Security News

54% of businesses now have a policy in place to deal with ransomware attacks
2021-07-14 03:30

54% of businesses now have a defined policy in place to deal with ransomware attacks - whether this means paying a ransom, relying on insurance policies or refusing to pay at all, according to Databarracks. A ransomware policy may differ 21% have a policy to never pay a ransom.

Regula: Open source policy engine for IaC security
2021-06-29 06:00

Fugue announced Regula 1.0, an open source policy engine for infrastructure as code security. Available at GitHub, the tool includes support for common IaC tools such as Terraform and AWS CloudFormation, prebuilt libraries with hundreds of policies that validate AWS, Microsoft Azure, and Google Cloud resources, and new developer tooling to support custom rules development and testing with Open Policy Agent.

Strengthen Your Password Policy With GDPR Compliance
2021-06-17 01:06

When you're implementing a password policy for your AD with GDPR compliance in mind it's a good idea to use a 3-rd party tool to help your password policy reach your entire end-user directory. During a password change in Active Directory, this service will block and notify users if the password they have chosen is found in a list of leaked passwords and provides dynamic feedback for password compliance.

CISA Announces Vulnerability Disclosure Policy Platform
2021-06-08 13:52

The U.S. Cybersecurity and Infrastructure Security Agency today announced that it has partnered with the crowdsourced cybersecurity community for the launch of its vulnerability disclosure policy platform. Working in collaboration with bug bounty platform Bugcrowd and government technology contractor Endyna, CISA introduced its VDP platform to help Federal Civilian Executive Branch agencies identify and address vulnerabilities in critical systems.

IT service desks lacking user verification policy, putting businesses at risk
2021-06-07 03:30

48% of organizations don't have a user verification policy in place for incoming calls to IT service desks, according to Specops Software. The survey found that 28% of the companies that actually do have a user verification policy in place are not satisfied with their current policy due to security and usability issues.

TikTok Quietly Updated Its Privacy Policy to Collect Users' Biometric Data
2021-06-06 22:04

The policy change, first spotted by TechCrunch, went into effect on June 2. TikTok users who reside in the European Economic Area, the U.K., Switzerland, and other geographies where the service operates are exempted from the changes.

GitHub Updates Policy to Remove Exploit Code When Used in Active Attacks
2021-06-05 10:01

Code-hosting platform GitHub Friday officially announced a series of updates to the site's policies that delve into how the company deals with malware and exploit code uploaded to its service. Stating that it will not allow the use of GitHub in direct support of unlawful attacks or malware campaigns that cause technical harm, the company said it may take steps to disrupt ongoing attacks that leverage the platform as an exploit or a malware content delivery network.

The policy of truth: As ransomware claims rise, what's a cyber insurer to do?
2021-06-04 09:41

If you rely on your insurer to pay off crooks after a successful ransomware attack, you wouldn't be the only one. When you're dealing with a ransomware attack, how much do you know about who you're making a payment to? And what's the role of not just the insurer but also, say, the intermediary company that the insurer contracts with to negotiate the payment?

Facebook Will Limit Your WhatsApp Features For Not Accepting Privacy Policy
2021-05-14 00:38

"No one will have their accounts deleted or lose functionality of WhatsApp on May 15 because of this update," the Facebook-owned messaging service said in a statement. The move marked a turnaround from its previous stance earlier this year when the company outlined plans to make the accounts inaccessible completely should users choose not to comply with the data-sharing agreement and opt not to have their WhatsApp account information shared with Facebook.

Cybersecurity Community Unhappy With GitHub's Proposed Policy Updates
2021-04-30 11:10

GitHub wants to update its policies regarding security research, exploits and malware, but the cybersecurity community is not happy with the proposed changes. The community has been asked to provide feedback until June 1 on proposed clarifications regarding exploits and malware hosted on GitHub.