Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Friday 4 November 2022

The European Aviation Industry’s New Cybersecurity Rules


Europe has expanded its cybersecurity rules around airline flight safety. And for the first time, the requirements cover a range of companies in the aviation supply chain. 
WSJ Pro Cybersecurity reporter Catherine Stupp joins host Julie Chang to discuss the new rules and how companies are responding

Wednesday 21 September 2022

Cybersecurity Experts on Edge Amid Ex-Uber Executive’s Trial


The trial of Uber's former head of security is being closely watched by cybersecurity professionals, who worry it could set a precedent for who is liable when a company is hacked. 

WSJ cybersecurity reporter Robert McMillan joins host Zoe Thomas to discuss the ins and outs of the trial and its wider ramifications.

Wednesday 6 July 2022

The ongoing battle to beat the crypto thieves


The price of crypto currencies has plunged recently, but whatever the value of their investment, for digital asset holders, protecting their crypto from thieves is an ongoing problem. In March this year, hackers carried out one of the biggest cryptocurrency heists of all time and with cyber criminals increasingly wielding high-tech tools and techniques, in 2021 cryptocurrency theft grew by around 500 per cent over the previous year.

Monday 18 April 2022

Former NSA Director on cybersecurity risks from Russia


Former head of NSA and U.S. Cyber Command Admiral Michael Rogers weighs in the risk of a Russian cyber-attack.

Saturday 8 January 2022

Who will secure the Metaverse - and how will they do it?

With the metaverse being talked up everywhere — even though the concept still seems to be a bit vague — concerns about safety have bubbled up, and you wouldn’t be along in wondering what cybersecurity challenges may come with it.

The metaverse, a concept of the next incarnation of the Internet, an immersive virtual 3D world connecting all sorts of digital environments, has been gaining a strong foothold in the media and has quickly become one of the hot topics in the digital landscape. You can even consider it as a new decentralized marketing ecosystem, characterized as social, live, and persistent, as it will contain a lot of user-generated content. It will also be easy to join and contribute to for hardware-agnostic users.

Just like in any other digital landscape where authentication plays a key role, cybersecurity will play a significant role in keeping the parties safe. No matter how sophisticated the technology and techniques of circumventing security measures will be, businesses will need to stay one step ahead of cyber criminals. So, the armaments race in cybersecurity that we’ve known for years will get even more intense.

And what will actually happen to the cheaters? Will they be sent to a sub-universe where they’re free to cheat where cheating is accepted as part of the rules? How will users in the metaverse be monitored to ensure any removal of possible illegal operations, morally corrupt conduct, and hate speech? By private companies themselves or by some governmental cyber-police?

There are a lot of open questions to be answered and certainly an interesting challenge for the metaverse community as well as the cybersecurity providers.

Find out more HERE

 

Triple Extortion Ransomware - What it is and how to prevent It

The global surge in ransomware attacks increased by 102% in 2021 compared to the beginning of 2020, and shows no sign of slowing down

The number of organizations impacted by ransomware globally has more than doubled in the first half of 2021 compared with 2020.

The healthcare and utilities sectors are the most targeted sectors while organizations in Asia Pacific are targeted more than any other region.

Since April, researchers at Check Point Research (CPR) have seen an average of over 1,000 organizations being impacted by ransomware every week.

Prominent attacks that have taken place at the end of 2020 and the beginning of 2021 point at a new attack chain – essentially an expansion to the double extortion ransomware technique, integrating an additional, unique threat to the process – that CPR calls the Triple Extortion. 

What is Triple Extortion? You can find out HERE.

Thursday 6 January 2022

A practical guide to Log4shell remediation

Log4Shell (CVE-2021 – 44228): is a zero-day vulnerability in Log4j, a popular Java logging framework. Log4j has left businesses and government officials scrambling to deal with the blatant cybersecurity threat to global computer networks. The bug disclosed recently could trigger potentially devastating cyberattacks spanning economic sectors and international borders, security experts say.

Leading researchers and technology companies have warned that hackers with links to foreign governments and ransomware criminal groups seek to exploit vulnerabilities in targets’ computer systems.

Find out more and what you should be doing HERE.

Wednesday 5 January 2022

You can’t stop the ‘next SolarWinds’ — but you can slow it down

It was one of the biggest questions in cybersecurity of 2021, and it’s sure to remain on the minds of countless businesses into 2022, too: How do you prevent a software supply chain attack?

