Security News

Industries with critical infrastructure are at greater risk during the pandemic
2020-04-09 13:49

Fewer people working onsite due to the pandemic means critical infrastructure is at greater risk in industries like oil and gas, manufacturing, and utilities-and most organizations don't have the right tools in place, according to Dave Weinstein, chief security officer at Claroty, a provider of OT software. Dave Weinstein: A lot of the blocking and tackling of remote access management isn't happening, so there's clearly a need for that; certainly in the coronavirus age, but even before the pandemic occurred and even after it goes away.

Cisco ‘Critical Update’ Phishing Attack Steals Webex Credentials
2020-04-09 13:00

An ongoing phishing campaign is reeling in victims with a recycled Cisco security advisory that warns of a critical vulnerability. The campaign urges victims to "Update," only to steal their credentials for Cisco's Webex web conferencing platform instead. The campaign is looking to leverage the wave of remote workers who, in the midst of the coronavirus pandemic have come to rely on online conferencing tools like Webex.

Google removes Android VPN  with ‘critical vulnerability’ from Play Store
2020-04-09 09:48

Google has removed an Android VPN program from the Google Play store after researchers notified it of a critical vulnerability. VPNpro, a company that reviews and advises on VPN products, warned in February of a vulnerability in the product that could cause a man in the middle attack, enabling an intruder to insert themselves between the user and the VPN service.

Accenture Acquires Critical Infrastructure Protection Firm Revolutionary Security
2020-04-08 19:33

Consulting giant Accenture announced this week that it has acquired critical infrastructure protection firm Revolutionary Security for an undisclosed sum. A privately held startup, Philadelphia-based Revolutionary Security provides security solutions for both information technology and operational technology environments.

Google Patches Critical RCE Vulnerabilities in Android's System Component
2020-04-07 13:00

Google this week released the April 2020 set of security patches for the Android operating system to address over 50 vulnerabilities, including four critical issues in the System component. "The most severe of these issues is a critical security vulnerability in the System component that could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process," Google notes in an advisory.

Qualys VMDR: Discover, prioritize, and patch critical vulnerabilities in real time
2020-04-07 04:00

VMDR continuously assesses these assets for the latest vulnerabilities and applies the latest threat intel analysis to prioritize actively exploitable vulnerabilities. The reason is, if you look at the statistics over the last 10 years, you would see that the total number of vulnerabilities which get discovered in a year, maybe let's say 15,000 to 16,000 of vulnerabilities that are getting discovered, out of those vulnerabilities, only a handful, like 1000 vulnerabilities get exploited.

These are the countries trying to hack US critical infrastructure
2020-04-06 14:45

Robert Lee, founder & CEO of Dragos, Inc., speaks with Dan Patterson about which countries pose a threat to US industrial infrastructures.

Why critical infrastructure is vulnerable to cyberattacks
2020-04-06 14:41

Robert Lee, founder and CEO of Dragos, discusses the dangers cyberattacks pose to critical industrial infrastructures. Dan Patterson: What do we mean when we talk about this abstract idea of infrastructure and connected infrastructure?

Why critical infrastructure is vulnerable to cyberattacks
2020-04-06 14:39

Robert Lee, founder and CEO of Dragos, discusses the dangers cyberattacks pose to critical industrial infrastructures.

These are the countries trying to hack US critical infrastructure
2020-04-06 14:00

Dan Patterson speaks with cybersecurity expert Robert Lee about how Russia, Iran, China, and North Korea pose a threat to US industrial infrastructures. Robert Lee: The [countries] we've seen over the years would be Russia, Iran, China, North Korea-the normal players.