y Why Are We So Stupid About RDP Passwords? By www.careersinfosecurity.eu Published On :: Ransomware Gangs Keep Pwning Poorly Secured Remote Desktop Protocol EndpointsIn honor of World Password Day, here's a task for every organization that uses remote desktop protocol: Ensure that all of your organization's internet-facing RDP ports have a password - and that it's complex and unique. Full Article
y What We've Learned About Business Resiliency By www.careersinfosecurity.eu Published On :: Business resiliency and the supply chain - they both were tested by the disruptions we've all experienced. But Patrick Potter of RSA says there are lessons to be learned from the response, and they will guide us as we prepare for the next evolution of our business climate. Full Article
y Analysis: COVID-19 Contact-Tracing Privacy Issues By www.careersinfosecurity.eu Published On :: The latest edition of the ISMG Security Report analyzes the privacy issues raised by COVID-19 contact-tracing apps. Also featured: An update on efforts to fight fraud tied to economic stimulus payments; John Kindervag on the origins of "zero trust." Full Article
y Analysis: Ransomware's Costly Impact By www.careersinfosecurity.eu Published On :: The latest edition of the ISMG Security Report analyzes the rising costs of ransomware attacks and the latest victims. Also featured: An assessment of Australia's new contact-tracing app designed to help battle the spread of COVID-19, and a discussion of applying the "zero trust" model to the remote workforce. Full Article
y Analysis: The Contact-Tracing Conundrum By www.careersinfosecurity.eu Published On :: The latest edition of the ISMG Security Report analyzes the many challenges involved in developing and implementing contact-tracing apps to help in the battle against COVID-19. Also featured: A discussion of emerging privacy issues and a report on why account takeover fraud losses are growing. Full Article
y Continuity Amid COVID-19: Ensuring Secure Business Continuity By www.careersinfosecurity.eu Published On :: Full Article
y Your Phone and Your Face: Anchoring Users to Real Identities By www.careersinfosecurity.eu Published On :: Full Article
y Live Webinar | How to avoid the security dangers with working from home (WFH) By www.careersinfosecurity.eu Published On :: Full Article
y Live Webinar | Why Automation of AST Solutions is the Key to DevSecOps By www.careersinfosecurity.eu Published On :: Full Article
y Ransomware Slams Healthcare, Logistics, Energy Firms By www.careersinfosecurity.eu Published On :: Attacks Traced to Gangs Wielding Nefilim, Snake StrainsRansomware attacks hit at least four large organizations around the world this week, including a hospital group in Europe that has been battling the COVID-19 pandemic. Full Article
y Zoom's NY Settlement Spells Out Security Moves By www.careersinfosecurity.eu Published On :: Meanwhile, Video Conferencing Firm Acquires Start-Up Encryption CompanyZoom has reached a settlement with the N.Y. attorney general's office to provide better security and privacy controls for its video conferencing platform. Meanwhile, the company announced it's acquiring a start-up encryption company. Full Article
y APT Group Wages 5-Year Cyber-Espionage Campaign: Report By www.careersinfosecurity.eu Published On :: Naikon Hacking Group Targeted Asia-Pacific Countries With New RATOver the last five years, a hacking group that's apparently tied to China has been targeting government ministries in the Asia-Pacific region as part of a cyber-espionage campaign, according to Check Point Research. Full Article
y Digital Contact-Tracing Apps: Hype or Helpful? By www.govinfosecurity.com Published On :: Australia, India and UK Pursuing Centralized Approach Many Privacy Experts Warn AgainstTechnology is no panacea, including for combating COVID-19. While that might sound obvious, it's worth repeating because some governments continue to hype contact-tracing apps. Such apps won't magically identify every potential exposure. But they could make manual contact-tracing programs more effective. Full Article
y Forget Whitelists and Blacklists: Go for 'Allow' or 'Deny' By www.govinfosecurity.com Published On :: Terminology Shift Announced by Britain's National Cyber Security CenterForget "whitelists" and "blacklists" in cybersecurity. So recommends Britain's National Cyber Security Center, in a bid to move beyond the racial connotations inherent to the terminology. Henceforth, NCSC - part of intelligence agency GCHQ - will use the terms "allow list" and "deny list." Will others follow? Full Article
y Why Are We So Stupid About RDP Passwords? By www.govinfosecurity.com Published On :: Ransomware Gangs Keep Pwning Poorly Secured Remote Desktop Protocol EndpointsIn honor of World Password Day, here's a task for every organization that uses remote desktop protocol: Ensure that all of your organization's internet-facing RDP ports have a password - and that it's complex and unique. Full Article
y Analysis: Ransomware's Costly Impact By www.govinfosecurity.com Published On :: The latest edition of the ISMG Security Report analyzes the rising costs of ransomware attacks and the latest victims. Also featured: An assessment of Australia's new contact-tracing app designed to help battle the spread of COVID-19, and a discussion of applying the "zero trust" model to the remote workforce. Full Article
