October, 2016

article thumbnail

Interview with a hacker: S1ege from Ghost Squad Hackers

Tech Republic Security

Ghost Squad Hackers has emerged as one of the world's most influential indie hacking teams. S1ege, the group's 'administrator,' explains his tactics, how the group works, and the ethics of hacking.

Hacking 167
article thumbnail

Five Ways to Ward off the Horrors of Cybersecurity

CompTIA on Cybersecurity

What ghastly horrors are lurking behind firewalls and in dark corners behind flickering monitors this Halloween? Read on to face the frighteningly dark realms of cybersecurity and get five steps you can take to protect yourself today – as well as a particularly useful tool for you and your company.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Top 5 Causes of Data Loss. Google Workspace Security Tips

Spinone

Data loss should not be considered as an avoidable accident, as it is almost inevitable that any type of business may be exposed to data loss risks. This article presents cybersecurity tips on the top 5 causes of data loss. Instead, it’s important to have an action plan in place that considers all different risks […] The post Top 5 Causes of Data Loss.

Risk 52
article thumbnail

Full(er) House: Exposing high-end poker cheating devices

Elie

In-depth research publications, industry talks and blog posts about Google security, research at Google and cybersecurity in general in open-access.

article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

Social Engineering – The Mental Game, Part II.

NopSec

Now, let’s talk technical. Malicious executable are used to deliver a payload to a victim. These can be very technical packages that can be used for remote access to the victim’s host or can be much simpler making the attack footprint and code smaller by simply prompting the user for a response. Email attachments are one of the best known social engineering attack vectors.

article thumbnail

US Officially Blames Russia For DNC Hack

Privacy and Cybersecurity Law

The United States (US) Department of Homeland Security (DHS) and Office of the Director of National Intelligence (ODNI) issued a […].

Hacking 40

LifeWorks

More Trending

article thumbnail

A must-read IT security handbook: TAG Cyber's massive 2017 guide

Tech Republic Security

TAG Cyber CEO Dr. Edward Amoroso has created a 1,200+ page resource for cybersecurity pros. The handbook includes tech recommendations on 50 controls, interviews, and vendor lists.

article thumbnail

Delete unused Android apps now, or risk a security nightmare

Tech Republic Security

Your Android device most likely contains unused apps that could still use data or fall prey to vulnerabilities. The solution to this potential security problem: delete those apps.

Risk 167
article thumbnail

2017 cybercrime trends: Expect a fresh wave of ransomware and IoT hacks

Tech Republic Security

This year companies were rocked by over 90 million cyberattacks. In 2017 the number could double. Cybersecurity expert Sameer Dixit explains how new innovation leads to increased vulnerability.

article thumbnail

Tor: The smart person's guide

Tech Republic Security

This comprehensive guide covers everything you need to know about Tor, the onion router web browser that allows users to access the Dark Web and other encrypted websites.

article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

Dyn DDoS attack: 5 takeaways on what we know and why it matters

Tech Republic Security

On October 21, a Distributed Denial of Service attack on Dyn took many key web properties such as Twitter and Netflix offline. Here are some more details on the attack and the breadth of its impact.

DDOS 167
article thumbnail

How to install Advanced Intrusion Detection Environment on CentOS

Tech Republic Security

For an added layer of security on your CentOS system, you should consider installing Advanced Intrusion Detection Environment. Find out why.

167
167
article thumbnail

IBM and SBI Securities test bond trading on the blockchain

Tech Republic Security

SBI Securities will adopt the Hyperledger Fabric and work with IBM to test the application of blockchain technology for operational processes and security around bond trading.

article thumbnail

Help wanted: Universities double down on security to help fill 1 million open jobs

Tech Republic Security

Universities are increasingly including cybersecurity majors and concentrations to better prepare students to fill the many open jobs that exist globally in the field.

article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

Zero in on IT security risks by applying the 80/20 rule to vulnerability assessments

Tech Republic Security

It is impossible to defend everything; the Pareto Principle, also known as the 80/20 rule, is one way for IT security pros to determine what's most important to protect.

Risk 167
article thumbnail

5 best practices for switching your site to HTTPS for improved security

Tech Republic Security

Chrome is starting to flag more pages as insecure. Here are five things every webmaster should know about HTTPS.

