Security News > 2020 > December

New study: DNS spoofing doubles in six years ... albeit from the point of naff all
2020-12-01 07:06

Boffins from the University of Southern California's Information Sciences Institute have crunched six years and four months of data, and found that DNS spoofing, while uncommon, has doubled during that time. In their paper, the US academics explain, "DNS spoofing can be accomplished by proxying, intercepting and modifying traffic; DNS injection, where responses are returned more quickly than the official servers; or by modifying configurations in end hosts."

Incomplete 'Go SMS Pro' Patch Left Millions of Users' Data Still Exposed Online
2020-12-01 06:13

A week after cybersecurity researchers disclosed a flaw in the popular GO SMS Pro messaging app, it appears the developers of the app are silently taking steps to fix the issue from behind the scenes. Although the behavior was observed on version 7.91 of GO SMS Pro for Android, the app makers have since released three subsequent updates, two of which were pushed to the Google Play Store after public disclosure of the flaw and Google's removal of the app from the marketplace.

Why microlearning is the key to cybersecurity education
2020-12-01 06:00

A different kind of training is needed to become truly "Cyber secure" - a training that keeps the idea of cybersecurity top of mind and part of the critical information retained in the brain. That's not the case with cybersecurity education and training: attacks are ever-changing, they differ based on the targeted demographic, current affairs, and the environment we are living in.

Foiling RaaS attacks via active threat hunting
2020-12-01 05:30

One of the biggest issues organizations have today is ransomware attacks. Basically, what they do is they sell access to their attacks.

Retail CISOs and the areas they must focus on
2020-12-01 05:00

In this interview, Matt Cooke, cybersecurity strategist, EMEA at Proofpoint, discusses the cybersecurity challenges for retail organizations and the main areas CISOs need to focus on. What areas should a CISO of a retail organization be particularly worried about?

Theoretical Attack on Synthetic DNA Orders Highlights Need for Better Cyber-Biosecurity
2020-12-01 04:34

Threat actors could target DNA researchers with malware in an effort to modify synthetic DNA orders and create pathogens or toxins, researchers warn. In a newly published article in Nature, a group of academic researchers from Israel's Interdisciplinary Center Herzliya and Ben-Gurion University of the Negev detail a cyberattack that exploits gaps within the security of the DNA procurement process for malicious purposes.

Malware may trick biologists into generating dangerous toxins in their labs
2020-12-01 04:30

An end-to-end cyber-biological attack, in which unwitting biologists may be tricked into generating dangerous toxins in their labs, has been discovered by Ben-Gurion University of the Negev researchers. Malware could easily replace a short sub-string of the DNA on a bioengineer's computer so that they unintentionally create a toxin producing sequence.

Worldwide SD-WAN market to reach $43 billion by 2030
2020-12-01 04:00

Due to the rising adoption of IoT and the growing utilization of big data, the valuation of the global SD-WAN market is predicted to increase from $1.4 billion to $43 billion from 2019 to 2030. Between the solution and service categories, under the offering segment of the SD-WAN market, the former is expected to register higher revenue growth in the market in the coming years.

The CISO’s guide to rapid vendor due diligence
2020-12-01 03:30

Vendors are at the heart of many companies’ processes and activities, and their numbers are increasing. But the process of onboarding vendors has become complicated because of concerns about...

Windows 10 20H2 update fixes broken in-place upgrade feature
2020-12-01 03:00

Microsoft has released a new cumulative update for Windows 10 20H2 that fixes a bug preventing users from performing in-place upgrades with the Microsoft Media Creation Tool. An in-place upgrade is when you reinstall Windows 10 with files downloaded from Microsoft's servers without deleting existing apps or files.