FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Friday, February 4, 2022

Cloud Threats: What Business Executives Need To Know Right Now

FREDERICK, Md.–(BUSINESS WIRE)–In a brief video explainer and commentary, Josh Stella, co-founder and CEO of Fugue, the cloud security and compliance SaaS company, talks to business and security leaders about what hackers are searching for when they target cloud computing infrastructures and how to thwart them.

The ancient Chinese general Sun Tzu famously wrote: “If you know the enemy and know yourself, you need not fear the result of a hundred battles.” That advice is just as relevant today as companies face a constant, never-ending war against hackers attacking their cloud computing infrastructures. Ninety percent of hacking is discovery, and 90% of defending is knowledge. Before you implement any security products or adopt new processes, you must first understand your cloud environment, and the unique threats against it.

A New Threat Landscape

The cloud infrastructure is very different from the data center. Developers and engineers build their own cloud infrastructure when they need to and have the ability to make (and change) their own infrastructure decisions, including security-critical configurations. This is significant because each change creates the risk of a misconfiguration left open to attack. And make no mistake about it — the bad guys will find it.

What Is a Cloud Misconfiguration?

A misconfiguration is anything that proves ineffective at stopping a hacker. These vary from individual misconfigurations like leaving a dangerous port open or not patching a server to significant architectural problems that are easier for security teams to overlook. I guarantee that your organization has both kinds of misconfigurations in your cloud environments.

The primary driver of cloud computing is application programming interfaces (APIs) — the software “middlemen” that allow different applications to interact with each other. This eliminates a fixed IT architecture requirement in a centralized data center. It also means the traditional security model for securing data centers you may be familiar with — erecting an outward-facing barrier around the network perimeter to block incoming attacks — is not applicable in the cloud.

The control plane is the API surface that configures and operates the cloud. For example, you can use the control plane to build a container, modify a network route, and gain access to data in databases or snapshots of databases (which are more prevalent among hackers than breaking into live production databases). Put simply, the API control plane is the collection of APIs used to configure and operate the cloud.

Hackers are focused on finding and exploiting misconfigurations to get to the control plane APIs. Therefore, cloud security is a function of design and architecture, not monitoring and intrusion detection. By the time you’ve detected something, the damage has already been done.

Unfortunately, the security industry remains a step behind the hackers because many vendors do not protect their customers against attacks that target the cloud control plane. Frankly, most of them are meeting checkboxes to make senior executives and security teams feel better — until they’re hacked. It’s a security theater, and it remains all too prevalent in our business.

The Alphabet Soup of Cloud Security Categories

As a result, executives and security professionals are constantly bombarded by various security solution product categories and acronyms like CWPP, CNAPP and CSPM. But the hackers aren’t thinking about subverting vendors’ and analysts’ naming categories. They are thinking about how to get into your environment to do damage; that is all that matters to them.

You need to cut through the noise, clutter and confusion to understand where you should focus your attention. Don’t think about security in terms of individual product categories; they’re meaningless.

Lesson Learned From Real Cloud Breaches

Consider the 2019 Capital One data breach, which remains one of the largest ever to hit a big financial institution. The attacker broke through a misconfigured firewall (facilitated by permissions Capital One set that were likely broader than intended) to access a server and ultimately steal more than 100 million consumer credit applications.

The hacker didn’t care about getting into the server, except that doing so enabled them to surf the identity and access management (IAM) “network” using API keys to find and steal the data. Identifying that attack vector was the key to thwarting the attack, not whether Capital One had checked off that they had installed their vendors’ security products.

Hackers don’t live within the constraints of an organization’s security tools. Effective cloud security solutions ignore those product categories and focus instead on preventing what hackers do by analyzing all configurations and scenarios as a whole — because that’s what the hackers are doing.

A typical hack on the cloud spans identity, configuration (not just configuration of resources, but policy configuration of identity), the accessibility of resources, and the particular mechanisms you may use for encryption. The gaps that we see in most vendors’ security approaches are grounded in a false sense of security because they think they have satisfied all the items on a checklist.

The result is that a company feels confident in saying, “We have encryption turned on at rest,” but it doesn’t bother to examine whether it has an exposed identity, which contains credentials both to the data source and the keys for encryption, that’s long-lived and resident on a device in their cloud infrastructure.

Rest assured, that’s what the hackers are looking for because they don’t care about the categorization or the list of things that as security practitioners we do to make ourselves feel better. Creating an effective cloud security system requires that you first understand these threats. The most effective approach is to use Policy as Code.

Policy as Code

When developers build applications in the cloud, they’re also building the infrastructure for the applications instead of buying a pile of infrastructure and adding apps into it. That is a coding process using Infrastructure as Code, and developers own that process. Therefore, the security team’s role becomes that of the domain expert who imparts knowledge to the developers to ensure they work in a secure environment. The way you can do that is with Policy as Code, which enables your team to express security and compliance rules in a programming language that an application can use to check the correctness of configurations.

