Jun 16 2020

Elite CIA unit that developed hacking tools failed to secure its own systems, allowing massive leak, an internal report found

The publication of ‘Vault 7’ cyber tools by WikiLeaks marked the largest data loss in agency history, a task force concluded.

The theft of top-secret computer hacking tools from the CIA in 2016 was the result of a workplace culture in which the agency’s elite computer hackers “prioritized building cyber weapons at the expense of securing their own systems,” according to an internal report prepared for then-director Mike Pompeo as well as his deputy, Gina Haspel, now the current director.

Source: Elite CIA unit that developed hacking tools failed to secure its own systems, allowing massive leak, an internal report found.

Wikileaks Vault 7: What’s in the CIA Hacking Toolbox?
httpv://www.youtube.com/watch?v=X45Bb8O-gMI

CIA Hacking Tools Released in Wikileaks Vault 7 – Threat Wire
httpv://www.youtube.com/watch?v=5LYSjLwkAo4

Download a Security Risk Assessment steps paper!

Download a vCISO template

Take an awareness quiz to test your basic cybersecurity knowledge

Subscribe to DISC InfoSec blog by Email


Jun 15 2020

Dating Apps Exposed 845 GB of Explicit Photos, Chats, and More

Category: AWS Security,Security BreachDISC @ 2:37 pm

3somes, Gay Daddy Bear, and Herpes Dating are among the nine services that leaked the data of hundreds of thousands of users. Researchers find a developer running multiple dating services left 845GB of explicit photos, chats, and more exposed in AWS buckets

Source: Dating Apps Exposed 845 GB of Explicit Photos, Chats, and More

Download a Security Risk Assessment steps paper!

Download a vCISO template

Take an awareness quiz to test your basic cybersecurity knowledge

Subscribe to DISC InfoSec blog by Email

Best Practices for Amazon S3 Security with S3 Access Management Tools and S3 Block Public Access
httpv://www.youtube.com/watch?v=7M3s_ix9ljE

AWS S3 Bucket Security 👮- Restrict Privileges🔒to User using IAM Policy | Grant User Access
httpv://www.youtube.com/watch?v=vtz3ruCebH8


Jun 14 2020

Tech firms suspend use of ‘biased’ facial recognition technology

Amazon, IBM and now Microsoft ban the sale of facial recognition technology to police departments and are urging for federal laws to regulate its use.

Source: Tech firms suspend use of ‘biased’ facial recognition technology

Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email



Why Cities Are Banning Facial Recognition Technology | WIRED
httpv://www.youtube.com/watch?v=sYftT5YgwVI

Facial-recognition technology: safe or scary?
httpv://www.youtube.com/watch?v=-yvxbi5GMnA



ARTIFICIAL INTELLIGENCE Dangers to Humanity: AI, U.S., China, Big Tech, Facial Recogniton, Drones, Smart Phones, IoT, 5G, Robotics, Cybernetics, & Bio-Digital Social Programming


Jun 13 2020

Lamphone attack lets threat actors recover conversations from your light bulb | ZDNet

Category: Cyber Espionage,Cyber Threats,Threat detectionDISC @ 12:13 pm

Academics record light variations in a light bulb to recover the sound waves (speech, conversations, songs) from a room 25 meters (80 feet) away.

Source: Lamphone attack lets threat actors recover conversations from your light bulb | ZDNet

Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email


Jun 12 2020

Facebook contest reveals deepfake detection is still an “unsolved problem”

Category: DeepfakesDISC @ 12:30 pm

Facebook says deepfakes are not currently a big issue, but it wants to be prepared.

Source: Facebook contest reveals deepfake detection is still an “unsolved problem”

Best Of Deep Fakes Compilation
httpv://www.youtube.com/watch?v=xkqflKC64IM

Funniest DeepFakes *Compilation* II.
httpv://www.youtube.com/watch?v=RpRlrrNwr4U

Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email


Jun 11 2020

The importance of encryption and how AWS can help | Amazon Web Services

Category: AWS SecurityDISC @ 10:13 pm

Encryption is a critical component of a defense-in-depth strategy, which is a security approach with a series of defensive mechanisms designed so that if one security mechanism fails, there’s at least one more still operating. As more organizations look to operate faster and at scale, they need ways to meet critical compliance requirements and improve […]

Source: The importance of encryption and how AWS can help | Amazon Web Services



Why is Encryption Important? – Why is Cybersecurity Important Episode 1
httpv://www.youtube.com/watch?v=EZSjs8A7lmA



Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email

Tags: encryption


Jun 10 2020

Deepfakes Are Going To Wreak Havoc On Society. We Are Not Prepared.

