Skip to main content

Posts

Showing posts with the label security

How mobile security solutions affect the insurance industry

In the face of growing cybersecurity threats, many businesses are desperate for ways to protect themselves from severe financial losses created by malicious attacks. Many are even turning to insurance companies for help. According to PwC, the market for cyber insurance  is projected to hit $7.5 billion by 2020. But while these enterprises are hoping insurance companies can help mitigate losses, those insurance organizations are also seeking ways to protect themselves from emerging security threats. These businesses haven’t solved their own challenges regarding mobile security and the need for better insurance apps and data solutions. This is especially true when it comes to supporting employees and improving security as well as their productivity. Between insurance apps, claims management software and other business solutions relevant to their industry, insurance brands are eager to adopt technologies that address today’s security threats. Here are some ways i...

10 Ways To Prevent Your Mac From Being Hacked

Information protection is now scrutinized in all commercial and government industries. Theft of information has crippled many organizations and businesses. One of the main reasons information is lost, corrupt, or stolen is because many industries have not fully adopted it as a risk, and have yet to implement strong quality assurance policies and programs. Some of the most common risks are because of unattended computers, weak passwords, and poor information management practices. Hackers look for the weakest target and tunnel into a business from easy sources, like tablets or cell phones. Using smart encryption software can remediate this threat and vulnerability, making it difficult for competitors or rookie hackers to penetrate your device. However, software alone is not enough to prevent Macs from being hacked. It is the Mac user who has the authority and resources to save it from potential penetration.  The top 10 ways to prevent your Mac from being hacked  is ...

From Kaspersky To Webroot, Major Security Firms Can't Even Get Basic Android Encryption Right

When recently-appointed president of RSA, Amit Yoran, opened his company’s flagship conference yesterday, he warned the security industry was living in the dark ages. Protections just aren’t working, he said. Various anti-virus firms, including big names like Kaspersky and Webroot, have offered proof that the market’s many players get it wrong; they’re on a list of companies whose Google Play Android apps don’t do proper encryption checks, according to research from the Computer Emergency Response Team (CERT) at Carnegie Mellon’s Software Engineering Institute. The CERT discovered a whopping 22,000 apps that weren’t carrying out “SSL validation”, where the software is supposed to check certificates over encrypted communications to ensure the parties involved are verified.  Kaspersky’s Internet Security app  and  Webroot’s free offering  and its  “complete” tool  (an apt name, perhaps?) both failed to carry out these checks, mea...

Cybersecurity At RSA

You could tell by the din that the  RSA Conference  in San Francisco this week is the largest enterprise IT security confab in the world. The fact that several prominent breaches over the last year have shaken the C-suite out of its ostrichlike complacency clearly turned the volume up on this show all the way to eleven. So now money seems to be flowing into IT security like never before, adding to the commotion. The big question: with all this security gear from the many hundreds of vendors exhibiting at the conference, each trying to get their message heard above the clamor, why do the hackers appear to be winning? Clearly, tools aren’t enough – even when they’re arguably better than ever. Regardless, the RSA Conference is largely about the tools and technologies – where each tool addresses some corner of the security sphere. Here are my picks for some of the most interesting (in alphabetical order, so as not to play favorites). Are they sufficient? You be the judge. ...

New Browser Hack Can Spy On Eight Out Of Ten PCs

A group of Columbia University security researchers have  uncovered a new and insidious way for a hacker to spy on a computer , Web app or virtual machine running in the cloud without being detected. Any computer running a late-model Intel microprocessor and a Web browser using HTML5 (i.e., 80% of all PCs in the world) is vulnerable to this attack. The exploit, which the researchers are calling “the spy in the sandbox,” requires little in the way of cost or time on the part of the attacker; there’s nothing to install and no need to break into hardened systems. All a hacker has to do is lure a victim to an untrusted web page with content controlled by the attacker. Once there, the software inside the bogus content launches a program that  manipulates how data moves in and out of a victim PC’s cache, which is the part of the CPU that serves as the intermediary between the high-speed central processor and the lower-speed random access memory or RAM. The exploi...

Cisco . Firms Must Stop Playing ( Whack-a-Mole ) with Hackers

the growing number of large-scale, high-profile cyberattacks is evidence of something Martin Roesch has been predicting for several years now: the so-called industrialization of hacking. Security professionals need to respond with advanced strategies that can better defend against this new breed of attacks, said Roesch, vice president and chief architect for the  Cisco    Security Business Group, who was speaking Thursday at the RSA Conference 2015 taking place in San Francisco. As hackers have become increasingly sophisticated, they've found ever more profit and opportunity in breaking into the networks of businesses and other organizations, Roesch said. It's reached a point where, today, the hacking industry is three to five times the size of the security  industry, he said. That means that security experts need to approach their defense strategies from a new perspective, Roesch said. The past approach, which involved keeping security strong enou...

Comcast Deal May Be Dead, But Cable Consolidation Will Go On

Even if Comcast's $45.2 billion bid for Time Warner Cable is dead, consolidation among the companies that pipe in our TV, phone and Internet will carry on. Combining the No. 1 and No. 2 U.S. cable companies would have put nearly 30 percent of TV and about 55 percent of broadband subscribers under one roof, along with NBCUniversal. That appeared to be too much concentration for regulators. Bloomberg News and The New York Times both said Thursday that Comcast is planning to drop its bid, citing unidentified people with knowledge of the matter. Comcast and Time Warner Cable declined to comment on the reports. But cable companies are likely to keep merging as online video options proliferate, the number of cable and satellite TV subscribers slips and costs rise for the shows, sports and movies piped to subscribers. At the same time, there will be more competition for young customers seeking stand-alone Internet and mobile video offerings and cheaper TV channel packages. T...

Hackers can steal fingerprints from a Galaxy S5

You may not be the only one swiping fingerprints on your Galaxy S5. Criminals could be doing it, too, and without your knowledge. Researchers at FireEye discovered a serious flaw in some Androidphones — not just the Galaxy S5, though other affected models weren’t named. While fingerprint data is locked away in Android’s trusted storage area, the biometric scanner itself is exposed. With the right access, a criminal can perform a man-in-the-middle attack and siphon off scans while they’re in transit. Resident malware does the dirty work silently in the background. Once criminals have acquired those tasty bits, “you can generate the image of [the] fingerprint,” Yulong Zhang explained. He added “after that you can do whatever you want.” Scary, right? It would be, if not for a few important caveats. First, this particular flaw was fixed in Android 5.0. Most new devices are shipping with Lollipop pre-installed, and it’s been rolling out to more older ...