Security News

Malware attack that crippled Mumbai's power system came from China, claims infosec intel outfit Recorded Future
2021-03-01 16:05

Security intelligence firm Recorded Future's Insikt Group has written a paper alleging China was behind attacks on India's electricity grid. The attack is considered the probable source of Mumbai's power outage in October of the same year.

North Korea infected infosec bods with backdoors via dodgy blog pages, Visual Studio files – Google
2021-01-26 04:45

North Korea's hackers homed in on specific infosec researchers and infected their systems with a backdoor after luring them to a suspicious website, Google revealed on Monday. "The researchers have followed a link on Twitter to a write-up hosted on blog.br0vvnn[.]io, and shortly thereafter, a malicious service was installed on the researcher's system and an in-memory backdoor would begin beaconing to an actor-owned command and control server," said Googler Adam Weidemann.

Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture
2021-01-18 07:05

Last week ended with news that the venerable infosec mailing list Bugtraq was being shutdown at the end of the month. From its first posts in November 1993, Bugtraq aimed to get details of vulnerabilities, as well as defence and exploitation techniques, onto netizens' radar, and discussed among admins and security researchers.

Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture
2021-01-18 07:05

Last week ended with news that the venerable infosec mailing list Bugtraq was being shutdown at the end of the month. From its first posts in November 1993, Bugtraq aimed to get details of vulnerabilities, as well as defence and exploitation techniques, onto netizens' radar, and discussed among admins and security researchers.

How good are you at scoring security vulnerabilities, really? Boffins seek infosec pros to take rating skill survey
2021-01-08 09:30

By running a survey on whether infosec bods think the Common Vulnerability Scoring System is a useful tool for assessing security flaws, Dr Zinaida Benenson of Friedrich-Alexander Universität Erlangen-Nürnberg's IT Security Infrastructure Lab in Germany hopes to further the infosec world's understanding of how reliable the system really is. While the survey hopes to gain up to 300 respondents, Benenson was coy about precisely what she's hoping to prove or disprove, but she did drop The Register a hint about the current state of CVSS scoring.

Think you’re hot stuff when it comes to infosec? Prove it
2021-01-05 07:00

When it comes to cybersec certifications, GIAC is the gold standard. The organisation takes pride in certifications that "Rather than skimming the surface of different skillsetsare a mile deep for specialised job-focused tasks." And GIAC exams with Cyberlive don't just test you on the theory, but show you've proven your skills in lab-based situations.

2021 will overburden already stressed infosec teams
2020-12-30 06:00

While in 2020 organizations were focused on adapting existing technology to borderless and disconnected environments, we will see a massive shift to cloud-native solutions in 2021. In addition to new attacks on container-based environments, 2021 will bring the heightened threat of ransomware and new solutions to combat disinformation.

Special minisode: “20 years of cyberthreats that shaped infosec” [Podcast]
2020-12-14 01:14

Naked Security's Paul Ducklin interviews Sophos expert John Shier about his recently published paper, "20 years of cyberthreats that shaped information security". Join John on a dizzying journey all the way from legendary viruses such as ILOVEYOU and Code Red, which flooded the internet in 2000, to present-day ransomware gangs like Ryuk and REvil, who are extorting millions of dollars in blackmail money per attack.

No Xmas office party? Missing infosec pals and colleagues? Want to listen to DJs who also happen to be cyber warriors?
2020-11-23 10:15

Locked up indoors with nothing to do as the evenings draw closer? If lighthearted chats about cyber security are your thing, followed up by some banging dance tunes, then we have just the event - all in the name of charity, of course. The Cyber House Party launched this summer with the inaugural shindig held on 3 June and the second on 29 October, pulling in a total of 750 attendees and raising £10,000 in donations.

Manchester United working with infosec experts to 'minimize ongoing IT disruption' caused by 'cyber attack'
2020-11-21 15:41

Manchester United is working with infosec pros to "Minimize the ongoing IT disruption" that it says was caused by an assault on its tech systems. "In a statement, the club said:"Manchester United Plc can confirm that the club has experienced a cyber attack on its systems.