Forensic Focus Legal Update July 2021: Reliability And Credibility Of Digital Evidence

This quarter’s edition of our legal update starts with a look at improving digital forensics experts’ credibility, as well as the reliability of the evidence they find — all while dealing with rapidly advancing technology Two recent academic pape… Continue reading Forensic Focus Legal Update July 2021: Reliability And Credibility Of Digital Evidence

Insurance and Ransomware

As ransomware becomes more common, I’m seeing more discussions about the ethics of paying the ransom. Here’s one more contribution to that issue: a research paper that the insurance industry is hurting more than it’s helping.

However, the most pressing challenge currently facing the industry is ransomware. Although it is a societal problem, cyber insurers have received considerable criticism for facilitating ransom payments to cybercriminals. These add fuel to the fire by incentivising cybercriminals’ engagement in ransomware operations and enabling existing operators to invest in and expand their capabilities. Growing losses from ransomware attacks have also emphasised that the current reality is not sustainable for insurers either…

Continue reading Insurance and Ransomware

The Future of Machine Learning and Cybersecurity

The Center for Security and Emerging Technology has a new report: “Machine Learning and Cybersecurity: Hype and Reality.” Here’s the bottom line:

The report offers four conclusions:

  • Machine learning can help defenders more accurately detect and triage potential attacks. However, in many cases these technologies are elaborations on long-standing methods — not fundamentally new approaches — that bring new attack surfaces of their own.
  • A wide range of specific tasks could be fully or partially automated with the use of machine learning, including some forms of vulnerability discovery, deception, and attack disruption. But many of the most transformative of these possibilities still require significant machine learning breakthroughs.

Continue reading The Future of Machine Learning and Cybersecurity

Cybersecurity Insiders – 2021 Malware Report

The post Cybersecurity Insiders – 2021 Malware Report appeared first on Digital Defense, Inc..
The post Cybersecurity Insiders – 2021 Malware Report appeared first on Security Boulevard.
Continue reading Cybersecurity Insiders – 2021 Malware Report

Bizarro Banking Trojan

Bizarro is a new banking trojan that is stealing financial information and crypto wallets.

…the program can be delivered in a couple of ways­ — either via malicious links contained within spam emails, or through a trojanized app. Using these sneaky methods, trojan operators will implant the malware onto a target device, where it will install a sophisticated backdoor that “contains more than 100 commands and allows the attackers to steal online banking account credentials,” the researchers write.

The backdoor has numerous commands built in to allow manipulation of a targeted individual, including keystroke loggers that allow for harvesting of personal login information. In some instances, the malware can allow criminals to commandeer a victim’s crypto wallet, too…

Continue reading Bizarro Banking Trojan

The Problem with Treating Data as a Commodity

Excellent Brookings paper: “Why data ownership is the wrong approach to protecting privacy.”
From the introduction:

Treating data like it is property fails to recognize either the value that varieties of personal information serve or the abiding inter… Continue reading The Problem with Treating Data as a Commodity