y Analysis: The Contact-Tracing Conundrum By www.govinfosecurity.com Published On :: The latest edition of the ISMG Security Report analyzes the many challenges involved in developing and implementing contact-tracing apps to help in the battle against COVID-19. Also featured: A discussion of emerging privacy issues and a report on why account takeover fraud losses are growing. Full Article
y Testing Medical Device Security During COVID-19 Crisis By www.govinfosecurity.com Published On :: As manufacturers - including companies such as automakers that do not typically produce healthcare devices - race to help fill medical equipment shortages during the COVID-19 crisis, steps must be taken to ensure adequate security testing, says Fairuz Rafique of cybersecurity services firm EmberSec. Full Article
y Live Webinar | Take Control: Complete Visibility and Unmatched Security for Unmanaged and IoT Devices By www.govinfosecurity.com Published On :: Full Article
y Live Webinar | Third-Party Risk Management: How to Mature Your Program Beyond Just Outside-In Scanning By www.govinfosecurity.com Published On :: Full Article
y Live Webinar | 2021: A Cybersecurity Odyssey By www.govinfosecurity.com Published On :: Full Article
y NIST SP 800-39: Managing Information Security Risk By www.govinfosecurity.com Published On :: Organization, Mission and Information System View Full Article
y NIST FIPS PUB 201-2: Personal Identity Verification of Federal Employees and Contractors DRAFT By www.govinfosecurity.com Published On :: Specifying architecture and technical requirements for a common identification standard for federal employees and contractors. Full Article
y NIST SP 800-61 Revision 1: Computer Security Incident Handling Guide By www.govinfosecurity.com Published On :: Guidance on establishing processes to rapidly detect and respond to cyber incidents. Full Article
y DoD: Notice of Proposed Rulemaking on Privacy Training By www.govinfosecurity.com Published On :: The Department of Defense and two other government agencies have issued a proposed rule designed to help ensure that government contractors provide adequate privacy training to their staff members. Full Article
y Webcast: Keeping Remote Workers Safe and Your Work Secure By www.govinfosecurity.com Published On :: This webcast gives 6 tips for keeping employees safe and mitigating security threats as your workforce goes remote.Learn how to protect employees from malicious web content. Full Article
y Zoom's NY Settlement Spells Out Security Moves By www.govinfosecurity.com Published On :: Meanwhile, Video Conferencing Firm Acquires Start-Up Encryption CompanyZoom has reached a settlement with the N.Y. attorney general's office to provide better security and privacy controls for its video conferencing platform. Meanwhile, the company announced it's acquiring a start-up encryption company. Full Article
y APT Group Wages 5-Year Cyber-Espionage Campaign: Report By www.govinfosecurity.com Published On :: Naikon Hacking Group Targeted Asia-Pacific Countries With New RATOver the last five years, a hacking group that's apparently tied to China has been targeting government ministries in the Asia-Pacific region as part of a cyber-espionage campaign, according to Check Point Research. Full Article
y Hackers Try to Sell 26 Million Breached Records: Report By www.govinfosecurity.com Published On :: Data Apparently Obtained From Three Breaches, ZeroFox ReportsHackers are attempting to sell a fresh trove of approximately 26 million user records apparently obtained from three data breaches, according to researchers at the security firm ZeroFox. Full Article
y Digital Contact-Tracing Apps: Hype or Helpful? By www.careersinfosecurity.com Published On :: Australia, India and UK Pursuing Centralized Approach Many Privacy Experts Warn AgainstTechnology is no panacea, including for combating COVID-19. While that might sound obvious, it's worth repeating because some governments continue to hype contact-tracing apps. Such apps won't magically identify every potential exposure. But they could make manual contact-tracing programs more effective. Full Article
y Forget Whitelists and Blacklists: Go for 'Allow' or 'Deny' By www.careersinfosecurity.com Published On :: Terminology Shift Announced by Britain's National Cyber Security CenterForget "whitelists" and "blacklists" in cybersecurity. So recommends Britain's National Cyber Security Center, in a bid to move beyond the racial connotations inherent to the terminology. Henceforth, NCSC - part of intelligence agency GCHQ - will use the terms "allow list" and "deny list." Will others follow? Full Article
y Why Are We So Stupid About RDP Passwords? By www.careersinfosecurity.com Published On :: Ransomware Gangs Keep Pwning Poorly Secured Remote Desktop Protocol EndpointsIn honor of World Password Day, here's a task for every organization that uses remote desktop protocol: Ensure that all of your organization's internet-facing RDP ports have a password - and that it's complex and unique. Full Article
y Analysis: Ransomware's Costly Impact By www.careersinfosecurity.com Published On :: The latest edition of the ISMG Security Report analyzes the rising costs of ransomware attacks and the latest victims. Also featured: An assessment of Australia's new contact-tracing app designed to help battle the spread of COVID-19, and a discussion of applying the "zero trust" model to the remote workforce. Full Article
y Addressing Telehealth, Telework Security Amid COVID-19 By www.careersinfosecurity.com Published On :: With more employees working remotely and a much heavier demand for telehealth services, entities need to consider extra, accelerated steps in keeping data and systems secure, says Martin Littmann, Kelsey-Seybold Clinic CISO, and Stephen Moore, a former security leader at Anthem. Full Article
