Security News > 2021 > January

Microsoft Defender to enable full auto-remediation by default
2021-01-18 13:30

Microsoft will enable fully automated threat remediation by default for Microsoft Defender for Endpoint customers who have opted into public previews starting next month, on February 16, 2021. This change of the default automation level from Semi to Full comes after finding that organizations using full automation by default were more successful in remediating and containing threats.

OpenWRT Forum user data stolen in weekend data breach
2021-01-18 13:23

The OpenWRT forum, a large community of enthusiasts of alternative, open-source operating systems for routers, announced a data breach. Forum administrators posted the announcement in a high-visibility area, explaining what happened and the risks to users stemming from exposing their data.

Rob Joyce Appointed Director of Cybersecurity at NSA
2021-01-18 12:18

The U.S. National Security Agency on Friday announced that Rob Joyce, an official who is highly respected in the cybersecurity community, has been named the agency's new director of cybersecurity. Joyce, who according to his LinkedIn profile has been working for the Defense Department for the past 32 years, replaces Anne Neuberger, who has been appointed Deputy National Security Advisor for Cyber and Emerging Technology by the upcoming Biden administration.

Naked Security Live – Staying safe online at home (especially if you’re homeschooling!)
2021-01-18 11:33

Here's our latest Naked Security Live talk, where we discuss the tips in our article Home schooling- how to stay secure. Even if you don't have school-age children, or aren't living in a region where schools are currently closed, the video contains a wide range of advice that will help you stay secure at home anyway.

FBI warns of vishing attacks stealing corporate accounts
2021-01-18 10:00

The Federal Bureau of Investigation has issued a notification warning of ongoing vishing attacks attempting to steal corporate accounts and credentials for network access and privilege escalation from US and international-based employees. In multiple cases, once they gained access to the company's network, the threat actors gained greater network access than expected allowing them to escalate privileges using the compromised employees' accounts.

Port53 launches SOC-as-a-Service, offering 24/7 monitoring, detection, and response
2021-01-18 08:49

Port53 Technologies announced the launch of their new SOC-as-a-Service, offering 24/7 monitoring, detection, and response. Port53 harnesses the power of Cisco SecureX to provide a completely unique SOC-as-a-Service offering for the SMB and SME market.

Baffle DPS on AWS simplifies tokenization and encryption of data stored in Amazon RDS
2021-01-18 08:45

Baffle announced that its Data Protection Services on AWS dramatically simplifies tokenization and encryption of data stored in Amazon Relational Database Service environments without any application code modifications while supporting a Bring Your Own Key or Hold Your Own Key model. As an AWS Select Technology Partner, Baffle DPS gives enterprises the ability to instantly apply data-centric security for data stored in AWS without any application changes.

Prosperoware adds data protection features for Office 365, supports Azure for storage
2021-01-18 08:36

Prosperoware announces data protection features for Office 365 including OneDrive, SharePoint Online, Teams, and support Azure for storage location as part of its CAM platform. Faced with increasing data loss concerns and regulatory oversight, organizations are looking for improved capabilities to protect data and comply with privacy and cybersecurity regulations.

Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture
2021-01-18 07:05

Last week ended with news that the venerable infosec mailing list Bugtraq was being shutdown at the end of the month. From its first posts in November 1993, Bugtraq aimed to get details of vulnerabilities, as well as defence and exploitation techniques, onto netizens' radar, and discussed among admins and security researchers.

Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture
2021-01-18 07:05

Last week ended with news that the venerable infosec mailing list Bugtraq was being shutdown at the end of the month. From its first posts in November 1993, Bugtraq aimed to get details of vulnerabilities, as well as defence and exploitation techniques, onto netizens' radar, and discussed among admins and security researchers.