Such attacks have soared by 650% since mid-2020, due in large part to infiltration of open source software, according to a recent study by Sonatype.

But an even bigger driver of the question, of course, has been the unprecedented attack on SolarWinds and customers of its Orion network monitoring platform. In the attack, threat actors compromised the platform with malicious code that was then distributed as an update to thousands of customers, including numerous federal agencies.

Find out more, HERE

Monday 3 January 2022

10 worst password snafus of 2021

Using strong and secure passwords is sound advice not just for your own personal accounts but for any accounts or services you use on the job. In fact, a weak password can create far more trouble for an organization that holds user data and other sensitive information. To show just how much trouble it can create, password manager Dashlane has unveiled a list of the worst password-related security incidents for 2021.

For its 2021's Worst Password Offenders list, Dashlane looked at the year's 10 worst security mishaps that involved hacked or stolen passwords. These fiascos show that advice about creating a strong password is still being ignored by too many individuals and too many organizations.

Read the full list HERE.

Friday 31 December 2021

Conti Ransomware Gang Has Full Log4Shell Attack Chain

The Conti ransomware gang, which last week became the first professional crimeware outfit to adopt and weaponize the Log4Shell vulnerability, has now built up a holistic attack chain.

The sophisticated Russia-based Conti group – which Palo Alto Networks has called “one of the most ruthless” of dozens of ransomware groups currently known to be active – was in the right place at the right time with the right tools when Log4Shell hit the scene 10 days ago, security firm Advanced Intelligence (AdvIntel) said in a report shared with Threatpost on Thursday.

You can read the Threatpost story HERE.

Wednesday 29 December 2021

Check for Log4j vulnerabilities with this simple-to-use script

If you're not certain whether your Java project is free from Log4j vulnerabilities, you should try this easy-to-use scanning tool immediately.

To find out what you should be doing check HERE.

Wednesday 1 December 2021

Are Biometrics Replacing Passwords? Uncovering What Users Really Want (and Need)

Identity verification is integral to the secure use of digital platforms, many of which have become staples of consumers’ lives in recent years. But with so many authentication methods – from traditional passwords and usernames, to biometrics like face and fingerprint scans – it can be challenging to know just what consumers prefer from their apps and digital accounts, and how best to optimize these experiences from a merchant standpoint. In this virtual roundtable, PYMNTS Editor-in-Chief Matt Nesto hosts industry leaders to discuss this topic and more. Tune in.

Friday 5 November 2021

“TOP READS OF THE WEEK” (for week 30 October to 5 November)

This is the final edition of TOP READS OF THE WEEK in this format.

However, you can still get all the top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management by reading / subscribing to the “Citadel Advantage News Digest”.

The Citadel Advantage News Digest is published at least twice a week with all the latest news on Banking, Fintech, Payments, Operations Risk and much, much more. Check it out!

Subscribe to our newsletter click HERE. Under the topmost item “Newsletter” click on “Start reading” to access.

In this weeks selection;

Top Reads
From our Blog

Saturday 23 October 2021

“TOP READS OF THE WEEK” (for week ending 22 October)

This week’s top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management and much more

In this weeks selection;

Top Reads
From our Blog

Saturday 16 October 2021

“TOP READS OF THE WEEK” (for week ending 15 October)

This week’s top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management and much more

In this weeks selection;

Top Reads

From our Blog

Saturday 9 October 2021

“TOP READS OF THE WEEK” (for week ending 8 October)

This week’s top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management and much more

In this weeks selection;

Top Reads


From our Blog

Saturday 2 October 2021

“TOP READS OF THE WEEK” (for week ending 1 October)

This week’s top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management and much more

In this weeks selection;

Top Reads
From our Blog

Friday 24 September 2021

“TOP READS OF THE WEEK” (for week ending 24 September)

This week’s top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management and much more

In this weeks selection;

Top Reads
From our Blog

Saturday 18 September 2021

“TOP READS OF THE WEEK” (for week ending 17 September)

This week’s top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management and much more

In this weeks selection;

Top Reads

From our Blog

Friday 10 September 2021

“TOP READS OF THE WEEK” (for week ending 10 September)

This week’s top reads in banking, fintech, payments, cybersecurity, AI, IoT, risk management and much more

In this weeks selection;

Top Reads

From our Blog

 
Website Statistics mortgage payment calculator