Security

FortinetSecurity

Protecting Higher Education Networks with Secure Access Architecture

Credit to Author: Susan Biddle| Date: Fri, 27 Oct 2017 12:55:59 +0000

Colleges and universities have unique wireless network and security needs. They are typically densely-populated and highly-collaborative environments. Students and faculty alike rely on a consistent wireless connection that allows them fast and constant communication with each other across campuses and buildings. They require access to various online resources and publications to conduct research for assignments and lesson plans, as well as access to various applications and software solutions to record, present, and share their findings. Furthermore,…

Read More
FortinetSecurity

Why ICSA Advanced Threat Defense for Email is So Important

Credit to Author: David Finger| Date: Fri, 27 Oct 2017 12:50:59 +0000

Verizon’s 2017 Data Breach Investigations Report found that two-thirds (66%) of all installed malware that successfully made its way past established defenses were delivered by email.  This is particularly concerning as our weekly FortiGuard Labs Threat Intelligence Brief lists ransomware downloaders –typically delivered via email – as consistently among the top 5 pieces of malware in most weeks. {Update chart and excerpt closer to publication date} The reality is that while brand new attacks like WannaCry and Petya…

Read More
QuickHealSecurity

Android Ransomware Alert! DoubleLocker changes your phone’s PIN and encrypts your data

Credit to Author: Rajib Singha| Date: Fri, 27 Oct 2017 11:40:59 +0000

DoubleLocker is an Android ransomware the likes of which have never been seen before. The malware is designed to launch a two-pronged attack – it locks down the phone it infects and encrypts all files stored in the device. What is spreading DoubleLocker ransomware? The malware gets into a device…

The post Android Ransomware Alert! DoubleLocker changes your phone’s PIN and encrypts your data appeared first on Quick Heal Technologies Security Blog | Latest computer security news, tips, and advice.

Read More
FortinetSecurity

The Analysis of Apache Struts 1 Form Field Input Validation Bypass (CVE-2015-0899)

Credit to Author: Dehui Yin| Date: Wed, 25 Oct 2017 11:50:59 +0000

Apache Struts 1 is a popularly used JAVA EE web application framework. It offers many kinds of validators to filter user input by using the Apache Common Validator library, which is both convenient and fast. However, a bug in Apache Struts can be used to easily bypass the input validation process, allowing an attacker to submit arbitrary dirty data to the database, possibly resulting in a cross-site scripting attack when the user views the JSP file that refers directly to the corrupted data.

Read More