Pentagon lays out plan to secure websites in response to lawmaker inquiry

The Department of Defense says it has a plan to make sure that all of its public-facing websites are configured in a way that doesn’t put the security of their visitors at risk. In a letter responding to a lawmaker dated July 20, DOD Chief Information Officer Dana Deasy wrote that the department plans by the end of 2018 to fix issues with trust certificates and encryption that are present across many websites affiliated with it. Certain issues will take longer, he said, will at least have a definitive plan by the end of the year. “The Department is working hard to ensure DoD inspires trust among citizens and partners in its digital interactions across our missions, business, and entitlements roles,” Deasy wrote. Deasy laid out the plan in response to a May letter from Sen. Ron Wyden, D-Ore., that raised questions about the issue of insecure websites. Wyden initially […]

The post Pentagon lays out plan to secure websites in response to lawmaker inquiry appeared first on Cyberscoop.

Continue reading Pentagon lays out plan to secure websites in response to lawmaker inquiry

Recently Patched Oracle WebLogic Flaw Used in Active Attacks

Less than a week after a critical vulnerability was patched in Oracle’s WebLogic application server, attackers have already started exploiting the flaw to break into enterprise systems. WebLogic is a component of Oracle Fusion Middleware and und… Continue reading Recently Patched Oracle WebLogic Flaw Used in Active Attacks

From today, Google Chrome starts marking all non-HTTPS sites ‘Not Secure’

Starting today with the release of Chrome 68, Google Chrome prominently marks all non-HTTPS websites as ‘Not Secure’ in its years-long effort to make the web a more secure place for Internet users.

So if you are still running an insecure HTTP (Hyperte… Continue reading From today, Google Chrome starts marking all non-HTTPS sites ‘Not Secure’

Newsmaker Interview: Scott Helme on Securing the Web

Scott Helme, the well-known security researcher, international speaker and the founder of the securityheaders.com and report-uri.com free tools for web security, has devoted himself to improving the security environment of the internet for the past dec… Continue reading Newsmaker Interview: Scott Helme on Securing the Web

Less Than One Month Until Google Chrome Marks HTTP Sites “Not Secure”

This post was authored by Jason Wood, founder of Paladin Security, a host on Security Weekly and commentator on Hack Naked News. This post is sponsored by DigiCert.   There are a number of changes coming up to how Google Chrome warns people about … Continue reading Less Than One Month Until Google Chrome Marks HTTP Sites “Not Secure”

Chrome to mark HTTP as ‘not secure’

Google Chrome currently marks HTTPS-encrypted sites with a green lock icon and “Secure” sign. And starting in July, Chrome will mark all HTTP sites as “not secure.” Google hopes this move will nudge users away from the unencrypted we… Continue reading Chrome to mark HTTP as ‘not secure’