FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Wednesday, February 2, 2022

Apple Inc pays $100,500 to hacker for hacking MacBook Webcam

Apple Inc, the American tech giant that produces iPhone, has paid $100,500 to a hacker for hacking MacBook Webcam. Ryan Pickren is the hacker who was rewarded well by the iOS giant as he brought to their issue a severe vulnerability that could have allowed criminals to sneak into the computing activities of Mac users.

Ryan said to have picked up the vulnerability from the safari browser of the MacOS allowing him/or the hacker to gain full access to a device through the multimedia permission application dubbed ShareBear. Thus, from here on, the threat actor gained access to all the info being exchanged via the browser that includes Gmail, iCloud, Facebook and PayPal credentials.

From the past few months, Apple has been well rewarding the security researchers who point out flaws in its device operations or software.

However, many of them still complain that the company doesn’t acknowledge their work on time as the other tech companies do and is showing a lot of slow response in addressing the flaws with relative fixes.

The company also limits its feedback on who will receive a bounty when they highlight it to the world. So, a majority of white hat hackers have shown their reluctance in picking up the flaws and instead are interested in selling their hard work to government agencies or firms offering hacking services.

Hope, the Tim Cook led Consumer Electronics American Company, mends its ways before it’s too late!

The post Apple Inc pays $100,500 to hacker for hacking MacBook Webcam appeared first on Cybersecurity Insiders.


February 03, 2022 at 10:21AM

Register Today! By Popular Demand, More Entry-Level Cybersecurity Certification Pilot Exam Review Offerings Now Available

Register Today

(ISC)² has added two additional offerings to our online instructor-led review sessions in support of the new entry-level cybersecurity certification pilot exam. Our recent offering sold out in record time, and these first come, first serve opportunities are expected to do the same.

The five domains included in the pilot exam outline are:

  • Security Principles
  • Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts
  • Access Controls Concepts
  • Network Security
  • Security Operations

The entry-level cybersecurity certification pilot program will play a leading role in expanding the global cybersecurity workforce, creating new career opportunities and qualification pathways for individuals, and helping employers tackle a global cybersecurity skills shortage in excess of 2.7 million.

Review sessions are available and can be booked for U.S. $225 and includes an entry-level cybersecurity pilot exam voucher (two attempts included).

Dates for the live sessions:

February 7, 8, 9 (Mon, Tues, Wed) – 9:00–11:00 a.m. ET

To Enroll in this course click HERE

February 15, 16, 17 (Mon, Tues, Wed) – 5:00–7:00 p.m. ET

To Enroll in this course click HERE

February 26 & 27 – (Saturday and Sunday) – 1:00–4:00 p.m. ET

To Enroll in this course click HERE

Each session will accommodate 50 students and will be recorded for on-demand playback for those who cannot attend a live session. Sessions include access to example questions, helping candidates review and focus on what to expect on the actual pilot exam when they take it. Candidates will also receive a certificate of completion for the review session.

The certification is designed to be challenging while remaining attainable for newcomers and career changers without direct IT experience, an increasing industry trend according to the (ISC)² Cybersecurity Workforce Study.

To find out more about the (ISC)² entry-level cybersecurity pilot program and to see the exam outline, please visit: https://www.isc2.org/Notice/New-Cert.

The post Register Today! By Popular Demand, More Entry-Level Cybersecurity Certification Pilot Exam Review Offerings Now Available appeared first on Cybersecurity Insiders.


February 03, 2022 at 09:09AM

Menlo Security Finds Cloud Migration and Remote Work Gives Rise to New Era of Malware, Highly Evasive Adaptive Threats (HEAT)

MOUNTAIN VIEW, Calif.–(BUSINESS WIRE)–Menlo Security, a leader in cloud security, today announced it has identified a surge in cyberthreats, termed Highly Evasive Adaptive Threats (HEAT), that bypass traditional security defenses. HEAT attacks are a class of cyber threats targeting web browsers as the attack vector and employs techniques to evade detection by multiple layers in current security stacks including firewalls, Secure Web Gateways, sandbox analysis, URL Reputation, and phishing detection. HEAT attacks are used to deliver malware or to compromise credentials, that in many cases leads to ransomware attacks.

