Why do we ignore up to 90% of computer security alerts? Because we’re terrible at multi-tasking…

If your focus is elsewhere when an important security warning pops up, there’s a good chance (up to 90%) it will be dismissed and completely ignored.

The post Why do we ignore up to 90% of computer security alerts? Because we’re terrible at multi-tasking… appeared first on The State of Security.

Continue reading Why do we ignore up to 90% of computer security alerts? Because we’re terrible at multi-tasking…→

Video of Hillary Clinton meeting ISIS leader? Nah, it’s a malware attack

Symantec writes:

Cybercriminals are using clickbait, promising a video showing Democratic Party presidential nominee Hillary Clinton exchanging money with an ISIS leader, in order to distribute malicious spam emails.

The email’s subject announces “Clinton Deal ISIS Leader caught on Video,” however there is no video contained in the email, just malware. Adding to the enticement, the email body also discusses voting, asking recipients to “decide on who to vote [for]” after watching the non-existent clip.

Attached to the email is a ZIP archive, containing a Java file. Make the mistake of opening the Java file (in the mistaken belief that you are going to see a controversial video) and you will be infecting your computer with the Adwind backdoor Trojan horse.

It’s not unusual for criminals to use these kind of disguises to make their malicious emails more tempting to click on, and we’ve seen attacks like this during previous presidential election campaigns. Expect more of the same, and be on your guard.

Continue reading Video of Hillary Clinton meeting ISIS leader? Nah, it’s a malware attack→

IT security girl hits back at sexist trolls on LinkedIn

UK IT security firm Foursys writes:

Should we police or dictate how our employees dress? Should we only allow them to represent our brand if they have a specific body type or sense of style?

What about internet commenters or trolls? Is it ok for them to bombard our employees with abuse?

The reason they are asking is after Jayde, one of their sales executives, appeared in a harmless social media post on LinkedIn – celebrating that the firm now had 500 followers on the professional social network.

The response on LinkedIn was ghastly, with many offensive, derogatory and often sexual comments made towards Jayde.

Jayde, however, has stood up to the bullies – making her own brave video response where she details some of the abuse she received.

“For all of those who say that I know nothing about IT security: Shame on you. I know more than 99% of people you’d meet on the street. I can tell you what a denial-of-service attack is, how SQL injection works, and how to your protect against ransomware. To be perfectly clear: Bullying and shaming people because of the way that they look or how they choose to dress is nasty, and I am not just going to take it — and neither should you.”

Hear hear.

I find it extraordinary that some people would make such hurtful and mean remarks… and particularly dumb that so many did so on LinkedIn, which details their real names, jobs and places of employment.

Seriously, the IT security world needs to grow up and stop thinking that women can be treated in such an appalling way.

Watch Jayde’s video response to the cyber-bullies on YouTube, and read more in Foursys’s blog post.

Continue reading IT security girl hits back at sexist trolls on LinkedIn→