Security News

Sophos XG firewalls hacked, hotfix ready. Texts wreck Apple iThings. Yup, business as usual in infosec world
2020-04-26 12:04

Sophos XG Firewall hacked in the wild - hotfix available. Sophos has rushed out a hotfix for its XG Firewall products to close an SQL injection vulnerability - after hackers were spotted exploiting the hole in the wild.

New infosec products of the week: April 24, 2020
2020-04-24 05:00

Trustwave Security Colony delivers resources, playbooks and expertise to bolster security posture. Trustwave Security Colony is based on thousands of hours of actual consulting projects helping organizations implement new information security programs and heightening levels of security maturity.

Ministry of Defence lowers supplier infosec standards thanks to COVID-19 outbreak
2020-04-20 08:15

Security standards for defence contractors have been lowered thanks to the coronavirus outbreak, Britain's Ministry of Defence has told its suppliers. In an Industry Security Notice published to an obscure corner of GOV.UK, the ministry said it is suspending the need for its suppliers to have the Cyber Essentials Plus security certification.

New infosec products of the week: April 17, 2020
2020-04-17 06:00

Corsa Security Orchestrator offers a single-pane-of-glass view, enabling network security professionals to quickly and easily add more firewall capacity as their traffic inspection needs grow, without having to configure multiple elements. Advanced Security for Zoom ensures the organization has secure video conferencing and collaboration, free from Zoombombing and other security issues.

How to make a stranger's insecure 3D printer halt-and-catch-fire – plus more alerts from infosec world
2020-04-13 16:04

In what was surely a very serious piece of research and not just an excuse to set stuff ablaze, the team at the aptly-named CoalFire have demonstrated how a 3D printer could be tricked into bursting into flames remotely. By hijacking the firmware update process of a 3D printer called the Flashforge Finder, a miscreant could potentially flash the machine's software to remove its temperature constraints.

New infosec products of the week: March 20, 2020
2020-03-20 06:00

HYAS Insight lets analysts connect specific attack instances and campaigns to billions of historical and real-time indicators of compromise faster than ever before, bringing invaluable new intelligence and visibility to security efforts. Contrast Security announced Route Intelligence, a major new capability for application security.

Check Point chap: Small firms don't invest in infosec then hope they won't get hacked. Spoiler alert: They get hacked
2020-03-09 10:00

Far from being depressed, Wiley was expressing the forlorn hope that infosec as a field would be less dominated by malicious persons trying to make a fast buck by scamming honest folk and businesses out of their hard-earned money. As Check Point's incident response head honcho, Wiley has full visibility into what the infosec company's operations involve.

GCHQ's infosec arm has 3 simple tips to secure those insecure smart home gadgets
2020-03-03 15:30

Britain's National Cyber Security Centre wants owners of baby monitors and smart CCTV cameras to take some basic security precautions. Keep your camera secure by regularly updating security software.

Keen to check for 'abnormal' user behaviours? Microsoft talks insider risk, AWS imports and compliance at infosec shindig RSA
2020-02-20 14:35

RSA As IBM's crew cancels their hotel rooms, Microsoft's infosec staffers are still set to attend the decades-old RSA conference and pulled the covers off a raft of security releases and previews for the event today. We spoke to Microsoft 365 Senior Director, Alym Rayani, about compliance and insider risk at last year's Ignite event.

$2.07bn? That's one Dell of a deal offloads infosec biz RSA
2020-02-18 17:30

Dell Technologies is flogging its infosec business RSA for $2.075bn as it tries to reduce its longstanding debt. "The transaction will further simplify our business and product portfolio. It also allows Dell Technologies to focus on our strategy to build automated and intelligent security into infrastructure, platforms and devices to keep data safe, protected and resilient."