In an analysis of almost 500,000 malicious domains, The Menlo Security Labs research team discovered that 69% of these websites used HEAT tactics to deliver malware. These attacks allow bad actors to deliver malicious content to the endpoint by adapting to the targeted environment. Since July 2021, Menlo Security has seen a 224% increase in HEAT attacks.

“With the abrupt move to remote working in 2020, every organization had to pivot to a work from an anywhere model and accelerate their migration to cloud-based applications. An industry report found that 75% of the working day is spent in a web browser, which has quickly become the primary attack surface for threat actors, ransomware and other attacks. The industry has seen an explosion in the number and sophistication of these highly evasive attacks and most businesses are unprepared and lack the resources to prevent them,” said Amir Ben-Efraim, co-founder and CEO of Menlo Security. “Cyber Threats are a mainstream problem and a boardroom issue that should be on everyone’s agenda. The threat landscape is constantly evolving, ransomware is more persistent than ever before, and HEAT attacks have rendered traditional security solutions ineffective.”

HEAT attacks leverage one or more of the following core techniques that bypass legacy network security defenses:

  • Evades Both Static and Dynamic Content Inspection: HEAT attacks evade both signature and behavioral analysis engines to deliver malicious payloads to the victim using innovative techniques such as HTML Smuggling. This technique is used by threat actors including Nobelium, the hacking group behind the SolarWinds ransomware attack. In one recent case, dubbed ISOMorph, the Menlo Labs research team observed the campaign using the popular Discord messaging app to host malicious payloads.
    • Menlo Labs identified over 27,000 malware attacks that were delivered using HTML Smuggling within the last 90 days.
  • Evades Malicious Link Analysis: These threats evade malicious link analysis engines traditionally implemented in the email path where links can be analyzed before arriving at the user.
  • Evades Offline Categorization and Threat Detection: HEAT attacks evade web categorization by delivering malware from benign websites, either by compromising them, or patiently creating new ones, referred to as Good2Bad websites. Menlo Labs has been tracking an active threat campaign dubbed SolarMarker, which employs SEO poisoning. The campaign started by compromising a large set of low-popularity websites that had been categorized as benign, infecting these websites with malicious content.
    • Good2Bad websites have increased 137% year-over-year from 2020 to 2021.
    • 44% of Menlo Security customers have accessed a website in the past year that falls in the Good2Bad classification, however Menlo’s patented Elastic Isolation Core™ prevented any infection from taking place.
  • Evades HTTP Traffic Inspection: In a HEAT attack, malicious content such as browser exploits, crypto-mining code, phishing kit code and images impersonating known brand’s logos is generated by JavaScript in the browser by its rendering engine, making any detection technique useless.
    • The top three brands impersonated in phishing attacks are Microsoft, PayPal, and Amazon. A new phishing website imitating one of these brands is created every 1.7 minutes.

“Highly Evasive Adaptive Threat (HEAT) attacks evade existing security defenses by understanding all the technology integrated into the existing security stack and building delivery mechanisms to evade detection,” said John Grady, ESG Senior Analyst. “Organizations should focus on three key tenets to limit their susceptibility to these types of attacks: shifting from a detection to a prevention mindset, stopping threats before they hit the endpoint, and incorporating advanced anti-phishing and isolation capabilities.”

For more information on HEAT, please visit our blog, “Too Hot to Handle.”

About Menlo Security

Menlo Security protects organizations from cyberattacks by eliminating the threat of malware from the web, documents, and email. Menlo Security’s isolation-powered cloud security platform scales to provide comprehensive protection across enterprises of any size, without requiring endpoint software or impacting the end user-experience. Menlo Security is trusted by major global businesses, including Fortune 500 companies, eight of the ten largest global financial services institutions, and large governmental institutions. Menlo Security is backed by Vista Equity Partners, Neuberger Berman, General Catalyst, American Express Ventures, Ericsson Ventures, HSBC, and JP Morgan Chase. Menlo Security is headquartered in Mountain View, California. For more information, please visit www.menlosecurity.com.

The post Menlo Security Finds Cloud Migration and Remote Work Gives Rise to New Era of Malware, Highly Evasive Adaptive Threats (HEAT) appeared first on Cybersecurity Insiders.


