FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Thursday, March 22, 2018

The Pirate Bay is Down Again for the 3rd Time in a Week

By Waqas

Another day, another disappointing news for The Pirate Bay users

This is a post from HackRead.com Read the original post: The Pirate Bay is Down Again for the 3rd Time in a Week


March 22, 2018 at 09:42PM

Forrester Study: Breaking Down the Total Economic Impact of AlienVault USM

There’s just something about InfoSec that attracts the skeptics, the leery, the Agent Scullys among us. Perhaps this natural tendency to distrust is what makes security analysts so keen at threat hunting, so perceptive to see a glimmer of anomalous activity in a stream of “normal.”

It’s perhaps this same tendency to distrust that warrants big eye rolls when I, the InfoSec marketer [insert devil emoji here], tell IT security practitioners that AlienVault® Unified Security Management® (USM) can save them time and money.

And, I get it. They’ve heard it all before from SIEM and other security vendors: the promise and allure of a powerful security engine, low upfront costs, life-changing intelligence and analytics; only to be duped into 18 months of deployment hell, a black hole of maintenance and tuning, and mounting hidden costs for every new bell and whistle. All too often, security projects end up as shelf ware, the proverbial million-dollar door stop.

To be honest, this is exactly why we built AlienVault USM—to empower IT security teams to achieve world-class security without the cost and complexity of traditional approaches to security. With AlienVault USM, organizations of all sizes can deploy and get to real security insights on day one. But again, don’t trust me; I work in marketing.

Instead, take a look at the recent commissioned Total Economic Impact™ (TEI) study that the global research firm Forrester Consulting conducted on behalf of AlienVault. For this study, Forrester interviewed AlienVault USM Anywhere™ customers, both direct users and Managed Security Services Providers (MSSPs) to assess the overall value and ROI of AlienVault USM, quantified in cold hard numbers.

As stated in the study, “From the information provided in the interviews, Forrester has constructed a TEI framework for those organizations considering implementing AlienVault USM. The objective of the framework is to identify the cost, benefit, flexibility, and risk factors that affect the investment decision.”

Download a full copy of the Forrester TEI study here.

The key findings of the study are highlighted in the infographic below. They include:

  • 80% faster threat detection and response
  • 6X Return on Investment (ROI) over 3 Years
  • Payback in under 3 Months
  • 2,000 hours saved on Compliance Audits (94% reduction)
  • 80% Improvement in Security Operations Staff Productivity
  • $40,000+ Annual Savings in Threat Intelligence Expense

Need more convincing? Try our interactive product experience here.

      

The post Forrester Study: Breaking Down the Total Economic Impact of AlienVault USM appeared first on Cybersecurity Insiders.


March 22, 2018 at 09:09PM

Things I hearted this week 9th March 2018

It’s been an uneventful week for the most part. I did spend a lot of time reading tweets by Today In Infosec. If you don’t know of it, I suggest checking it out. As the name suggests, it tweets out news from the world of information security from previous years. I was thinking that maybe I could wait five years and then recycle these weekly roundup blogs as “This week in Infosec”

But that’s the future, let’s jump into the news that matters today.

An Olympic hack

What went on behind the scenes at the Olympics? How much hacking went on, who was behind it, and what can be done about it?

SAML, SSO many vulnerabilities

SAML-based single sign on systems have some vulnerabilities that allow attackers with authenticated access to trick SAML systems into authenticating as different users without knowledge of the victims’ password.

Sounds like a lot of fun.

Passhunt

I came across this little gem on GitHub this week. Basically, it’s a repository of default credentials for a plethora of network devices, web apps, and so forth for over 500 vendors and near 2100 default passwords.

Remember, Mirai originally only had 61 default passwords to wreak havoc.

Sharing is caring

If you give your information to a business, how many places do you think it shares that information with? None, a dozen, fifty?

Well, thanks to GDPR compliance, PayPal has shared a list of over 600 entities it shares data with.

Related

The case against hack porn

Joseph Cox at Motherboard raises an interesting point, that while new research is valuable, many times, it is only applicable in the realm of research, or for Bond films.

Personally, I feel that it’s important to allow and encourage new and innovative ways to hack into things. But it’s worth bearing in mind that very few people or companies are hacked with highly sophisticated techniques. The more we can do first to raise the bar to address fundamentals the better.

