[27 Apr 2017 04:37am]

» Fitbit: One explodes, data from another used to charge husband with wife's murder
[26 Apr 2017 09:54am]

» Old Windows Server machines can still fend off hacks. Here's how
[26 Apr 2017 05:01am]

» How your company needs to train workers in cybersecurity
[25 Apr 2017 10:21am]

» Customers roast Microsoft over security bulletins' demise
[24 Apr 2017 12:49pm]

» Researchers remotely kill the engine of a moving car by hacking vulnerable car dongle
[24 Apr 2017 10:54am]

» Russian man receives longest-ever prison sentence in the U.S. for hacking
[24 Apr 2017 09:17am]

» FAQ: What is blockchain and how can it help business?
[24 Apr 2017 04:01am]

» How to minimize the risks of phishing scams
[24 Apr 2017 01:00am]

» There's now a tool to test for NSA spyware
[22 Apr 2017 05:43am]

***
Microsoft Security Advisories

» 3123479 - SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[14 Mar 2017 11:00am]

» 4010983 - Vulnerability in ASP.NET Core MVC 1.1.0 Could Allow Denial of Service - Version: 1.0
[27 Jan 2017 11:00am]

» 3214296 - Vulnerabilities in Identity Model Extensions Token Signing Verification Could Allow Elevation of Privilege - Version: 1.0
[10 Jan 2017 11:00am]

» 3181759 - Vulnerabilities in ASP.NET Core View Components Could Allow Elevation of Privilege - Version: 1.0
[13 Sep 2016 11:00am]

» 3174644 - Updated Support for Diffie-Hellman Key Exchange - Version: 1.0
[13 Sep 2016 11:00am]

» 3179528 - Update for Kernel Mode Blacklist - Version: 1.0
[09 Aug 2016 11:00am]

» 2880823 - Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[18 May 2016 11:00am]

» 3155527 - Update to Cipher Suites for FalseStart - Version: 1.0
[10 May 2016 11:00am]

» 3152550 - Update to Improve Wireless Mouse Input Filtering - Version: 1.1
[22 Apr 2016 11:00am]

» 3137909 - Vulnerabilities in ASP.NET Templates Could Allow Tampering - Version: 1.1
[10 Feb 2016 11:00am]

» 2871997 - Update to Improve Credentials Protection and Management - Version: 5.0
[09 Feb 2016 11:00am]

» 3118753 - Updates for ActiveX Kill Bits 3118753 - Version: 1.0
[12 Jan 2016 11:00am]

» 3109853 - Update to Improve TLS Session Resumption Interoperability - Version: 1.0
[12 Jan 2016 11:00am]

» 2755801 - Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge - Version: 53.0
[05 Jan 2016 11:00am]

» 3057154 - Update to Harden Use of DES Encryption - Version: 1.1
[08 Dec 2015 11:00am]

***


***
Network World Security

» Hackers leak 10 new Orange Is the New Black episodes after Netflix failed to pay ransom
[30 Apr 2017 09:25am]

» NSA ends surveillance tactic that pulled in citizens' emails, texts
[28 Apr 2017 05:23pm]

» Stealthy Mac malware spies on encrypted browser traffic
[28 Apr 2017 02:33pm]

» Google's Chrome will soon start warning you more about HTTP pages
[28 Apr 2017 01:21pm]

» Fight firewall sprawl with AlgoSec, Tufin, Skybox suites
[10 Apr 2017 04:32am]

» Review: Canary Flex security camera lives up to its name
[24 Mar 2017 07:01am]

» Smackdown: Office 365 vs. G Suite management
[16 Mar 2017 07:01am]

» Zix wins 5-vendor email encryption shootout
[13 Mar 2017 04:00am]

» Review: vArmour flips security on its head
[06 Mar 2017 03:50am]

» 5 open source security tools too good to ignore
[21 Feb 2017 07:12am]

» Review: Samsung SmartCam PT network camera
[15 Feb 2017 07:00am]

» Review: Arlo Pro cameras offer true flexibility for home security
[09 Feb 2017 07:01am]

» Face-off: Oracle vs. CA for identity management
[26 Jan 2017 10:30am]

» NSA ends surveillance tactic that pulled in citizens' emails, texts
[28 Apr 2017 05:23pm]

» Stealthy Mac malware spies on encrypted browser traffic
[28 Apr 2017 02:33pm]

***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Welcome
Username:

Password:




Remember me

[ ]

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}