After a seemingly endless barrage of cyberattacks, debate is heating up on hitting back at hackers where it hurts.
read more
How Do You Define Prevention?
In discussions about cybersecurity, a word that gets used a lot is “prevention.” How do you prevent cyberattacks before they succeed? Will the cybersecurity measures currently in place offer the prevention of losses due to a cyberattack? What part of an attacker’s playbook does prevention actually stop?
read more
Google to Distrust WoSign, StartCom Certificates
Google announced on Monday that it has decided to distrust certificates from WoSign and StartCom due to their failure to maintain the high standards expected of certificate authorities (CAs).
read more
Google Discloses Windows Zero-Day Vulnerability
Google has disclosed a Windows zero-day vulnerability after Microsoft failed to release a patch within the 7-day deadline the search giant gives vendors when it finds a flaw that is actively exploited by malicious actors.
read more
PCI 3.2 Compliant Organizations Are Likely GDPR Compliant
PCI DSS version 3.1 will be retired on October 31, 2016, with version 3.2 being the only valid version beginning the 1st of November. From that date, any new validation of PCI compliance will have to be against version 3.2. The new requirements will, however, be considered 'best practices' until Feb. 1, 2018 when they will be mandatory.
read more
Dutchman ‘Who Almost Broke the Internet’ to Go on Trial
A Dutchman accused of launching an unprecedented cyberattack that reportedly "almost broke the internet" is to go on trial Tuesday on charges of masterminding the 2013 incident that slowed down web traffic world-wide.
read more
“Shadow Brokers” Leaks Servers Allegedly Hacked by NSA
The group calling itself Shadow Brokers has leaked more files, including a list of servers allegedly used by the NSA-linked Equation Group in its attacks.
read more
U.S. Should Strike Back at Cyberattackers: Report
The US government and private sector should strike back against hackers to counter cyberattacks aimed at stealing data and disrupting important computer networks, a policy report said Monday.
read more
How Cloud App Visibility Helps Wrangle Shadow IT
What Does an Organization Need to do to Get Shadow IT Under Control?
read more
Nymaim Starts Using PowerShell to Download Payload
A recently discovered variant of the Nymaim dropper brings several new features and capabilities, including new obfuscation and delivery methods, the use of PowerShell, and what researchers call an interesting anti-analysis and anti-detection mechanism.
read more

