Jul 21 2019

When It Come Down To It, Cybersecurity Is All About Understanding Risk

Category: Risk Assessment,Security Risk AssessmentDISC @ 12:11 am

Get two risk management experts in a room, one financial and the other IT, and they will NOT be able to discuss risk.

Source: When It Come Down To It, Cybersecurity Is All About Understanding Risk

An Overview of Risk Assessment According to
ISO 27001 and ISO 27005






Enter your email address:

Delivered by FeedBurner


Jul 19 2019

The Problem With the Small Business Cybersecurity Assistance Act

Category: cyber securityDISC @ 1:08 pm

Small Business Administration (SBA) Cyber Awareness Act (H.R. 2331)

The Small Business Cybersecurity Assistance Act may provide business owners with access to government-level tools to secure small business against attacks.

Source: The Problem With the Small Business Cybersecurity Assistance Act

The House passes Small Business Administration (SBA) Cyber Awareness Act (H.R. 2331), which requires the SBA to expand its ability to combat cyber threats.

Source: Small Business Cybersecurity: House Passes Key Bill – MSSP Alert

 

10 Cyber Security Tips for Small Business


9 Interesting Cybersecurity Statistics Everyone Should Know  

Tags: SBCAA


Jul 07 2019

How To Sell Cyber Security To Your Board

Category: Selling cyber securityDISC @ 10:48 am

How To Sell Cyber Security To Your Board – via Steve King



How to Sell Cyber Security



[pdf-embedder url=”https://blog.deurainfosec.com/wp-content/uploads/2019/07/Talking-cybersecurity-to-board.pdf” title=”Talking cybersecurity to board”]



Todd Fitzgerald’s book,

Information Security Governance Simplified:

From the Boardroom to the Keyboard, presents 15 chapters of advice and real-world experience on how to handle the roll out of an effective program …. Todd has taken the time to include for the reader some practical security considerations for managerial, technical, and operational controls. This is followed up with a discussion on how legal issues are impacting the information security program.
#TomPeltier, CISSP






Enter your email address:

Delivered by FeedBurner

Tags: Selling InfoSec to the board


Jul 05 2019

10 essential PowerShell security scripts for Windows administrators

Category: PowerShell SecurityDISC @ 3:40 pm

PowerShell is a valuable tool for automating Windows administration tasks, including laborious security chores

Source: 10 essential PowerShell security scripts for Windows administrators
 
Defending Against PowerShell Attacks



Enter your email address:

Delivered by FeedBurner

Tags: Powershell Security


Jul 03 2019

US wants to isolate power grids with ‘retro’ technology to limit cyber-attacks

Category: Grid VulnerabilitiesDISC @ 2:04 pm

SEIA bill, inspired by the 2015 cyber-attack on Ukraine’s power grid, passes Senate.

Source: US wants to isolate power grids with ‘retro’ technology to limit cyber-attacks | ZDNet

US power grid increasingly vulnerable to cyber threats



Enter your email address:

Delivered by FeedBurner

Tags: OT security, Power grid vulnerabilities, Utility security


Jul 01 2019

Don’t tell Alice and Bob: Security maven Bruce Schneier is leaving IBM

Category: Security ProfessionalDISC @ 2:52 pm

Says bye bye to #BigBlue

Source: Don’t tell Alice and Bob: Security maven Bruce Schneier is leaving IBM

 
Bruce Schneier: “Click Here to Kill Everybody” | Talks at Google


Enter your email address:

Delivered by FeedBurner

Tags: Hands down InfoSec genius, InfoSec leader, InfoSec trail blazer


Jun 29 2019

Cyber Crime: Understanding Online Business Model (NCSC)

Category: CybercrimeDISC @ 10:29 pm




The Business of Cybercrime




Enter your email address:

Delivered by FeedBurner


Jun 27 2019

Western intelligence hacked Russia’s Google Yandex to spy on accounts

Category: Cyber Espionage,MalwareDISC @ 2:15 pm

Exclusive: Western intelligence hacked ‘Russia’s Google’ Yandex to spy on accounts – sources

Source: Western intelligence hacked ‘Russia’s Google’ Yandex to spy on accounts


Enter your email address:

Delivered by FeedBurner

Tags: cyber espionage, cyber spy


Jun 25 2019

New Silex malware is bricking IoT devices, has scary plans | ZDNet

Category: MalwareDISC @ 10:07 pm

Over 2,000 devices have been bricked in the span of a few hours. Attacks still ongoing.

Source: New Silex malware is bricking IoT devices, has scary plans | ZDNet

How dangerous are IOT devices? | Yuval Elovici | TEDxBGU


Enter your email address:

Delivered by FeedBurner


Jun 24 2019

OpenSSH introduces a security feature to prevent Side-Channel Attacks

Category: Cyber AttackDISC @ 1:37 pm

OpenSSH introduces a new feature to prevent Side-Channel attacks, latest release encrypts secret keys in memory as temporary solution.

