Independent

IndependentKrebs

Beware of Security by Press Release

Credit to Author: BrianKrebs| Date: Thu, 10 Aug 2017 15:40:30 +0000

On Wednesday, the security industry once again witnessed an all-too-familiar cycle: I call it “Security by press release.” It goes a bit like this: A security firm releases a report claiming to have unearthed a major flaw in a competitor’s product; members of the trade press uncritically republish the claims without adding much clarity or waiting for responses from the affected vendor; blindsided vendor responds in a blog post showing how the issue is considerably less dire than originally claimed. At issue are claims made by Denver-based security company DirectDefense, which published a report this week warning that Cb Response — a suite of security tools sold by competitor Carbon Black (formerly Bit9) — was leaking potentially sensitive and proprietary data from customers who use its product.

Read More
ComputerWorldIndependent

New in Windows security: Automatically log off suspicious users

Credit to Author: Gregg Keizer| Date: Thu, 10 Aug 2017 02:59:00 -0700

Microsoft has added rapid reaction to a year-old subscription service that will automatically shut down accounts – logging a user out of all managed apps and services, including those delivered by a third-party – at the first hint of suspicious activity.

The new feature in Cloud App Security (CAS), a security service launched in August 2016, collaborates with Azure Active Directory (AAD), another subscription service, to automatically bump off users behaving unusually and shut down accounts suspected of having been hijacked. CAS is built, at least in part, on technology Microsoft acquired in 2015 when it bought the Israeli cloud security vendor Adallom for $250 million.

To read this article in full or to leave a comment, please click here

Read More