SamuraiWTF 4.0 Finally Released

  In February of this year, Mic posted a blog discussing the future of SamuraiWTF. (You can go read it here if you don’t remember).  As we discussed then, the build process that has supported this project for the last decade is WAY too … Continue reading SamuraiWTF 4.0 Finally Released

The Missing Piece of the Security Conference Circuit

So far this year I think I’ve attended 20+ security conferences around the world – speaking at many of them. Along the way I got to chat with hundreds of attendees and gather their thoughts on what they hoped to achieve or learn at each of these confe… Continue reading The Missing Piece of the Security Conference Circuit

The National Cyber Security Centre and IBM Security Join Forces to Improve Security Skills

Organizations are struggling to hire enough people with the right security skills. Industry and government must work together to give more opportunities to potential cyber talent.

The post The National Cyber Security Centre and IBM Security Join Forces to Improve Security Skills appeared first on Security Intelligence.

Continue reading The National Cyber Security Centre and IBM Security Join Forces to Improve Security Skills

Use This NERC CIP v6 Standards Summary to Stay Compliant

Thanks to FERC’s Order 822, the North American Electric Reliability Corporation’s critical infrastructure protection standards, known as NERC CIP, are continually updated. Seven updated standards proposed by NERC for inclusion have now been… Continue reading Use This NERC CIP v6 Standards Summary to Stay Compliant

CEHv10 and CEHv9: Comparing The Versions

CEH, Certified Ethical Hacker, by EC-Council is a highly sought after IT security certification. EC-Council recently released a new version of the exam, CEHv10. We’ve taken the guesswork out of deciphering what has changed between the latest vers… Continue reading CEHv10 and CEHv9: Comparing The Versions

Training Announce: “Hunting with OSSEC”

I’m proud to have been selected to give a training at DeepSec (Vienna, Austria) in November: “Hunting with OSSEC“. This training is intended for Blue Team members and system/security engineers who would like to take advantage of the OSSEC integration capabilities with other tools and increase the visibility of their infrastructure behaviour.

[The post Training Announce: “Hunting with OSSEC” has been first published on /dev/random]

Continue reading Training Announce: “Hunting with OSSEC”

It Is Important To Have Ethics In Social Engineering

Over the years of being a professional social engineer (SE), I have been asked questions like, “Are you really testing your clients if you don’t use EVERY method possible?” Or, “You are acting like the bad guys, why do you need … Continue reading It Is Important To Have Ethics In Social Engineering

Cyber hygiene training is infrequent and inconsistent

Finn Partners Research released findings from its Cybersecurity at Work study that examined the level of cyber risk that employees pose to their organizations. The in-depth study, which surveyed 500 full-time office employees across the US, found that … Continue reading Cyber hygiene training is infrequent and inconsistent

How the Federal Government Is Working to Improve Its Cybersecurity Workforce

On the heels of last month’s White House reorganization plan, the state of cybersecurity careers within the government is changing. In part, this plan aims to address several pressing issues in the job category within the context of government em… Continue reading How the Federal Government Is Working to Improve Its Cybersecurity Workforce

How to use the cloud to improve your technology training

Anyone who has tried to hire an IT expert knows that the shortage of qualified people is real. We’re not just talking about IT security jobs, either. Almost every area of tech faces a skills shortage that threatens to sap productivity and presents chal… Continue reading How to use the cloud to improve your technology training