Author: admin

MalwareBytesSecurity

Drive-by download campaign targets Chinese websites, experiments with exploits

Credit to Author: Jérôme Segura| Date: Thu, 22 Feb 2018 16:00:00 +0000

This custom made drive-by download attack targets some Chinese websites and their visitors while experimenting with exploits.

Categories:

Tags:

(Read more…)

The post Drive-by download campaign targets Chinese websites, experiments with exploits appeared first on Malwarebytes Labs.

Read More
SecurityTrendMicro

Securing IoT Networks

Credit to Author: William “Bill” Malik (CISA VP Infrastructure Strategies)| Date: Thu, 22 Feb 2018 15:28:10 +0000

The typical enterprise has more than 500 applications in place.Q: How do you segment a mesh? A: You can’t. Legacy IoT devices, Industrial Control Systems with custom networking, are exceptionally difficult to secure. Typically, these devices contain only enough compute capabilities to support their primary operational function. They have limited memory, low power, constrained CPU resources, and very little network bandwidth. They do not…

Read More
FortinetSecurity

Securing the Network: What Three Key Verticals Require

Credit to Author: Derek Manky| Date: Thu, 22 Feb 2018 13:45:59 +0000

While new, innovative threats continue to pop up on almost daily, our latest Global Threat Landscape Report reveals that long known and yet still unpatched vulnerabilities continue to serve as the primary gateway for attacks, with organizations reporting an average of 274 attacks per firm – a 82% increase over the previous quarter. This alarming trend emphasizes that while remaining vigilant for new threats and vulnerabilities in the wild is critical, organizations also need to stay focused on what is happening within their own environment.

Read More
FortinetSecurity

Rise of the 'Hivenet': Botnets That Think for Themselves

Credit to Author: Derek Manky| Date: Wed, 21 Feb 2018 13:45:59 +0000

Over the past few years, a new development has occurred: predictive software systems are being programmed using artificial intelligence techniques. The latest advances in these kinds of tools use swarm technology to leverage massive databases of expert knowledge comprised of billions of constantly updated bits of data in order to make accurate predictions.

Read More
ComputerWorldIndependent

Throwback Thursday: Now he's feeling even LESS secure

Credit to Author: Sharky| Date: Thu, 22 Feb 2018 03:00:00 -0800

This organization’s IT security officer leaves and isn’t replaced. “A year and a half goes by and the organization suffers a web page defacement,” says a pilot fish on the scene. “During the course of the remediation, another server that has a couple of Trojans on it is found.”

That’s not really a big surprise. Since the infosec guy’s departure, the CIO has repeatedly demanded that ports be opened in the firewall, external connections be made to servers bypassing the firewall and servers in the DMZ be connected to internal servers.

The support manager objects every time — and is always overruled.

“Worse, support isn’t part of the process of selection or meetings with potential vendors for the new web services,” fish says. “Support only finds out about the requirements when they are directed to create the holes.”

To read this article in full, please click here

Read More
QuickHealSecurity

Thanatos Ransomware – an analysis by Quick Heal Security Labs

Credit to Author: Shriram Munde| Date: Thu, 22 Feb 2018 09:04:02 +0000

Quick Heal Security Labs has come across a new ransomware with AES encryption technique that demands 0.01 Bitcoin as a ransom after encrypting the victim’s files. It’s known as Thanatos Ransomware. Thanatos is a type of a Trojan malware that spreads through malicious advertisements, phishing sites, spam emails, freeware and…

Read More