Attackers bypass Microsoft patch to deliver Formbook malware

Sophos Labs researchers have detected the use of a novel exploit able to bypass a patch for a critical vulnerability (CVE-2021-40444) affecting the Microsoft Office file format. The attackers took a publicly available proof-of-concept Office exploit an… Continue reading Attackers bypass Microsoft patch to deliver Formbook malware

Ransomware Empire: Who might blackmail your company?

The history of ransomware attacks covers slightly over 30 years. Over this modest period, cybercriminals have been relentlessly building ransomware capacities and improving logistics to facilitate the infections of their victims and reach the most high… Continue reading Ransomware Empire: Who might blackmail your company?

Salesforce CTO talks e-commerce cybersecurity threat trends for 2022

Online retailers are dealing with more cybersecurity threats than ever before, and the holiday (shopping) season is when they have to fend them off most aggressively. In this interview with Help Net Security, Dr. Taher Elgamal, cryptographer, infosec l… Continue reading Salesforce CTO talks e-commerce cybersecurity threat trends for 2022

What’s stopping consumers from using credit freezes?

A Identity Theft Resource Center and DIG.Works research explored the relationship between data breach notices and a decision for a consumer to freeze their credit, as well as credit freezes in general. Consumer credit freeze awareness The research surv… Continue reading What’s stopping consumers from using credit freezes?

How confident can organizations be in their managed services security?

MITRE Engenuity and Cybersecurity Insiders announced the results of a research about the state of affairs in managed services security. The survey of IT security professionals representing organizations of all sizes from industries such as Technology, … Continue reading How confident can organizations be in their managed services security?

Valuing IT professionals to retain talent and reduce their stress

Keeping up with digital transformation (32%) and keeping talent in technical roles (26%) are the two biggest challenges organizations face today, an Ivanti survey of IT professionals reveals. Additionally, the study found that IT departments are viewed… Continue reading Valuing IT professionals to retain talent and reduce their stress

Cybercriminals shifting focus: IT sector most targeted in 2021

Darktrace reported that the IT and communications sector was globally the most targeted industry by cybercriminals in 2021. Darktrace’s data is developed by ‘early indicator analysis’ that looks at the breadcrumbs of potential cyber-a… Continue reading Cybercriminals shifting focus: IT sector most targeted in 2021

Why the updated OWASP Top 10 list can’t be addressed by WAF?

Did you know that OWASP published its updated Top 10 web vulnerabilities list? And that it includes updates that could impact the design and functionality of your WAF solution? Note that the preliminary API risk factors published by OWASP are not align… Continue reading Why the updated OWASP Top 10 list can’t be addressed by WAF?

Cybersecurity budgets surge, as skills gap wreaks havoc on 2022 plans

As enterprises plan and set budgets for the new year ahead, the vast majority are expecting to channel more dollars toward enhancing their cybersecurity efforts. Organizations committed to bolstering their cybersecurity budgets According to the latest … Continue reading Cybersecurity budgets surge, as skills gap wreaks havoc on 2022 plans

How familiar are consumers with data protection best practices?

With data breaches on the rise along with consumer demand for privacy and control over their own data, governments have in turn adopted new data protection regulations — and businesses are feeling the pressure. Now, a consumer research from Ground Labs… Continue reading How familiar are consumers with data protection best practices?