Acceptance of Norms Positively Contributes to Security Culture, Finds Report

Users’ acceptance of norms reduces risky behaviors and positively contributes to an organization’s security culture, finds a new report. In their study Indepth insights into the human factor: The 2017 Security Culture Report, authors Kai Roer of CLTe and Dr. Gregor Petric of the University of Ljubljana analyzed data collected from more than 10,000 employees […]… Read More

The post Acceptance of Norms Positively Contributes to Security Culture, Finds Report appeared first on The State of Security.

Continue reading Acceptance of Norms Positively Contributes to Security Culture, Finds Report

Ismdoor: Greenbug’s Signature Malware that Might Have Aided the Shamoon Campaigns

The Shamoon attack campaigns have been busy over the past few months. On 17 November 2016, the operation unveiled its second incarnation by targeting an organization in Saudi Arabia with Disttrack wiper malware. Just a few days later, the second wave of Shamoon 2 once again dropped Disttrack on another Saudi Arabian company’s network, only […]… Read More

The post Ismdoor: Greenbug’s Signature Malware that Might Have Aided the Shamoon Campaigns appeared first on The State of Security.

Continue reading Ismdoor: Greenbug’s Signature Malware that Might Have Aided the Shamoon Campaigns

iPhone Phishing Scam Combines Physical Theft and Digital Crime

An iPhone phishing scam combines elements of physical theft and digital crime in an effort to steal victims’ Apple ID credentials. According to Trend Micro senior threat researcher Fernando Mercês, it all started when someone stole his friend’s iPhone while they were walking around one of the big metropolitan areas in Brazil. The friend purchased […]… Read More

The post iPhone Phishing Scam Combines Physical Theft and Digital Crime appeared first on The State of Security.

Continue reading iPhone Phishing Scam Combines Physical Theft and Digital Crime

Phishers Spoofing Email Senders to Muck around with Victims’ Web Accounts

Users encounter phishing attacks across every medium of their digital lives. Fortunately, there are lots of ways they can protect themselves. When a suspect email lands in their inbox, for example, recipients can check for grammar/spelling errors and other suspicious indicators. They can also verify the source by hovering over or clicking on the sender’s […]… Read More

The post Phishers Spoofing Email Senders to Muck around with Victims’ Web Accounts appeared first on The State of Security.

Continue reading Phishers Spoofing Email Senders to Muck around with Victims’ Web Accounts

Kazuar’s API Access Lets Trojan Run Commands on Compromised Systems

A backdoor espionage trojan known as Kazuar has API access that it can leverage to run commands on the systems it compromises. The malware, which is written in Microsoft’s .NET Framework and uses the ConfuserEX open source packer, initializes by gathering system and malware information and using those items to generate a mutex. It then […]… Read More

The post Kazuar’s API Access Lets Trojan Run Commands on Compromised Systems appeared first on The State of Security.

Continue reading Kazuar’s API Access Lets Trojan Run Commands on Compromised Systems

ICS Security: What It Is and Why It’s a Challenge for Organizations

Industrial control systems (ICS) security was much simpler before the web. Firewalls and demilitarized zones (DMZs) separating the corporate and plant networks either didn’t exist or weren’t necessary. Organizations were primarily concerned… Continue reading ICS Security: What It Is and Why It’s a Challenge for Organizations