Policy as Code is designed to check other code and running environments for unwanted conditions. It empowers all cloud stakeholders to operate securely without ambiguity or disagreement on the rules and how to apply them at both ends of the software development life cycle (SDLC).

Leverage Automation Technology

Policy as Code also enables you to automate the continuous search for misconfigurations and, in some cases, their remediation. This relieves your security and infrastructure teams of the responsibility of spending the bulk of their time every day doing so via time-consuming, error-prone manual processes. A holistic response requires you to implement Policy as Code at the development phase, in the runtime, and the continuous integration/continuous delivery (CI/CD) pipeline. As you gain maturity, these things can then be institutionalized and built into your processes so that it’s all automated.

Protecting your cloud infrastructure begins with understanding how attackers think and operate and, critically, just how different their methodologies are compared to hackers targeting systems in the on-premises data center. You’ll likely discover your security team has implemented a grab bag of point solutions, perhaps all acquired from one vendor with one product name, that is insufficient in solving the little pieces of what Policy as Code can solve, fundamentally and strategically.

About Josh Stella

Josh Stella, co-founder and CEO of Fugue, is a technical authority on cloud security. Bringing 25 years of expertise as a chief technology officer, principal solutions architect at Amazon Web Services, and advisor to intelligence agencies, Josh founded Fugue in 2013 to help companies proactively change the security paradigm and get ahead of the hackers. He wrote the first book on “Immutable Infrastructure,” holds numerous cloud security technology patents, and hosts complimentary Cloud Security Masterclasses. Connect with Josh on LinkedIn and via Fugue at www.fugue.co.

About Fugue

Fugue is a cloud security and compliance SaaS company enabling regulated companies such as AT&T, Red Ventures, and SAP NS2 to ensure continuous cloud security and earn the confidence and trust of customers, business leaders, and regulators. Fugue empowers engineering and security teams to automate cloud policy enforcement and move faster than ever before — without breaking the rules. Since 2013, Fugue has pioneered the use of policy-based cloud security automation and earned the patent on policy as code for cloud infrastructure. For more information, connect with Fugue at www.fugue.co, GitHub, LinkedIn and Twitter.

All brand names and product names are trademarks or registered trademarks of their respective companies.

Tags: Fugue, cloud security, SaaS, Josh Stella, policy as code, cybersecurity, cloud, infrastructure as code, open source, cloud security automation, network configuration, cloud configuration, cloud misconfiguration, ransomware, data breach, cloud threats, application programming interface, API

The post Cloud Threats: What Business Executives Need To Know Right Now appeared first on Cybersecurity Insiders.


February 04, 2022 at 09:08PM

US hacker claims to have downed the internet of North Korea

A hacker from United States named P4x has admitted that he took down the internet of North Korea last week by launching a distributed denial of service attack on the central DNS servers of the country.

The denial of service attack launched by P4x was retaliation for the digital attack made on him or the US government by Pyongyang’s DPK hackers.

Reports are in that the attack might have been funded by American intelligence in order to punish the Kim Jong Un nation for testing missiles from September 2021.

To those uninitiated, most of the websites in North Korea were down after a digital disruption caused by P4x and that includes web portals related to Air Koryo, Naenara, and the website linked to the Communist Party led by Mr. Kim.

Security experts feel that the cyber attack launched by the US based hacker could have a backup of expertise from the Joe Biden led administration, as causing disruption to the critical infrastructure of an adversary nation is not that easy for a budding hacker.

P4x claimed that most of the IT infrastructure operating in North Korea was obsolete and so that made him exploit the vulnerabilities to down the infrastructure within no time.

According to United Nations, over 35 countries have been targeted by hackers from Pyongyang till date and the principal motive behind the attacks is to fund the nuclear ambitions of Kim Jong Un by stealing money from financial institutions like banks and cryptocurrency exchanges.

Note- On February 2nd,2022, Kim appeared specially on a white horse galloping in the forest and captured on the camera lens for a short film on the occasion of Lunar New Year. And for the first time in the history of KCTV- the official media platform of the Kim Jong government, his wife Ri Sol Ju and his aunt Kim Kyong Hui appeared beside him at the theatre event to celebrate the birthday of Kim Jong II yesterday. Kim Kyong was thought to have died following an execution by her narrow-minded husband, Jang Song Thaek, 6 years ago.

The post US hacker claims to have downed the internet of North Korea appeared first on Cybersecurity Insiders.