February 03, 2022 at 09:09AM

ISACA Awards Gala to Recognize Outstanding Technology Professionals for Exceptional Contributions

SCHAUMBURG, Ill.–(BUSINESS WIRE)–Every year ISACA members and tech professionals worldwide serve their organizations and industries with exemplary achievements and noteworthy contributions to advancing technology. Outstanding IT audit, risk, governance, privacy and cybersecurity professionals are being recognized with ISACA’s 2022 Global Achievement Awards and Hall of Fame inclusion for their accomplishments and contributions that advance the professional community and exemplify ISACA’s purpose: helping individuals and organizations realize the positive potential of technology.

The recipients of the 2022 Global Achievement Awards, Chapter Awards, Certification Exam Top Scores, and the 2022 class of the Hall of Fame will be recognized at the in-person ISACA Awards Gala in New Orleans on Wednesday, 4 May at 6:30 pm and at the virtual ISACA Awards Gala on 25 May at 9 a.m. CDT (UTC-5). Tickets are US $100 for the in-person gala in New Orleans and US $25 for the virtual gala, which will include a featured speaker.

Global Achievement Award Winners

The following recipients of the 2022 ISACA Global Achievement Awards will be recognized at each Gala:

ISACA Technology for Humanity Award: Code Your Dreams, USA

“For leadership in empowering the next generation of civic-minded technologists.”

ISACA Educational Excellence Award: Andre Pitkowski, CRISC, CGEIT, Professor, SENAC University, Brazil

“For significant contributions to undergraduate student education in IT governance and information security, and empowering future and current ISACA members and professionals.”

ISACA Inspirational Leadership Award: Kashifu Inuwa Abdullahi, Chief Information Technology Officer, National Information Technology Development Agency, Nigeria

“For leadership in bridging the digital divide by providing computers and other IT infrastructure to rural areas and schools and for providing virtual libraries.”

ISACA Innovative Solutions Award: Eventcombo, USA

“For enabling community connections and continuing education virtually during a global pandemic through innovative EventTech solutions.”

Hall of Fame Inductees

The 2022 class of the Hall of Fame—members honored for showing exemplary dedication to advancing ISACA’s purpose through volunteer service and/or member engagement activities— are member-nominated inductees:

  • Abdul Hamid Abdullah, CISA (Singapore)
  • Steven Ross, CISA, CDPSE (USA)
  • Nalin Wijetilleke, CISA, CGEIT (New Zealand)
  • Frank Yam, CISA (Hong Kong)
  • Turhan Yükseliyor, CISA, CRISC, CISM, CGEIT, CDPSE (Turkey)

“ISACA values the passionate contributions of our members and professionals across our industry,” said Julia Kanouse, ISACA chief membership officer. “Our 2022 award recipients and Hall of Fame inductees have made a meaningful impact in the global professional community, and we are honored to recognize their achievements.”

To learn more about the ISACA Awards Gala and register for the in-person and/or virtual event, visit www.isaca.org/awards-gala.

Nominations for the 2023 Global Achievement Awards, Chapter Awards and the Hall of Fame will be open from 15 May to 15 August. To nominate an outstanding colleague, organization or program, visit https://isaca.secure-platform.com/a/page/awards/aboutawards.

To learn more about the ISACA Awards Program, including the Certification Exam Top Score and Chapter Award recipients, visit www.isaca.org/awards.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews

LinkedIn: www.linkedin.com/company/isaca

Facebook: www.facebook.com/ISACAGlobal

Instagram: www.instagram.com/isacanews

The post ISACA Awards Gala to Recognize Outstanding Technology Professionals for Exceptional Contributions appeared first on Cybersecurity Insiders.


February 03, 2022 at 09:09AM

Orca Security Launches Industry’s First Cloud Risk Encyclopedia to Provide Ongoing Education for Cloud Security Best Practices

PORTLAND, Ore.–(BUSINESS WIRE)–Orca Security, the cloud security innovation leader, today launched the Orca Cloud Risk Encyclopedia to serve as a global resource for practitioners and researchers throughout the InfoSec community. Rapid cloud adoption, increased multi-cloud complexity, and a shortage of cloud security professionals have contributed to a widening cloud security knowledge gap. Orca Security believes in education and transparency and is sharing the same collection of public cloud risks and remediations found in the Orca Security platform, including new discoveries like Superglue and BreakingFormation.

