Posts

Showing posts with the label Hacking

How Businesses Can Utilise Penetration Testing

Image
Understand your security vulnerabilities Article by  Beau Peters The basic approaches like  phishing simulations are good, but they tend to have limited reach. This is why more agile methods, penetration testing among them, have been getting increasing attention. In essence, this sees experts with a background in ethical hacking utilizing the techniques of cybercriminals to breach a business’ systems. This also receives a certain amount of hesitancy — business owners are often unsure about the idea of letting somebody hack their systems in the name of cybersecurity. As always, there is more to this issue. So, let’s explore what penetration testing is, why businesses should engage with it and how they can do so to get the most impact. What are the Benefits? Penetration testing requires a significant amount of trust. Therefore, it’s important to look at what the payoffs of this approach are as opposed to ostensibly safer techniques. Some of the key benefits include: Ascertai...

The Role of Translation in Cyber Security and Data Privacy

Image
Article by Shiela Pulido Due to our dependence on the internet for digital transformation, most people suffer from the risks of cyberattacks. It is an even greater concern this year due to the trend of remote working and international business expansions. According to  IBM , the cost of cyber hacks in 2020 is about $3.86 million. Thus, understanding how cybersecurity and data privacy plays a priority role in organizations, especially in a multilingual setting. But, what is the relationship of languages in data privacy, and how can a reliable translation help prevent cyber-attacks? The Connection of Translation Company to Data Privacy A lot of people will ask about the clear connection between translations and cybersecurity. In data privacy, conveying important information through effective communications is important. However, with language barriers and complicated jargon in the IT industry, only IT professionals can understand their messages. It is also especially difficult for mu...

Which is more Important: Vulnerability Scans Or Penetration Tests?

Image
Which Is Better? A Vulnerability Scan Or A Penetration Test? Vulnerability scanning and penetration tests are two very different ways to test your system for any vulnerabilities. Despite this, they are often confused about the same service, which leads to business owners purchasing one service when they are really in need of the other. In an effort to help these business owners tell the difference between the two services and understand which is best suited to their needs, SecureTeam , a cybersecurity consultancy, has written this guide to explain vulnerability scans vs. penetration testing. In a brief summary, a vulnerability scan is an automated, high-level test that looks for and reports potential vulnerabilities in your system. A penetration test, on the other hand, is a detailed hands-on examination by a cybersecurity professional that tries to detect and exploit weaknesses in your system. Now, let’s look a little deeper at the two services. What is a Vulnerability Scan? Vulnerabi...

The Linux Flaw you can't afford to Ignore (CVE-2021-3156)

Image
Linux and Unix operating systems require regular patching like any IT system, but as security professionals, ethical hackers, and criminal hackers will tell you, regular Linux and Unix patching is often neglected. CVE-2021-3156 sudo Vulnerability Last week (26th January 2021) a new critical rated Linux\Unix vulnerability was made public under  CVE-2021-3156 . Specifically, the vulnerability is within the 'sudo' program, which is an abbreviation of ' superuser do ', well that's how I remember it. Sudo is a powerful and fundamental program found within all Linux and Unix distributions, allowing users to execute programs with the security privileges of another user. A typical use of sudo is where you need to run a program with privilege level (i.e. administrator) access rights. The sudo 'heap overflow' vulnerability was discovered by Qualys researchers, the exploit  allows any unprivileged user to gain root level (i.e. administrative) privileges.   Qualys has p...

Fact vs. Fiction: Film Industry's Portrayal of Cybersecurity

Image
Article by Beau Peters The movie industry is infamous for its loose depictions of hacking and cybersecurity. Hollywood often gets a lot wrong about hacking and digital protections, but what does it get right? The power of film in influencing the future of technology and the experts that create it is immense. Because of this, it is important to assess what the facts are versus movie fiction.  Here, we’ll explore the film industry’s portrayal of cybersecurity. Cybersecurity in Movies From WarGames to Blackhat, hacking and cybersecurity movies have glamorized the world of digital safety and the compromising of said safety. However, each Hollywood outing does so with varying levels of realism, typically embracing excitement over reality.  In the 1983 WarGames movie, a young hacker almost triggers World War 3 These portrayals have led to common tropes and views of the cybersecurity industry in their attempts to prevent and combat hacking attempts. Among these tropes are some of th...

iPhone Hacks: What You Need to Know About Mobile Security

Image
Guest Post by Jennifer Bell Learn How Hackers Steal and Exploit Information to Ensure This Doesn’t Happen to You  Cybersecurity is an important topic to know and understand in order to keep your information safe and secure. Even more specifically, it’s important to know and understand mobile security as well. Mobile security, especially with iPhones, is crucial as hackers are becoming smarter and more creative when it comes to iCloud hacks. Apple has partnered with network hardware and insurance companies such as Cisco and Aon to provide security against data breaches; but how can you ensure that even with these Apple partnerships that your iPhone is secure and protected against hackers? Here are the most common ways that hackers get into iPhones to steal or exploit personal information, keep these points in mind to best protect yourself from mobile security hacks. Poor Passwords Often, poor password choices or poor password management allows hackers to easily hack into iPhones ...

