Security News > 2021

The Different Flavors of Cyber Resilience
2021-03-03 12:03

According to MITRE, cyber resilience "Is the ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on cyber resources." The need for cyber resilience arises from the growing realization that traditional security measures are no longer enough to assure sufficient information, data, and network security. The Department of Homeland Security's Cyber Resilience Review offers guidance on how to evaluate an organization's operational resilience and cybersecurity practices.

Encoded Message in the Perseverance Mars Lander’s Parachute
2021-03-03 12:00

NASA made an oblique reference to a coded message in the color pattern of the Perseverance Mars Lander ‘s parachute. More information.

It's not easy being green: EV HTTPS cert seller Sectigo questions Chrome's logic in burying EV HTTPS cert info
2021-03-03 11:45

Sectigo's chief compliance officer has hit out at Google for minimizing the visibility of Extended Validation HTTPS certificates in Chrome. In a chat with The Register, Sectigo CCO Tim Callan said his biz, which among other things is one of the biggest sellers of EV HTTPS certificates, was "Going to remove street and postal information from all of our public sites," seeing as Google thinks no one cares where a business is based.

Hacking is not a crime – and the media should stop using 'hacker' as a pejorative
2021-03-03 11:00

This week's motion is: Hacking is not a crime, and the media should stop using 'hacker' as a pejorative. Now, arguing FOR the motion is ALYSSA MILLER.... Using the term "Hacker" to describe cyber criminals is an unfortunate habit that plagues modern media.

Microsoft Expands Secured-core to Servers, IoT Devices
2021-03-03 09:49

Microsoft this week announced Secured-core Server and Edge Secured-core, two solutions aimed at improving the security of servers and connected devices. Initially announced in 2019, Secured-core is the result of a partnership between Microsoft and hardware manufacturers, and its goal is to add a security layer that combines identity, virtualization, operating system, hardware and firmware protection capabilities.

Cash App phishing kit deployed in the wild, courtesy of 16Shop
2021-03-03 08:29

The developer of the 16Shop phishing platform has added a new component that targets users of the popular Cash App mobile payment service. 16Shop is a complex phishing kit from a developer known as DevilScream, who set up a protection mechanism against unlicensed use and research activity.

TPG buys Thycotic, immediately merges it with Centrify to create ~$230m access management monster
2021-03-03 07:58

Private equity group TPG has acquired security vendor Thycotic and announced it will merge it with another recent acquisition, Centrify. TPG in January announced its intention to acquire a majority stake in privileged access management vendor Centrify from fellow private equiteer Thoma Bravo.

Microsoft promises end-to-end encrypted Teams calls for some, invites you to go passwordless with Azure AD
2021-03-03 07:24

Microsoft has said it will add end-to-end encryption for some one-to-one Teams calls later this year - and urged folks to move away from using passwords with Azure AD. The Teams improvements, announced at the tech giant's Ignite conference this week, will be available "To commercial customers in preview in the first half of this year." Video conferencing rival Zoom offers end-to-end encryption with a few caveats and additional steps, and that appears to be more or less the approach Microsoft will take, too.

Proliferation of sneakerbots across industries: The long tail of DIY bot operators
2021-03-03 06:00

Swing states were heavily targeted with false information posted by fake social media accounts created by bot operators. There is currently little being done to strike back against or even frustrate bot operators.

Eugene Kaspersky says cyber-crooks coined it during COVID and will take a break to spend their loot
2021-03-03 05:58

Kaspersky CEO Eugene Kaspersky has suggested that the end of the COVID-19 pandemic will bring a slowdown in cyber-crime. This theory was swiftly shot down by Australian infosec boffin, Dr. Greg Austin, a professor of Cyber Security, Strategy and Diplomacy at the University of New South Wales.