Category: Deepfakes,Information SecurityDISC @ 4:44 pm

In the months and years ahead, deepfakes threaten to grow from an Internet oddity to a widely destructive political and social force.

Source: Deepfakes Are Going To Wreak Havoc On Society. We Are Not Prepared.

Best Of Deep Fakes Compilation
httpv://www.youtube.com/watch?v=xkqflKC64IM

Funniest DeepFakes *Compilation* II.
httpv://www.youtube.com/watch?v=RpRlrrNwr4U

Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email


Jun 09 2020

Windows Group Policy flaw lets attackers gain admin privileges

Category: Windows SecurityDISC @ 6:13 pm

Microsoft has fixed a vulnerability in all current Windows versions that allow an attacker to exploit the Windows Group Policy feature to take full control over a computer. This vulnerability affects all Windows versions since Windows Server 2008.

Source: Windows Group Policy flaw lets attackers gain admin privileges



Windows Security: The dashboard for device protections
httpv://www.youtube.com/watch?v=e_Z2bk7Cp1g





Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email


Jun 08 2020

Amid Pandemic and Upheaval, New Cyberthreats to the Presidential Election

Category: Election Security,Voting MachineDISC @ 10:50 am

Fear of the coronavirus is speeding up efforts to allow voting from home, but some of them pose security risks and may make it easier for Vladimir V. Putin, or others, to hack the vote.

Source: Amid Pandemic and Upheaval, New Cyberthreats to the Presidential Election

Tech giants meet with government agencies to talk 2020 election security
httpv://www.youtube.com/watch?v=iXpL7A35hX0

The Trouble With Election Security
httpv://www.youtube.com/watch?v=TgKPkfuNV4s





Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email


Jun 06 2020

5 principles for effective cybersecurity leadership in a post-COVID world

Category: cyber security,Security Risk AssessmentDISC @ 6:32 pm

 

As more people work from home due to COVID-19, cybersecurity operations are facing tremendous challenges. These five principles can help Chief Information Security Officers (CISOs) and cybersecurity leaders ensure effective business continuity in the “new normal.”

Source: 5 principles for effective cybersecurity leadership in a post-COVID world

7 Security Risks and Hacking Stories for Web Developers
httpv://www.youtube.com/watch?v=4YOpILi9Oxs

Download a Security Risk Assessment steps paper!

Download a vCISO template

Subscribe to DISC InfoSec blog by Email

Tags: COVID-19, worrisome risks


Jun 05 2020

Apple releases new open source ‘Password Manager Resources’ project for developers – 9to5Mac

Category: Password SecurityDISC @ 12:35 pm

Apple has announced today that it is launching an open source project designed for developers of password managers. The goal is to make it easier for developers to “create strong passwords that are compatible with popular websites. Apple’s iCloud Keychain platform is already able to generate strong passwords at the time of account creation or […]

Source: Apple releases new open source ‘Password Manager Resources’ project for developers – 9to5Mac



Password Security Best Practices
httpv://www.youtube.com/watch?v=t8SQo3R7qeU



Protect your data by the military grade AES XTS 256-bit hardware encryption




Download a Security Risk Assessment steps paper!

Subscribe to DISC InfoSec blog by Email


Jun 04 2020

Hackers steal secrets from US nuclear missile contractor

Category: Hacking,Information SecurityDISC @ 1:15 pm

Cyber extortionists have stolen sensitive data from a company which supports the US Minuteman III nuclear deterrent.

Source: Hackers steal secrets from US nuclear missile contractor

Download a Security Risk Assessment steps paper!

Subscribe to DISC InfoSec blog by Email


Jun 03 2020

RATs 101: The Grimy Trojans That Scurry Through Remote Access Pipes

Category: TrojanDISC @ 2:09 pm

Remote Access Trojans (RATs) can be the beginning of very bad things on your network or workstations.