February 04, 2022 at 11:12AM

Thursday, February 3, 2022

Cyber Attack on Europe’s major Oil terminal

A Cyber Attack on Europe’s major oil terminal could trigger an oil shortage in coming days and that too at the time when the entire nation was suffering to curtail the already high energy prices.

Cybersecurity Insiders have learnt that the fuel shortage is being caused because of a digital attack that has affected all the port terminals that handle oil barges. And as the shipping of these barges is delayed, fuel traders expect a surge in oil prices in coming weeks.

Interestingly, the disruption was caused during the same time when Germany’s Oiltanking Deutschland GmBH & Co. KG, the business that stores and supplies oil was hacked.

EU’s Europol has been asked to investigate the incident and the prima facie conducted revealed that the primary victim of the incident turned out to be Amsterdam- Rotterdam- Antwerp Oil Trading Hub.

According to a Belgian Police, SEA- Tank Terminal, that stores and process oil reserves to different parts of the nation were also down because of the cyber attack and highly placed sources confirm that the incident could have been triggered by ransomware spreading gang/s.

With almost whole of Europe’s critical infrastructure being hit by cyber attacks, the Dutch National Cyber Security Centre believes the attacks seem like a kind of cyber war launched by the adversary nations like China and Russia.

And with the assurance of a Russian war with Ukraine on the cards, the suspicion finger points strongly at the Vladimir Putin led nation.

The post Cyber Attack on Europe’s major Oil terminal appeared first on Cybersecurity Insiders.


February 04, 2022 at 11:10AM

AT&T Cybersecurity Insights Report: Securing the Edge – Available today

The data is in, the analysis is done, and the eleventh edition of the AT&T Cybersecurity Insights™ Report: Securing the Edge is ready for you!

We know cybersecurity is a journey and not a destination, that is why each year we look forward to the publication of this report, a guide to help you on your journey to cybersecurity resiliency.

Since the ninth edition of this report, we examined what it means to safeguard your digital assets in a new compute paradigm underpinned by 5G and edge. I encourage you to read the previous two reports – AT&T Cybersecurity Insights Report: Security at the Speed of 5G and AT&T Cybersecurity Insights Report: 5G and the Journey to the Edge along with this new report to gain an understanding of the necessarily increasing role of cybersecurity in organizations of all types and sizes.

Before I highlight some of the key findings from our current report, here are some demographic elements to help set context.

This report is a vendor-neutral thought leadership piece that:

  • Offers quantitative analysis – a global survey of 1,520 professionals in security, IT, and line of business
  • Delivers qualitative analysis – subject matter expert interviews with technical leaders across the cybersecurity industry
  • Focuses on common edge use cases in six vertical industries – healthcare, retail, finance, manufacturing, energy, and U.S. public sector
  • Presents actionable advice for securing the edge
  • Examines cybersecurity and the broader edge ecosystem of networking, service providers, and top use cases

Securing the edge

Let’s examine some of the key findings of the report. A great place to start is with the title of the report – AT&T Cybersecurity Insights Report: Securing the Edge. The first question most readers posit is “what do you mean by “edge””? Our research shows that edge means different things to different people. This is analogous to early days of the cloud when there was little consensus on the definition of the cloud, however, there were common characteristics that helped identify the cloud.

Likewise, we are in that same state of flux in searching for a standard definition of “edge”. While our research finds no standard definition of “edge”, we do have three common characteristics that edge deployments may share. Those common characteristics are:

  • A distributed model of management, intelligence, and networks
  • Applications, workloads, and hosting closer to users and digital assets that are generating or consuming the data, which can be on-premises and/or in the cloud
  • Software defined (which can mean the dominant use of private, public, or hybrid cloud environments; however, this does not rule out on-premises environments)

These common characteristics of edge will serve the industry well as we move to an even further democratized version of computing with an abundance of connected IoT devices that will process enormous amounts of data.

Report goal

At the onset of our research, we wanted to understand three primary things:

  1. What are the most common architectures used in edge networks?
  2. What are the most common use cases of these architectures?
  3. What is the perceived risk and perceived benefit of the common use cases?

We found some surprising and some not so surprising answers to these three broad questions.

Edge deployments have momentum

Our research shows that edge deployments have surprising momentum despite a high concern of “perceived risk” among organizations globally.  Security is a critical success factor for edge initiatives.

More edge network projects are underway—and completed in production—than one might anticipate. Many edge use cases are partially or fully implemented across industries and geographies using diverse network environments and security controls. The line of business sees the necessity and benefit of edge use cases.

Over 40% of the surveyed population are in the mature stage of adoption on specific edge projects, with each vertical industry as follows: 

  • 52% of retail and public sector are in the mature stage
  • 52% of manufacturing are in the mature stage
  • 47% finance are in the mature stage
  • 43% healthcare are in the mature stage
  • 40% energy and utilities are in the mature stage

Globally and across industry use cases, loss prevention in retail and video-based quality inspection in manufacturing have the highest rate of mature stage adoption (59%).