Accelerated Digital Innovation to impact the Cybersecurity Threat Landscape in 2020

Image
Its December and the Christmas lights are going up, so it can't be too early for cyber predictions for 2020.   With this in mind,  Richard Starnes, Chief Security Strategist at Capgemini , sets out what the priorities will be for businesses in 2020 and beyond. Richard Starnes, Chief Security Strategist, Capgemini Accelerated digital innovation is a double-edged sword that will continue to hang over the cybersecurity threat landscape in 2020.  As businesses rapidly chase digital transformation and pursue the latest advancements in 5G, cloud and IoT, they do so at the risk of exposing more of their operations to cyber-attacks. These technologies have caused an explosion in the number of end-user devices, user interfaces, networks and data; the sheer scale of which is a headache for any cybersecurity professional.  In order to aggressively turn the tide next year, cyber analysts can no longer avoid AI adoption or ignore the impact of 5G.  AI ...

2019 Verizon Data Breach Investigations Report (DBIR) Key Takeaways

Image
The 2019 Verizon Data Breach Investigations Report (DBIR ) was released today, and I was lucky enough to be handed a hot off the press physical copy while at the Global Cyber Alliance Cyber Trends 2019 event at Mansion House, London. For me, the DBIR provides the most insightful view on the evolving threat landscape, and is the most valuable annual “state of the nation” report in the security industry. Global Cyber Alliance Cyber Trends 2019 The DBIR has evolved since its initial release in 2008, when it was payment card data breach and Verizon breach investigations data focused. This year’s DBIR involved the analysis of 41,686 security incidents from 66 global data sources in addition to Verizon. The analysed findings are expertly presented over 77 pages, using simple charts supported by ‘plain English’ astute explanations, reason why then, the DBIR is one of the most quoted reports in presentations and within industry sales collateral. DBIR 2019 Key Takeaways Financial g...

Automotive Technologies and Cyber Security

Image
A guest article authored by Giles Kirkland Giles is a car expert and dedicated automotive writer with a great passion for electric vehicles, autonomous cars and other innovative technologies. He loves researching the future of motorisation and sharing his ideas with auto enthusiasts across the globe. You can find him on Twitter , Facebook and at Oponeo . Automotive Technologies and Cyber Security Surveys show that about 50% of the UK feel that driverless vehicles will make their lives much easier and are eagerly anticipating the arrival of this exciting technology. Cities expect that when driverless car technology is fully implemented, the gridlock which now plagues their streets will be relieved to a large extent. Auto-makers predict that the new technology will encourage a surge in vehicle purchases, and technology companies are lining up with the major auto manufacturers to lend their experience and knowledge to the process, hoping to earn huge profits. Delays to Driverles...

Cyber Security Conferences to Attend in 2019

A list of Cyber and Information Security conferences to consider attending in 2019. Conference are not only great places to learn about the evolving cyber threat landscape and proven security good practices, but to network with industry leading security professionals and likeminded enthusiasts, to share ideas, expand your own knowledge, and even to make good friends. JANUARY 2019 SANS Cyber Threat Intelligence Summit Monday 21st & Tuesday 22nd January 2019 Renaissance Arlington Capital View Hotel, VA, USA https://www.sans.org/event/cyber-threat-intelligence-summit-2018 AppSec California 2019 (OWASP) Tuesday 22nd & Wednesday 23rd January 2019 Annenberg Community Beach House, Santa Monica, USA https://2019.appseccalifornia.org/ PCI London Thursday 24th January 2019 Park Plaza Victoria Hotel, London, UK https://akjassociates.com/event/pcilondon The Future of Cyber Security Manchester Thursday 24th January 2019 Bridgewater Hall, Manchester, UK https://cybermanc...

British Airways Hack Update: Caused by Injected Script & PCI DSS Non-Compliance is Suspected

Image
On Friday (7th September 2018),  British Airways disclosed   between 21st August 2018 and 5th September 2018, 380,000 BA customer's payment card transactions were compromised by a third party through its website and mobile app. This data included the customer's full name, email address, debit\credit card 16 digit number (PAN), expiry date and card security code i.e. CVV, CV2 Details of how the hack was orchestrated have now come to light.  In  a blog post RiskIQ researchers  have claimed to have found evidence that a web-based card skimmer script was injected into the BA website, very  similar to the approach used by the Magecard group, who are believed to be behind a similar attack against the  Ticketmaster website recently . Web-based card skimmer script attacks have been occurring since 2015. In this case, once the customer has entered their payment card details and then submits the payment either on a PC or on a touchscreen de...

British Airways Customer Data Stolen in Website and Mobile App Hack

Image
In a statement, British Airways stated: " From 22:58 BST August 21 2018 until 21:45 BST September 5 2018 inclusive, the personal and financial details of customers making bookings on ba.com and the airline’s app were compromised ." The airline said they will be notifying affected customers, and if anyone has been impacted to contact their bank or credit card providers. The Telegraph reported 380,0000 payments were compromised, and that BA customers had experienced payment card fraud as a result before the BA breach disclosure, which strongly suggests unencrypted debit\credit cards were stolen. There are no details about the data theft method at the moment, but given the statement said the BA website and BA mobile app was compromised, I think we could be looking at another example of an insecure API being exploited, as per the  Air Canada breach  and the T-Mobile breach last month. We'll see what comes out in the wash over the next few days and weeks, but...