Security, Compliance Remain Biggest Concerns Over Cloud

A new survey into cloud concerns undertaken by database security firm HexaTier provides no surprises: security risks (44%) followed by compliance and regulation (29%) are the two biggest factors preventing greater cloud adoption (although we are specifically talking about database as a service rather than cloud in general).
read more

Continue reading

Code Execution Flaw Found in Lhasa Decompression Library

Cisco reported on Thursday that it has discovered a vulnerability in the Lhasa library that allows attackers to execute arbitrary code on targeted systems.
Lhasa is an open source tool and library used to parse and decompress LHA (.lzh) archives, and it’s offered as an alternative for the UNIX LHA utility.
read more

Continue reading

Researchers Can Now Register to Hack The Pentagon

Department of Defense Partners With HackerOne on First Federal Government Bug Bounty Program
Earlier this month, the Department of Defense (DoD) announced "Hack the Pentagon," a new bug bounty program that will award security researchers who can discover vulnerabilities on the Pentagon's public web pages.
read more

Continue reading

“KimcilWare” Ransomware Targets Magento Websites

A new piece of ransomware apparently designed to encrypt files on websites running the popular Magento ecommerce solution has been spotted in the wild.
The threat, dubbed “KimcilWare,” has been analyzed by researchers of the Malware Hunter Team and Lawrence Abrams of Bleeping Computer.
read more

Continue reading