Security News

Infosec products of the month: November 2021
2021-12-01 03:45

An Imperva Snapshot assessment lets teams assess the status of their databases and the data stored, to identify non-compliance with privacy regulations as well as compliance requirements for cloud data stores. iStorage datAshur SD offers data storage solution to securely share and scale unlimited encrypted data.

EU needs more cybersecurity graduates, says ENISA infosec agency – pointing at growing list of master's degree courses
2021-11-26 16:37

The EU needs more cybersecurity graduates to plug the political bloc's shortage of skilled infosec bods, according to a report from the ENISA online security agency. In a new report titled "Addressing the EU Cybersecurity Skills Shortage and Gap Through Higher Education", academics Jason Nurse and Konstantinos Adamos, together with ENISA's Athanasios Grammatopoulos and Fabio Di Franco, said the European Union needs to get more students signing up for cybersecurity degrees.

New infosec products of the week: November 26, 2021
2021-11-26 06:30

Boxcryptor protects business data in Microsoft Teams with end-to-end encryption features. Via the personal app, there is the possibility to access encrypted data in the personal OneDrive.

Crypto for cryptographers! Infosec types revolt against use of ancient abbreviation by Bitcoin and NFT devotees
2021-11-23 18:45

Infosec must "Reclaim" the word crypto from people who trade in Bitcoins and other digital currencies, according to industry veteran Bruce Schneier - and it seems some Reg readers agree. "I have long been annoyed that the word 'crypto' has been co-opted by the blockchain people, and no longer refers to 'cryptography'," blogged Schneier in a classically brief post on Monday.

Infosec bods: After more than a year, Sky gets round to squashing hijacking bug in 6m home broadband routers
2021-11-23 07:31

Sky has fixed a flaw in six million of its home broadband routers, and it only took the British broadcaster'n'telecoms giant a year to do so, infosec researchers have said. If an attack was successful, their router would fall under the attacker's control, allowing the crook to open up ports to access other devices on the local network, change the LAN's default DNS settings to redirect browsers to malicious sites, reconfigure the gateway, and cause other general mischief and irritation.

New infosec products of the week: November 19, 2021
2021-11-19 07:00

The new version features a modern design, increased productivity capabilities, and enhanced security and privacy features. Palo Alto Networks Prisma Cloud 3.0 protects cloud environments from development to runtime.

FBI spams thousands with fake infosec advice after 'software misconfiguration'
2021-11-15 02:30

The United States Federal Bureau of Investigation has admitted that a software misconfiguration let parties unknown send email from its servers. A statement from the Bureau, dated November 14th, states that the agency "Is aware of a software misconfiguration that temporarily allowed an actor to leverage the Law Enforcement Enterprise Portal to send fake emails".

ChaosDB: Infosec bods could pull anyone's plaintext Azure Cosmos DB keys at will from Microsoft admin tools
2021-11-12 19:19

An astonishing piece of vulnerability probing gave infosec researchers a way into to Microsoft's management controls for Azure Cosmos DB - with full read and write privileges over customer databases. The so-called ChaosDB vuln gave Wiz researchers "Access to the control panel of the underlying service" that hosts Azure Cosmos, Microsoft's managed cloudy document database service, they said.

New infosec products of the week: November 12, 2021
2021-11-12 06:30

iStorage datAshur SD offers data storage solution to securely share and scale unlimited encrypted data. Rather than the classic USB flash-drive design of incorporating fixed memory, the brand new datAshur SD is designed with an integrated microSD Card slot which enables consumers to use one drive with as many iStorage microSD Cards, in varying capacities, as required, ultimately offering a data storage solution to securely share and scale unlimited encrypted data.

Shotgun targeting of malware attacks will be the defining infosec theme of 2022, reckons Sophos
2021-11-09 19:30

Future malware and ransomware infections will consist of "Shotgun attacks with pinpoint targeting", according to Sophos' 2022 threat report. As if that wasn't enough, the British infosec biz reckons established commodity malware attacks will end up delivering ever more ransomware, while extortion tactics used by ransomware gangs will become more diverse and intense - with the aim of browbeating victims into handing over cash.