Security News

Datadog now supports Amazon EFS for AWS Lambda on Amazon Web Services
2020-06-19 00:15

Datadog's integration with Amazon EFS for AWS Lambda brings single-click correlation between AWS Lambda and the underlying Elastic File System. "We are excited to see Datadog integrating support for Amazon EFS for AWS Lambda into their serverless monitoring at launch," said Adam Fergus, Manager, DevOps at Fiix.

Acunetix adds Business Logic Recorder to enable deeper vulnerability scanning of web apps
2020-06-18 01:15

The Business Logic Recorder is a unique Acunetix feature that is designed to enable effective testing of particular scenarios, especially multi-step web forms, which would otherwise make it impossible for a scanner to reach all areas of a web application. "Many web applications, including those with shopping carts, use multi-step forms," said Nicholas Schiberras, Acunetix Chief Technology Officer.

Web Traffic Security Provider Kasada Raises $10 Million
2020-06-16 14:29

Web traffic security solutions and services provider Kasada has completed a $10 million Series B funding round, bringing the total raised to date by the company to $26 million. Kasada says it wants to also invest in the development of new products.

Exposing the dark web coronavirus scammers
2020-06-15 15:28

What we noticed on the dark net was almost immediately a series of schemes and fraud schemes perpetrated toward the banks, the small business administration, and the other agencies that were affected by the stimulus money. What they're using as seed data for these particular loan applications is stolen private information, PII data, of individuals on the dark net.

Exposing the dark web coronavirus scammers
2020-06-15 15:24

Kurtis Minder, co-founder and CEO of GroupSense, explains why the coronavirus has been big business for bad actors.

Magecart attackers hit Claire’s, Intersport web shops
2020-06-15 09:46

Magecart attackers have compromised web shops belonging to large retail chains Claire's and Intersport and equipped them with payment card skimmers. How the attackers managed to compromise the web shops is still unknown, but they started planning the attack a month before actually executing it.

The mystery of the expiring Sectigo web certificate
2020-06-02 16:48

There's a bit of a kerfuffle in the web hosting community just at the moment over an expired web security certificate from a certificate authority called Sectigo, formerly Comodo Certificate Authority. To make it harder for crooks to mint a web certificate in your name, you need to get your certificate vouched for by someone else, known as a certificate authority.

COVID-19 tests, PPE and antivirual drugs find a home on the dark web
2020-05-29 11:15

Empire Market is one of the most popular places to buy illegal goods on the dark web, transacting a little over $1,000,000 a week. Empire Market has over 52 thousand listings across 11 categories, but the Drugs & Chemicals category dwarfs the others by an order of magnitude.

Siren 10.5: Fusing big local data with results returned dynamically by remote web services
2020-05-29 01:30

The latest version of Siren features several notable improvements, including the ability to fuse big local data with results returned dynamically by remote web services - a capability Siren calls Knowledge Graph "Augment on demand". Dr. Giovanni Tummarello, Founder and Chief Product Officer at Siren, said: "With Siren, a data model is used to virtually connect organizational data - from DBs to Elasticsearch clusters - as a single knowledge graph. Siren 10.5 introduces drivers that connect external web services to this knowledge graph so that it can grow as investigators ask questions."

Phishing attack impersonates Amazon Web Services to steal user credentials
2020-05-28 11:56

The emails spoof an automated notification from AWS to try to capture Amazon account credentials, according to Abnormal Security. A blog post published Wednesday by security provider Abnormal Security describes how phishing attacks are taking advantage of Amazon Web Services to steal user credentials.