“Orca Security knows it can be a challenge for security professionals to stay on top of the burgeoning number of public cloud security risks,” says Mor Himi, VP, Applied Threat Research and head of Orca Security’s research team, dubbed the ‘Orca Research Pod’. “We hope that by sharing information in the Orca Cloud Risk Encyclopedia about the risks that our research uncovers, along with steps for remediation, we can help IT security professionals harden their public cloud environments and make the cloud a safer place for all of us.”

The Orca Security research team’s vulnerability and incident findings will be continually captured in the Orca Cloud Risk Encyclopedia, serving as a learning hub for cloud security practitioners, researchers, developers, and the press. This valuable resource includes:

  • Find Key Information on the Latest Cloud Security Risks: The encyclopedia includes detailed cloud security risk descriptions, scoring to show which risks are the most critical, and remediation steps.
  • Gain Best Practices for Breach Prevention: By providing a comprehensive collection of cloud security risks along with best practices, security teams can implement preventive measures to improve their security posture.
  • See Which Risks Apply to Particular Compliance Frameworks: By filtering risks for a particular compliance framework or CIS benchmark, security professionals can research the key cloud security risks impacting their compliance programs.

Trending risks listed in the Orca Cloud Risk Encyclopedia:

“The increasingly complex public cloud landscape requires a different approach to security,” said Avi Shua, CEO and co-founder, Orca Security. “Organizations need a comprehensive view of their rapidly evolving cloud estate to identify issues, close neglected access points, and improve their security posture. Opening up a core part of our platform in the form of our Cloud Risk Encyclopedia aligns with our commitment to increased transparency in the cybersecurity industry, to help shift the balance of power back to defenders and away from threat actors.”

Cloud Security and Transparency in Cybersecurity Resources:

About the Orca Cloud Risk Encyclopedia

The Orca Cloud Risk Encyclopedia is designed to be a go-to resource for developers, IT architects, and security professionals to find information on cloud risks, remediation strategies, and best practices, in an effort to help organizations prevent security breaches. The Encyclopedia’s risk listings are pulled directly from the Orca cloud security platform and can be filtered by cloud platform, risk category, compliance framework, and risk score. With regular cloud risk additions and optional email notifications, the Encyclopedia also helps IT security professionals and researchers stay informed about new and trending cloud security risks.

About Orca Security

Orca Security provides instant-on security and compliance for AWS, Azure, and GCP - without the gaps in coverage, alert fatigue, and operational costs of agents or sidecars. Simplify cloud security operations with a single CNAPP platform for workload and data protection, cloud security posture management (CSPM), vulnerability management, and compliance. Orca Security prioritizes risk based on the severity of the security issue, its accessibility, and business impact. This helps you focus on the critical alerts that matter most. Orca Security is trusted by global innovators, including Databricks, Autodesk, NCR, Gannett, and Robinhood. Connect your first account in minutes: https://orca.security or take the free cloud risk assessment.

The post Orca Security Launches Industry’s First Cloud Risk Encyclopedia to Provide Ongoing Education for Cloud Security Best Practices appeared first on Cybersecurity Insiders.


February 03, 2022 at 09:08AM

Axio Joins with Cyber Risk Institute to Deliver Cybersecurity Resilience to Financial Services Institutions Across the Globe

NEW YORK & WASHINGTON–(BUSINESS WIRE)–Axio, a leading SaaS provider of cyber risk management and quantification solutions, today announced a new joint initiative with the Cyber Risk Institute (CRI), a non-profit coalition of financial institutions and trade associations. Together, Axio and CRI’s combined talents will deliver the CRI Cyber Profile tool to CRI members and other interested financial institutions with the Axio360 platform.

The CRI Profile is the benchmark for cyber security and resiliency in the financial services industry. The rapid increase of cyber security requirements for financial firms has created a challenge for many institutions fighting to meet these requirements. CRI’s Profile is designed to help financial organizations continue to meet these regulatory expectations while improving all crucial security efforts by streamlining compliance activity. The CRI Profile is currently being used as the cyber risk assessment tool of choice by financial institutions of varying sizes and complexities.

“The Profile is based on established frameworks and standards, and Axio principals are experts in cyber security framework authorship and architecture,” says Scott Kannry, CEO of Axio. “We understand how financial organizations can achieve the maximum benefit by dynamically using the CRI Profile. It is my pleasure to announce the advantages that financial institutions and other organizations will enjoy by using the Profile on Axio360.”

