Security News

Have you tried to guess your boss's password? Lots of workers have, according to a report
2021-09-17 16:13

An August Beyond Identity report takes a look at people's password protection habits as well as their tendencies to guess other folk's passwords. Last month, Beyond Identity published the results of a survey highlighting password protection habits, office password "Guessing games" and more.

Thousands of internet-connected databases contain high or critical CVEs, says report by cloud security biz
2021-09-14 11:30

After spending five years poring over port scan results, infosec firm Imperva reckons there's about 12,000 vulnerability-containing databases accessible through the internet. The news might prompt responsible database owners to double-check their updates and patching status, given the increasing attractiveness of databases and their contents to criminals and hostile foreign states alike.

Serious Security: How to make sure you don’t miss bug reports!
2021-09-13 18:59

Lots of companies these days either run bug bounties, or hire an outside company to look after bug submissions, which shows that they are genuinely interested in knowing about security vulnerabilities in their products or services. Secondly, even researchers who do this sort of thing for a living need to know the right place to start, and having a standardised storage place for contact details makes bug reporting easier for everyone.

Remote cybersecurity concerns and labor shortages are front and center in a new small business report
2021-09-10 16:25

On Wednesday, Verizon released the results from a new survey, detailing sentiment among business leaders about the economic impacts of COVID-19, labor shortages, network security in the age of remote work and more. In August 2021, 90% of business owners and decision-makers said they were very or somewhat concerned about the impact of COVID-19 on small U.S. businesses, a 2% decrease from August 2020, per Verizon.

WFH is a cybersecurity "ticking time bomb," according to a new report
2021-09-09 11:00

On Thursday, HP released an HP Wolf Security report titled "Rebellions & Rejection." The findings detail employee pushback due to company cybersecurity policies and operational drawbacks for IT teams overseeing these networks. At the same time, these new operations also presented security risks with remote workers logging on from home on a mixed bag of personal and company devices.

Report: The State of Password Security in the Enterprise
2021-09-08 02:30

A recent Authentication Security Strategy survey by Enzoic and Redmond magazine revealed insights into the way that passwords are currently being used in various organizations, and what the future looks like regarding this ubiquitous authentication method. How much longer organizations expect to use passwords.

Proxyware Services Open Orgs to Abuse – Report
2021-08-31 20:12

Proxyware services are attractive to businesses that use them for internet-related traffic research, such as search engine optimization. For consumers, Cisco points out, proxyware services are "Advertised as a means to circumvent geolocation checks on streaming or gaming platforms," while at the same time allowing consumers to generate income for the use of their bandwidth.

Trend Micro's Linux Threat Report identifies the most vulnerable distributions and biggest security headaches
2021-08-23 19:40

Analysts reviewed 13 million security incidents and found that end-of-life versions of Linux distributions were at the biggest risk. Linux now has been around long enough that old versions are causing security problems, according to a new report from Trend Micro.

Facebook sat on report that reveals most-shared post for months was questionable COVID story
2021-08-23 03:31

Facebook has revealed a report that shows the most-shared link on the platform in the first three months of 2021 described questionable interpretation of a death attributed to a COVID-19 vaccination - but only did so after publishing a later and more flattering report. The document wasn't Facebook's first such report.

ICS vulnerability reports are increasing in number and severity, and exploit complexity is dropping
2021-08-18 17:19

71% of vulnerabilities found in the first half of 2021 are classified as high or critical, and 90% are of low complexity, meaning an attacker can expect repeated success under a variety of conditions, says Claroty. Industrial cybersecurity company Claroty has released a report on the state of vulnerabilities in industrial control systems in the first half of 2021, and the data reveals several serious issues that should leave any business with an ICS system on high alert.