The infamous Carbanak malware is now capable of using Google services for command and control (C&C) communication, Forcepoint security researchers warn.
read more
US-CERT Issues Warning After Hackers Offer SMB Zero-Day
The United States Computer Emergency Readiness Team (US-CERT) has issued a warning after the threat group calling itself Shadow Brokers has offered to sell what it claims to be a zero-day exploit targeting the Server Message Block (SMB) network file sharing protocol.
read more
Cyber Skills Gap Quantified in Terms of Supply and Demand
Gaining and retaining security talent is a major headache for almost all security leaders — indeed, the consensus is that the world is suffering under a chronic security skills gap. But most of the evidence for this skills gap is empirical; there is little hard evidence in facts and figures.
read more
What’s Ahead for ICS Cyber Security in 2017
The new year is only a couple of weeks old and there have already been several ICS related security incidents in the news. The media often sensationalizes these incidents. This is creating hype and growing worldwide awareness and concern over the threat of cyber attacks against industrial and critical physical infrastructures. I believe that 2017 will be the year ICS security becomes a mainstream media topic.
read more
Oracle Patches 270 Vulnerabilities Across Product Portfolio
Oracle on Tuesday released its first Critical Patch Update (CPU) for 2017. The software update addresses 270 security issues across its products, 121 of which were found in Oracle E-Business Suite.
read more
Facebook Awards $40,000 Bounty for ImageTragick Hack
A researcher claims to have received a $40,000 bounty from Facebook for finding a remote code execution vulnerability introduced by the ImageMagick image processing suite.
read more
Security Bug Lurked in Nexus 9 Kernel for Two Years
A security vulnerability that allowed a privileged attacker to arbitrary write values within kernel space lurked in Nexus 9’s kernel for two years before being patched, IBM security researchers reveal.
read more
Responsible Disclosure – Critical for Security, Critical for Intelligence
Not Adhering to Responsible Disclosure has the Potential to Amplify the Threats Posed by Certain Vulnerabilities and Incidents
read more
Critical Infrastructure Security: Risks Posed by IT Network Breaches
read more
Continue readingCredential Stuffing: a Successful and Growing Attack Methodology
With a database of 1 million stolen credentials, criminals using a credential stuffing attack with a tool such as Sentry MBA could expect to compromise roughly 10,000 accounts on a targeted but uncompromised site. In 2016, 3.3 billion user credentials were spilled onto the internet, according to figures from Shape Security's just released 2017 Credential Spill Report.
read more