The Axio platform was built to deliver on the belief that cyber security is not a challenge that can only be managed by compliance frameworks or periodic static assessments. The Profile is designed to scale across financial institutions of varying complexity, interconnectedness, and criticality. The robust functionality of Axio360 complements and supports the use of the Profile as a dynamic management method instead of just an assessment “snapshot” in time.

“From the sleek user interface to the Axio team’s technical expertise, CRI felt that the Axio platform provides both form and substance,” says Josh Magri, CRI Founder and President.

“Our initiative with Axio will help our member organizations and the broader financial services community more effectively use the Profile as a controls management tool. As a result, financial organizations will be better enabled to succeed in the cyber fight by allowing them to focus on risks that matter the most.”

The benefits of the CRI Profile being delivered via Axio360 include:

  • Optimized ease-of-use in using the Profile dynamically, setting and managing target profiles and stakeholder collaboration
  • Robust, anonymized peer benchmarking across CRI profile users
  • The ability to manage and view multiple deployments of the Profile across different operating entities with medium and large financial institutions.

About Axio: Axio is the leader in SaaS-based risk management software, which empowers security leaders to build and optimize security programs and quantify risk for better investment prioritization and decision-making. Since 2013, Axio has been a trusted partner of the world’s leading critical infrastructure, manufacturing, and financial services organizations. Axio360 is the only risk management platform designed to align security leaders, business leaders, executives, and Boards of Directors around a common set of benchmarks, performance metrics, and shared understanding of the most critical corporate risks. Learn more at http://www.axio.com.

About CRI: The Cyber Risk Institute (CRI) is a not-for-profit coalition of financial institutions and trade associations. CRI is working to protect the global economy by enhancing cybersecurity and resiliency through assessment standardization. Its Cyber Profile tool is the benchmark for cyber security and resiliency in the financial services industry. Learn more at https://cyberriskinstitute.org/.

The post Axio Joins with Cyber Risk Institute to Deliver Cybersecurity Resilience to Financial Services Institutions Across the Globe appeared first on Cybersecurity Insiders.


February 03, 2022 at 09:08AM

Lattice to Host Virtual Seminar on Anti-Fragile Security and Post-Quantum Cryptography in FPGAs

HILLSBORO, Ore.–(BUSINESS WIRE)–Lattice Semiconductor (NASDAQ: LSCC), the low power programmable leader, today announced the company will host a virtual seminar about the challenges, opportunities, and latest programmable logic solutions for anti-fragile security and post-quantum cryptography.

The seminar will explore today’s cybersecurity trends and risks as the threat of system fragility increases. We will discuss how to use FPGAs to future-proof systems for resilient and secure silicon, solutions, and services to reduce risk and decrease fragility. In addition, we will also focus on post-quantum cryptography and rapidly approaching standards requirements.

Who: Lattice Semiconductor

What: Anti-Fragile Security and Post-Quantum Crypto in FPGAs

When: Tuesday, Feb. 22, at 7 a.m. PST or 5 p.m. PST

Where: Lattice Security Seminar (Advance registration is required)

About Lattice Semiconductor

Lattice Semiconductor (NASDAQ: LSCC) is the low power programmable leader. We solve customer problems across the network, from the Edge to the Cloud, in the growing Communications, Computing, Industrial, Automotive, and Consumer markets. Our technology, long-standing relationships, and commitment to world-class support let our customers quickly and easily unleash their innovation to create a smart, secure, and connected world.

For more information about Lattice, please visit www.latticesemi.com. You can also follow us via LinkedIn, Twitter, Facebook, YouTube, WeChat, Weibo, or Youku.

Lattice Semiconductor Corporation, Lattice Semiconductor (& design), and specific product designations are either registered trademarks or trademarks of Lattice Semiconductor Corporation or its subsidiaries in the United States and/or other countries. The use of the word “partner” does not imply a legal partnership between Lattice and any other entity.

GENERAL NOTICE: Other product names used in this publication are for identification purposes only and may be trademarks of their respective holders.

The post Lattice to Host Virtual Seminar on Anti-Fragile Security and Post-Quantum Cryptography in FPGAs appeared first on Cybersecurity Insiders.


February 03, 2022 at 09:08AM