New IoT security rating system by global safety certification firm UL is designed to empower consumers to make smarter decisions about the products and IoT solutions they purchase.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Given the dearth of cybersecurity pros in the marketplace today, a new Juniper Networks report suggests that security automation is potentially the solution.
Attention is turning from smart home to smart building with Kaspersky report showing nearly 4 in 10 of smart buildings affected by a malicious cyber attack attempting to infect computers that control automation systems.
Another vulnerability that can expose master passwords in KeePass has surfaced, after one was discovered to start the year. The new security exploit involves traces of the password being left in system memory, and potentially reassembled if the memory is dumped.
A new WiFi security bug present on chips made by Broadcom and Cypress has likely rendered some one billion devices vulnerable to a theoretical attack that can decrypt information in transit.
Cyber Incident Reporting for Critical Infrastructure Act requires critical sector entities to promptly report to the DHS's Cybersecurity and Infrastructure Security Agency (CISA) certain cyber incidents and ransomware payments.
Sansec researchers found a new Magecart credit card skimmer capable of exfiltrating payment information from stores on multiple eCommerce platforms, including ZenCart, WooCommerce, Shopify and BigCommerce.
The next time you’re tempted to click on an online ad, think again. New malvertising attacks use polyglot images to run code for ad fraud, showing the growing sophistication for malvertising ad fraud.
Microsoft Exchange zero-day vulnerabilities affect an estimated 250,000 on-premise servers. The company is aware of attacks involving a single state-sponsored group that compromised less than ten organizations.
New national security memorandum from the Biden administration looks to provide the active cyber defenses of the US with a boost. The move brings crucial federal systems in line with the tougher cyber standards applied to civilian systems.