Source: OpenSSH introduces a security feature to prevent Side-Channel Attacks




Enter your email address:

Delivered by FeedBurner


Jun 20 2019

Seth : Perform A MitM Attack From RDP Connections

Category: MitM AttackDISC @ 10:04 pm

Seth is a tool written in Python and Bash to MitM RDP connections by attempting to downgrade the connection in order to extract clear text credentials.

Source: Seth : Perform A MitM Attack From RDP Connections



Enter your email address:

Delivered by FeedBurner

Tags: MitM Attack, RDP connection


Jun 19 2019

Hackers Disguise New JavaScript-Based Trojan as Game Cheat

Category: TrojanDISC @ 10:06 am

Researchers discovered a new JavaScript-based and modular downloader Trojan camouflaged and distributed to targets in the form of game cheats via websites owned by its developers.

Source: Hackers Disguise New JavaScript-Based Trojan as Game Cheat

Worst JavaScript Flaws That Hackers Love To Abuse


Jun 17 2019

U.S. Govt Achieves BlueKeep Remote Code Execution, Issues Alert

Category: Malware,Security IncidentDISC @ 8:57 am

The Cybersecurity and Infrastructure Security Agency (CISA) published an alert for Windows users to patch the critical severity Remote Desktop Services (RDS) RCE security flaw dubbed BlueKeep.

Source: U.S. Govt Achieves BlueKeep Remote Code Execution, Issues Alert

 
How to check if a target is vulnerable to the new RDP vulnerability (BlueKeep).


Enter your email address:

Delivered by FeedBurner

Tags: BlueKeep, RDP vulnerability, Remote Code Execution


Jun 15 2019

Chinese spies stole NSA hacking tools, report finds

Category: Hacking,Security ToolsDISC @ 4:01 pm

In the report, the cybersecurity company Symantec claims that a Chinese hacker group associated with Chinese government intelligence conducted a hacking campaign using a tool that at the time was only known to be the property of the NSA.

Source: Chinese spies stole NSA hacking tools, report finds


Enter your email address:

Delivered by FeedBurner


Jun 12 2019

Critical Bug in Infusion System Allows Changing Drug Dose in Medical Pumps

Category: hipaa,Security BreachDISC @ 1:52 pm

Researchers discovered two vulnerabilities in Alaris Gateway Workstations that are used to deliver fluid medication. One of them is critical and an attacker could leverage it to take full control of the medical devices connecting to it.

Source: Critical Bug in Infusion System Allows Changing Drug Dose in Medical Pumps



Healthcare privacy and security


Enter your email address:

Delivered by FeedBurner

Tags: Healthcare privacy and security, medical device breaches, medical device threats, medical device vulnerabilities


Jun 11 2019

Zydra : Password Recovery Tool & Linux Shadow File Cracker

Category: Security ToolsDISC @ 2:03 pm

Zydra is a file password recovery tool and Linux shadow file cracker. It uses the dictionary search or Brute force method for cracking passwords.

Source: Zydra : Password Recovery Tool & Linux Shadow File Cracker




 Subscribe in a reader

Tags: password recovery, zydra


Jun 10 2019

A guide to phishing emails and how they work -TEISS® : Cracking Cyber Security

Category: PhishingDISC @ 6:32 pm

Security Awareness writer Keil Hubert describes a mysterious email message that could well have been an insidiously clever spear phishing attack.

Source: A guide to phishing emails and how they work -TEISS® : Cracking Cyber Security



This is what happens when you reply to spam email


 Subscribe in a reader


Jun 09 2019

From phish to network compromise in two hours: How Carbanak operates

Category: Hacking,Phishing,Security BreachDISC @ 2:21 pm

Cybercriminal group Carbanak has stolen hundreds of millions of dollars from financial institutions. Here’s a detailed analysis by Bitdefender of an attack on one bank.

Source: From phish to network compromise in two hours: How Carbanak operates




Jun 02 2019

How to Download a Windows 10 ISO By Impersonating Other Devices

Category: Windows SecurityDISC @ 3:50 pm

Microsoft allows you to download the latest Windows 10 ISOs from their site, but only if you are using a non-Windows browser user agent. This article will explain how to change your user agent in Chrome and Edge so you can download an ISO instead of using the Windows 10 Media Creation Tool.

Source: How to Download a Windows 10 ISO By Impersonating Other Devices








 Subscribe in a reader

Tags: Microsoft Windows Security, Windows 10 ISO


Jun 01 2019

A dive into Turla PowerShell usage | WeLiveSecurity

Category: MalwareDISC @ 3:37 pm

ESET researchers show how, in a bid to evade detection, the Turla group leverages PowerShell scripts to inject malware directly into memory.

Source: A dive into Turla PowerShell usage | WeLiveSecurity








 Subscribe in a reader


« Previous PageNext Page »