Source: RATs 101: The Grimy Trojans That Scurry Through Remote Access Pipes

Remote access trojans (RATs) may not induce the same sort of nightmares as angry cannibal rats, but they can still be terror-inducing if they hit your network and workstations. Because there’s nothing like turning control of your resources over to someone you don’t know to make the job of IT security completely rat-tastic.



How easy is it to RAT Someone?
httpv://www.youtube.com/watch?v=t4CRx-aoynU



Download a Security Risk Assessment steps paper!

Subscribe to DISC InfoSec blog by Email


Jun 02 2020

Our latest InfoSec poll results

Category: Information SecurityDISC @ 12:28 pm

Please share your thoughts and vote, if poll has not expired yet.

Download a Security Risk Assessment steps paper!

Subscribe to DISC InfoSec blog by Email


Jun 01 2020

26 IoT Flaws Enable Denial-of-Service Attacks, Privilege Escalation

Category: IoT SecurityDISC @ 6:07 pm

Research details vulnerabilities in the Zephyr Real Time Operating Systems and MCUboot, both used in IoT devices and sensors.

Source: 26 IoT Flaws Enable Denial-of-Service Attacks, Privilege Escalation



Regulating the Internet of Things
httpv://www.youtube.com/watch?v=b05ksqy9F7k

Fixing the Mess of IoT Security
httpv://www.youtube.com/watch?v=l1TWGThB5gI





Download a Security Risk Assessment Checklist paper!

Subscribe to DISC InfoSec blog by Email


May 31 2020

How hoteliers can mitigate data breaches

Category: Data Breach,data securityDISC @ 6:45 pm

As hackers shift tactics, business owners can take steps to prevent attacks and minimize damage.

Source: How hoteliers can mitigate data breaches



The 5 Most Dangerous New Attack Techniques and How to Counter Them
httpv://www.youtube.com/watch?v=xz7IFVJf3Lk



Data Breaches: Crisis and Opportunity

Download a Security Risk Assessment Checklist paper!

Subscribe to DISC InfoSec blog by Email


May 31 2020

State-Based Contact Tracing Apps Could Be a Mess

Category: Information Privacy,Information SecurityDISC @ 12:15 pm

With no nationwide Covid-19 notification software in sight, security and interoperability issues loom large.

Source: State-Based Contact Tracing Apps Could Be a Mess



Big Tech’s Contact-Tracing Apps Might Make Things Worse | Mashable
httpv://www.youtube.com/watch?v=ViA0xR5q_w4

Coronavirus outbreak: What are the privacy risks behind ‘contact tracing’ apps?
httpv://www.youtube.com/watch?v=FmbOxY7yBL0


Ebola virus disease contact tracing activities, lessons learned

Download a Security Risk Assessment Checklist paper!

Subscribe to DISC InfoSec blog by Email


May 30 2020

Steganography Anchors Pinpoint Attacks on Industrial Targets

Category: Scada SecurityDISC @ 11:36 pm

Ongoing spear-phishing attacks aim at stolen Windows credentials for ICS suppliers worldwide.

Source: Steganography Anchors Pinpoint Attacks on Industrial Targets



Steganography Tutorial | How To Hide Text Inside The Image | Cybersecurity Training | Edureka
httpv://www.youtube.com/watch?v=xepNoHgNj0w

The Four Types of Threat Detection and Use Cases in Industrial Security
httpv://www.youtube.com/watch?v=zqvDu0OaY8k





Download a Security Risk Assessment Checklist paper!

Subscribe to DISC InfoSec blog by Email


May 30 2020

API Security and Hackers: What’s the Need?

Category: App SecurityDISC @ 11:05 am

There is a considerable demand for data-centric projects, that is why companies have quickly opened their data to their ecosystem through REST or SOAP APIs.

Source: API Security and Hackers: What’s the Need? …

















Download a Security Risk Assessment Checklist paper!

Subscribe to DISC InfoSec blog by Email


May 30 2020

Microsoft IIS servers hacked by Blue Mockingbird to mine Monero

Category: HackingDISC @ 12:01 am

This month news broke about a hacker group, namely Blue Mockingbird, exploiting a critical vulnerability in Microsoft IIS servers to plant Monero (XMR) cryptocurrency miners on compromised machines.

Source: Microsoft IIS servers hacked by Blue Mockingbird to mine Monero






Download a Security Risk Assessment Checklist paper!

Subscribe to DISC InfoSec blog by Email


« Previous PageNext Page »