Risk Resilience is the future

We are often told about how a big breach can affect a company’s profits, impact its share price, and basically mean bad news.

But as more data is available and we can see the impact of breaches, the general consensus is that while the share price may suffer a major dip in the aftermath of a breach, it is often forgotten in about 12 months.

In this well-written article, Daniel Miessler discussed how companies should focus on resilience, avoiding disruption, and human safety.

Marcus Hutchins

A really well-written piece on Marcus Hutchins aka Malware Tech Blog. Hard to appreciate how his life has literally been turned upside down.

Regulating the IoT

Left to their own devices, it’s unlikely that manufacturers will willingly spend time and resources hardening or securing smart devices. So, it’s likely some form of regulation will force some changes soon.

Somewhat related to IoT as it involves self-driving cars being attacked. Or as they say, “rage against the machine”

Cryptocurrencies

I keep thinking to myself that this week I’ll try to steer clear of any cryptocurrency-related news, yet there are always a couple that catch my eye and I think they’d be interesting to include. If for nothing else, just to keep track of how issues are evolving and developing in this new world.

      

The post Things I hearted this week 9th March 2018 appeared first on Cybersecurity Insiders.


March 22, 2018 at 09:09PM

Teen hacks Ledger hardware cryptocurrency wallet

By Waqas

A 5-year-old IT security researcher Saleem Rashid has identified a

This is a post from HackRead.com Read the original post: Teen hacks Ledger hardware cryptocurrency wallet


March 22, 2018 at 08:34PM

Care Analytics partner webinar: CloudPassage security and compliance

This post was originally published here by casey pechan.

Not only is Care Analytics a valued partner of ours, but they provide excellent cloud computing for the healthcare industry. In their latest webinar: Featured partner, CloudPassage security and compliance, we sat down with some of their team to demo and discuss our platform CloudPassage Halo, which Care Analytics has been using for their clients.

This webinar contains a demo and real use cases that demonstrate how you can best take advantage of CloudPassage Halo’s lightweight agent-based monitoring process for automated security. Our friends at Care Analytics also dive into how exactly they use Halo for their clients as well.

Care Analytics is an Amazon Web Services Partner and managed services provider. One of the main ways their team differentiates from other managed services providers is by partnering with what they consider to be the “Best of Breed” to enhance their own services, which is how they came to employ CloudPassage Halo.

The post Care Analytics partner webinar: CloudPassage security and compliance appeared first on Cybersecurity Insiders.


March 22, 2018 at 08:29PM

Orbitz: Why You Can’t Secure Data in the Dark

This post was originally published here by Jacob Serpa.

On March 1, 2018, Orbitz discovered that a malicious party may have stolen information from one of its legacy platforms. The compromised platform housed Orbitz customer information such as mailing addresses, phone numbers, email addresses, and full names, as well as details about nearly 900,000 payment cards. 

This breach highlights the struggle that many companies face on a day-to-day basis. 

Stated simply, organizations cannot afford to secure their data in the dark. Lacking comprehensive visibility makes it nearly impossible to protect sensitive information – you cannot defend against threats that you can’t see. Where enterprises fail to maintain automatic, thorough logging of all events involving corporate data, breaches are sure to follow. 

The fact that Orbitz was unable to confirm whether a hacker had stolen information is evidence that it lacked adequate visibility. If the company had tools that provided said visibility, then identifying a breach would have been fairly simple. Additionally, with real-time capabilities, the company could have identified the potential breach the moment that it occurred (somewhere between October and December of 2017), rather than months after the fact.

The speed at which hackers, malware, and malicious insiders can exfiltrate data demands real-time security and comprehensive visibility. Incomplete, reactive security tools are incapable of providing protection in today’s rapid, cloud-first world. Only a cloud access security brokers (CASB) can provide what the modern enterprise needs. 

The post Orbitz: Why You Can’t Secure Data in the Dark appeared first on Cybersecurity Insiders.


March 22, 2018 at 08:23PM

Wednesday, March 21, 2018

Vivaldi browser puts DuckDuckGo as default browser for private windows

By Waqas

DuckDuckGo search engine and Vivaldi browser are joining hands together to collaborate

This is a post from HackRead.com Read the original post: Vivaldi browser puts DuckDuckGo as default browser for private windows


March 22, 2018 at 04:36AM