Posts

Showing posts with the label ring

Passwords are and have always been an Achilles Heel in CyberSecurity

Image
LogMeOnce , a password identity management suite provider, has published a detailed interview with myself titled ' Passwords are and have always been an Achilles Heel in CyberSecurity '. In the Q&A I talk about Passwords Security (obviously), Threat Actors, IoT Security, Multi-Factor Authentication (MFA), Anti-Virus, Biometrics, AI, Privacy, and a bit on how I got into a career in Cybersecurity. Quotes “I’m afraid people will remain the weakest link in security, and the vast majority of cybercriminals go after this lowest hanging fruit. It’s the least effort for the most reward.” "There is no silver bullet with password security, but MFA comes close, it significantly reduces the risk of account compromise" "The built-in biometric authentication capabilities of smartphones are a significant advancement for security" "Cybercriminals go after this lowest hanging fruit, the least effort for the most reward." "As technology becomes more sec...

Cyber Security Roundup for March 2020

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, February 2020. Redcar and Cleveland Borough Council became the latest UK organisation to become the victim of a mass ransomware attack  which started on 8th February.  The north-east Council's servers, PCs, mobile devices, websites and even phone lines have been down for three weeks at the time of writing. A Redcar and Cleveland councillor told the Guardian it would take several months to recover and the cost is expected to between £11m and £18m to repair the damage done . A significant sum for the cash-strapped council, which confirmed their outage as ransomware caused 19 days after the attack. The strain of ransomware involved and the method initial infiltration into the council's IT systems has yet to be confirmed. The  English FA shut down its investigation into allegations Liverpool employees hacked into Manchester ...

Researchers find security flaws in ‘Amazon’s Ring Video Doorbell Pro’ IoT device

Image
Bitdefender researchers have discovered an issue in ‘ Amazon’s Ring Video Doorbell Pro ’ IoT device that allows an attacker to intercept the owner’s Wi-Fi network credentials. During the configuration stage, the mobile app sends the Wi-Fi network credentials in plaintext to the Ring Video Doorbell Pro. This then allows the hacker to sniff the packets and find out the sensitive data it needs to connect to the user’s WiFi. Once in possession of a user’s WiFi password, an attacker has full access to the network. And it’s no secret that an internal network can be very lax. In fact, many devices such as Smart TVs allow interaction without any authentication whatsoever – even if a device was under attack, there is no trace left and users will have no idea they were even a victim. Examples of possible things an attacker might do without your knowledge: Interact  with all devices within the household network  Intercept network traffic and run ‘man-in-the-middle’ attacks ...