167
167
article thumbnail

Why big data leaders must worry about IoT security

Tech Republic Security

The security risks associated with IoT devices cannot be ignored. If your big data plans include IoT devices, follow these four steps to reduce your chances of a security breach.

Big data 167
article thumbnail

Infographic: How to identify and avoid phishing attacks

Tech Republic Security

A recently-published infographic from Digital Guardian can help your employees recognize and steer clear of phishing, spear phishing, and social media attacks.

Phishing 167
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Facebook rolls out encryption for Messenger, but it's not as private as you think

Tech Republic Security

Facebook recently enabled end-to-end encryption for all Facebook Messenger users with an opt-in program called Secret Conversations. Here's what it means and how to use it.

article thumbnail

10 programs to help you break into a cybersecurity career

Tech Republic Security

Eighty-two percent of IT professionals report a shortage of cybersecurity skills at their company. Here are 10 programs spanning all education levels to help you get your start in the field.

article thumbnail

How to configure G Suite for HIPAA compliance

Tech Republic Security

You can use G Suite and comply with HIPAA, but you'll need to spend some time configuring your Admin console settings.

166
166
article thumbnail

Millennials most likely to lose money from tech support scams, says Microsoft

Tech Republic Security

A new report from Microsoft details the victim demographics of tech support scams, and some of the findings may surprise you.

Scams 166
article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

How to use Apple Configurator 2 to simplify deploying iOS upgrades OTA

Tech Republic Security

Follow these steps to create a configuration file in Apple Configurator 2 that you can deploy to end users or push via MDM to manage settings on devices over-the-air (OTA).

165
165
article thumbnail

October is National Cyber Security Awareness Month: How secure is your enterprise?

Tech Republic Security

It's National Cyber Security Awareness Month. Enterprises of all sizes should take time to educate their workforce on lurking cyber security threats.

article thumbnail

3 inexpensive steps to secure IoT

Tech Republic Security

IoT devices powered the attack against Dyn, causing major disruptions to certain web properties. Follow these three steps to secure your IoT devices.

IoT 164
article thumbnail

Metasploit eyeing Linux and usability improvements; iOS support uncertain

Tech Republic Security

Metasploit owner Rapid7 is working on making its penetration testing software easier to use, more welcoming for Linux-based techniques, and a better partner to network security controls.

article thumbnail

IDC Analyst Report: The Open Source Blind Spot Putting Businesses at Risk

In a recent study, IDC found that 64% of organizations said they were already using open source in software development with a further 25% planning to in the next year. Most organizations are unaware of just how much open-source code is used and underestimate their dependency on it. As enterprises grow the use of open-source software, they face a new challenge: understanding the scope of open-source software that's being used throughout the organization and the corresponding exposure.

article thumbnail

Report: Android and iOS apps both leak private data, but one is definitely worse for the enterprise

Tech Republic Security

iOS apps are actually leaking more data than Android apps, with one important qualifier: The countries where the most leaks are happening.

162
162
article thumbnail

The real reason companies don't take security seriously: Their money isn't on the line

Tech Republic Security

Today a company's investors don't feel the pain of security breaches, but customers do. In order for security to improve, that needs to change.

161
161
article thumbnail

Hackable heart implants: St. Jude comes under fire for security risks

Tech Republic Security

In an ongoing legal battle between St. Jude and Muddy Waters and MedSec, new filings claim that devices created for heart issues are vulnerable to cyberattacks.

Risk 160
article thumbnail

Infographic charts history and potential risks of the Industrial Internet of Things

Tech Republic Security

By 2020 the IIoT is expected to be a multi-billion dollar market. With massive scale comes massive security challenges. Security expert Lancen LaChance share his enterprise security best practices checklist.

Internet 158
article thumbnail

Beware of Pixels & Trackers on U.S. Healthcare Websites

The healthcare industry has massively adopted web tracking tools, including pixels and trackers. Tracking tools on user-authenticated and unauthenticated web pages can access personal health information (PHI) such as IP addresses, medical record numbers, home and email addresses, appointment dates, or other info provided by users on pages and thus can violate HIPAA Rules that govern the Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates.