Security News > 2021 > June

Swedish Public Health Agency Says Disease Database Targeted in Cyberattacks
2021-06-01 12:41

The Swedish Public Health Agency is currently investigating several attempts to hack into SmiNet, a database that stores reports of infectious diseases, including COVID-19 cases. SmiNet was shut down on Thursday, after the agency identified several attempts to gain unauthorized access to the database, but it was restored by Friday night.

A CISO’s Guide: Mitigating the Human Risk Factor
2021-06-01 11:42

Security teams deploy several technologies to protect their attack vectors. Verizon's 2021 data breach report shows phishing is responsible for the vast majority of breaches and Business Email Compromises were the second most common form of social engineering.

Cybersecurity M&A Roundup: 36 Deals Announced in May 2021
2021-06-01 11:36

Both companies provide - among several others - cybersecurity services, and Ascend said the deal will enable it to offer a brader portfolio of services and solutions, including network monitoring and cybersecurity assessments. State-owned communications and cybersecurity firm Kordia has acquired Base2, which provides managed IT, network, and cybersecurity solutions.

Security Vulnerability in Apple’s Silicon “M1” Chip
2021-06-01 11:26

The website for the M1racles security vulnerability is an excellent demonstration that not all vulnerabilities are exploitable. Be sure to read the FAQ through to the end. EDITED TO ADD: Wired article.

Meat-packing Giant JBS USA Shuts Down Systems Following Cyberattack
2021-06-01 11:23

JBS USA, the US subsidiary of the world's largest meat processing company, said Monday that some operations were shut down following a cyberattack that affected its North American and Australian IT network. Headquartered in Greeley, Colorado, JBS USA is a global food company wholly owned by Brazil-based JBS S.A., the largest meat processing firm in the world.

Increase confidence in public cloud security: Integrate Intel SGX, says G-Core Labs Cloud
2021-06-01 07:30

That's why last December we were one of the first in the world to launch support for the Intel SGX encryption standard in our public cloud. This technology dramatically enhances data protection with built-in cloud management tools from Intel.

How do I select a data analytics solution for my business?
2021-06-01 06:00

Data analytics is and in-depth way of knowing your data and making the most of it, while protecting your assets. To select a suitable data analytics solution for your business, you need to think about a variety of factors.

Cybersecurity industry analysis: Another recurring vulnerability we must correct
2021-06-01 05:30

Gartner's recent Hype Cycle for Application Security report, and Forrester's The State of Application Security 2021 report - both bibles for security experts that undoubtedly help to shape their program and potential product adoption - are almost entirely tools-focused. Security tooling is a must-have, but we need to look wider and restore balance to the people component of security defense.

Helping security teams respond to gaps in security and compliance programs with Qualys CSAM
2021-06-01 05:00

While traditional IT teams and inventory tools provide an IT view of inventory, software support, and licensing, security teams are looking for the security context of assets such as assets that are not running security tools, detection of unauthorized software, internet visibility, and more. Security tools like EDR help secure assets, but do not let security teams know which critical assets are not running EDR, or if databases are visible from the internet? All security teams have defined authorized and unauthorized software policies.

EUCC receives first EU cybersecurity certification scheme
2021-06-01 04:30

In July 2019, the EUCC was the first candidate cybersecurity certification scheme request received by the EU Agency for Cybersecurity under the Cybersecurity Act. This scheme aims to serve as a successor to the currently existing schemes operating under the SOGIS MRA. It covers the certification of ICT products, using the Common Criteria ISO/IEC 15408 and is the foundation of a European Cybersecurity certification framework.