y Analysis: The Contact-Tracing Conundrum By www.careersinfosecurity.com Published On :: The latest edition of the ISMG Security Report analyzes the many challenges involved in developing and implementing contact-tracing apps to help in the battle against COVID-19. Also featured: A discussion of emerging privacy issues and a report on why account takeover fraud losses are growing. Full Article
y Testing Medical Device Security During COVID-19 Crisis By www.careersinfosecurity.com Published On :: As manufacturers - including companies such as automakers that do not typically produce healthcare devices - race to help fill medical equipment shortages during the COVID-19 crisis, steps must be taken to ensure adequate security testing, says Fairuz Rafique of cybersecurity services firm EmberSec. Full Article
y Live Webinar | How to avoid the security dangers with working from home (WFH) By www.careersinfosecurity.com Published On :: Full Article
y Live Webinar | Third-Party Risk Management: How to Mature Your Program Beyond Just Outside-In Scanning By www.careersinfosecurity.com Published On :: Full Article
y Live Webinar | 2021: A Cybersecurity Odyssey By www.careersinfosecurity.com Published On :: Full Article
y Ransomware Slams Healthcare, Logistics, Energy Firms By www.careersinfosecurity.com Published On :: Attacks Traced to Gangs Wielding Nefilim, Snake StrainsRansomware attacks hit at least four large organizations around the world this week, including a hospital group in Europe that has been battling the COVID-19 pandemic. Full Article
y Webcast: Keeping Remote Workers Safe and Your Work Secure By www.careersinfosecurity.com Published On :: This webcast gives 6 tips for keeping employees safe and mitigating security threats as your workforce goes remote.Learn how to protect employees from malicious web content. Full Article
y Zoom's NY Settlement Spells Out Security Moves By www.careersinfosecurity.com Published On :: Meanwhile, Video Conferencing Firm Acquires Start-Up Encryption CompanyZoom has reached a settlement with the N.Y. attorney general's office to provide better security and privacy controls for its video conferencing platform. Meanwhile, the company announced it's acquiring a start-up encryption company. Full Article
y APT Group Wages 5-Year Cyber-Espionage Campaign: Report By www.careersinfosecurity.com Published On :: Naikon Hacking Group Targeted Asia-Pacific Countries With New RATOver the last five years, a hacking group that's apparently tied to China has been targeting government ministries in the Asia-Pacific region as part of a cyber-espionage campaign, according to Check Point Research. Full Article
y Digital Contact-Tracing Apps: Hype or Helpful? By www.cuinfosecurity.com Published On :: Australia, India and UK Pursuing Centralized Approach Many Privacy Experts Warn AgainstTechnology is no panacea, including for combating COVID-19. While that might sound obvious, it's worth repeating because some governments continue to hype contact-tracing apps. Such apps won't magically identify every potential exposure. But they could make manual contact-tracing programs more effective. Full Article
y Forget Whitelists and Blacklists: Go for 'Allow' or 'Deny' By www.cuinfosecurity.com Published On :: Terminology Shift Announced by Britain's National Cyber Security CenterForget "whitelists" and "blacklists" in cybersecurity. So recommends Britain's National Cyber Security Center, in a bid to move beyond the racial connotations inherent to the terminology. Henceforth, NCSC - part of intelligence agency GCHQ - will use the terms "allow list" and "deny list." Will others follow? Full Article
y Why Are We So Stupid About RDP Passwords? By www.cuinfosecurity.com Published On :: Ransomware Gangs Keep Pwning Poorly Secured Remote Desktop Protocol EndpointsIn honor of World Password Day, here's a task for every organization that uses remote desktop protocol: Ensure that all of your organization's internet-facing RDP ports have a password - and that it's complex and unique. Full Article
y Network and Security Transformation - Enabling your Digital Business By www.cuinfosecurity.com Published On :: Vistra Energy, a Texas-based power generation firm, recently underwent a network transformation project. CISO Paul Reyes, joined by Zscaler's Dan Shelton, opens up on how to make the move to cloud-based models and what it can do to support your business. Full Article
y Analysis: Ransomware's Costly Impact By www.cuinfosecurity.com Published On :: The latest edition of the ISMG Security Report analyzes the rising costs of ransomware attacks and the latest victims. Also featured: An assessment of Australia's new contact-tracing app designed to help battle the spread of COVID-19, and a discussion of applying the "zero trust" model to the remote workforce. Full Article
y Analysis: The Contact-Tracing Conundrum By www.cuinfosecurity.com Published On :: The latest edition of the ISMG Security Report analyzes the many challenges involved in developing and implementing contact-tracing apps to help in the battle against COVID-19. Also featured: A discussion of emerging privacy issues and a report on why account takeover fraud losses are growing. Full Article
y Live Webinar | Take Control: Complete Visibility and Unmatched Security for Unmanaged and IoT Devices By www.cuinfosecurity.com Published On :: Full Article