Security News > 2021

Why cyberinsurance can save your business
2021-01-14 12:00

"In its early days, cyberinsurance coverage was offered through either expensive, highly manuscripted policy forms or cheap, sublimited endorsements to other policies," said Dan Burke, senior vice president at Woodruff Sawyer and Company, in his article Cyber 101: Understand the Basics of Cyber Liability Insurance. It's important to be realistic, in that cyberinsurance protects against the costs of cyber breaches, not the actual attack.

Entrust acquires HyTrust to offer identity, encryption and security policy control for cloud environments
2021-01-14 11:53

By acquiring HyTrust, Entrust adds a critical management layer for encryption, cryptographic keys, and cloud security policy to its digital security solutions, serving the data protection and compliance needs of organizations accelerating their digital transformations. "HyTrust solutions help enterprises manage, automate and scale security controls across computing environments. Now, customers can turn to Entrust as a single source for high-assurance data protection, identity and compliance solutions that allow enterprises to encrypt data and enforce security policy across virtualized, public and hybrid cloud environments."

Over 70 Vulnerabilities Will Remain Unpatched in EOL Cisco Routers
2021-01-14 11:27

Cisco this week announced that it does not plan on addressing tens of vulnerabilities affecting some of its small business routers. "Cisco has not released and will not release software updates to address the vulnerabilities described []. The Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers have entered the end-of-life process. Customers are advised to refer to the end-of-life notices for these products," the company underlines.

EU Court Opinion Leaves Facebook More Exposed Over Privacy
2021-01-14 09:46

Any EU country can take legal action against companies like Facebook over cross-border violations of data privacy rules, not just the main regulator in charge of the company, a top court adviser said Wednesday. The preliminary opinion is part of a long-running legal battle between Facebook and Belgium's data protection authority over the company's use of cookies to track the behavior of internet users, even those who weren't members of the social network.

Office January security updates fix remote code execution bugs
2021-01-14 09:32

Microsoft addresses important severity remote code execution vulnerabilities affecting multiple Office products in the January 2021 Office security updates released during this month's Patch Tuesday. In total, this month the company released 26 security updates and 5 cumulative updates for 7 different products, fixing 11 vulnerabilities that could allow attackers to escalate privileges or execute arbitrary code remotely on systems running vulnerable software.

Oracle Database 21c introduces 200+ innovations
2021-01-14 08:18

Oracle announced that Oracle Database 21c, the latest version of the world's leading converged database, is available on Oracle Cloud, including the Always Free tier of Oracle Autonomous Database. "Oracle Database 21c continues our strategy of delivering the world's most powerful converged database engine," said Andrew Mendelsohn, executive vice president, database server technologies, Oracle.

Telegram-based phishing service Classiscam hits European marketplaces
2021-01-14 07:06

Some of the brands abused through this scam are extremely popular in Europe and include LeBonCoin, Allegro, OLX, Sbazar, FAN Courier, Lalafo, Kufar and DHL. Scam expanding to Europe. The scammers publish ads on popular marketplaces and classifieds claiming to offer various products at low prices.

Is a remote workforce making your organisation less secure?
2021-01-14 07:00

Last year your bosses embraced remote working because, let's face it, none of us had a choice. Now many companies are wondering: will we ever need those big glass buildings again? Research shows more than half of companies are going to cut back on office space in 2021, and that means work-from-home is becoming a permanent feature of professional life.

Minimizing cyberattacks by managing the lifecycle of non-human workers
2021-01-14 06:00

Organizations frequently only apply access controls to humans, despite the risks associated with cyberattacks and data breaches linked to non-human workers and their privileged access to sensitive information. Organizations must track and manage the lifecycle approach to non-human workers.

Most containers are running as root, which increases runtime security risk
2021-01-14 05:30

Among its findings, the report states that while 74 percent of customers are scanning before deployment, still 58 percent of containers are running as root. There are some containers that should run as root-security and system daemons for example-but this is a small portion of total containers.