While edge deployments have momentum and we are seeing these in production, there is still a high level of perceived risk and overall impact to the business. Across all vertical industries, survey participants resoundingly told us they believe there is a high likelihood of a cybersecurity attack and a high impact to the organization as a result.

Despite these perceived risks, organizations see the competitive benefit of edge deployments. In our 2021 report, 58% of respondents told us they were adopting 5G and edge technologies to remain competitive.

The high number of edge deployments is encouraging and shows that cybersecurity is no longer an activity performed by a select few. The rapid business and digital transformation of the last two years moved cybersecurity from a being a technical issue to a business enabler and requirement.

We provide deeper analysis of edge deployments, perceived risk factors, and concerns of attack vectors in the report.

Hybrid is the reality

Architectures for edge networks and security controls continue to exist in a hybrid world – on-premises and multi-cloud. According to our survey participants, this hybrid world is a reality for the foreseeable future of at least the next three years and possibly longer.

This hybrid approach is evidenced by how organizations view cybersecurity controls and network functions. Secure access service edge (SASE), which converges network functions and security controls, is top of mind for all vertical industries surveyed.

Our research shows an almost equal split in the number of respondents interested in either deploying an on-premises solution that mirrors the security plus network capabilities (51.9%) and/or deploying a similar solution in the cloud, i.e. SASE (51.3%).

This almost equal approach to on-premises and cloud is typical as new and innovative technologies are introduced to market. Some of this split may also have to do with a perceived readiness and risk appetite of an organization. A more conservative view may take an on-premises approach while organizations with a greater appetite for risk may be willing to go all-in on a cloud approach.

See the full report for a detailed breakdown of on-premises and cloud preferences for network functions, security controls, and network types preferred for edge deployments.

In with the old and in with the new – Legacy security controls still remain

The cost of various security controls vs. effectiveness of those controls is still “in debate.”

More importantly, organizations are adopting new approaches and emerging security solutions, but those same organizations are definitely not finished with legacy controls.

It is very telling that organizations are not yet willing to part with legacy cybersecurity controls. We asked our survey participants about the perceived cost benefit of legacy security controls.

Respondents simply stated that the following were the most cost effective:

  • Firewall at network edge
  • Intrusion/threat detection
  • Network access restrictions device-device
  • Data leakage monitoring
  • Password authentication
  • Application proxy (e.g., secure web gateway, CASB, etc.)

An important mention is that patching is ranked low in terms of cost effectiveness. Patching is reactionary, manual, and time-consuming. Edge deployments require always available networks, ephemeral and high-quality applications, and seamless integration. As organizations look to the future it is likely they will leave manual activities such as patching behind and focus on automation, integration, and real-time alerts for security controls.

The good news with edge deployments is that security is top of mind and on average all industries surveyed expect security to be in the range of 11 – 21% of the total project budget.

We offer up different views of the cost benefit, preferred cybersecurity controls by network and devices, and a look into overall security budgets for edge deployments. This analysis can be extremely helpful as you move forward with ideation, planning, or implementation of your edge deployments.

Removing the silos

We are enthusiastically moving to a world of edge computing. Whether that edge is in your city, your farm, your car, or your home – change is coming. This change calls for a new way of organizations working together – collaborate and communicate cross-functionally, remove artificial barriers to deliver exceptional edge experiences, and challenge old ideas of what security is and how it is implemented.

Edge use cases are abundant, read the AT&T Cybersecurity Insights Report: Securing the Edge to see how very real use cases across industries are.

If you are struggling with how to think about or implement edge deployments, work with a trusted advisor who has experience in this area. A full 65% of our survey participants are working with a third-party for designing and deploying new architectures for edge use cases.

Get the newly released AT&T Cybersecurity Insights Report: Securing the Edge here.

Special thanks

A report of this scope and magnitude comes together through a collaborative effort of leaders in the cybersecurity market. A special thanks to our sponsors for their contributions and guidance on this report.

  • Akamai
  • Check Point
  • Cisco
  • Digital Defense, by HelpSystems
  • Fortinet
  • Juniper Networks
  • Palo Alto Networks
  • RedShield
  • SentinelOne
  • VMware

One more thing

Join our webcast to learn more about the AT&T Cybersecurity Insights Report: Securing the Edge. We look forward to welcoming you and sharing more highlights of this research. Register here.

The post AT&T Cybersecurity Insights Report: Securing the Edge – Available today appeared first on Cybersecurity Insiders.


February 04, 2022 at 09:09AM

Security Awareness Training and Human Risk Management Company AwareGO Achieves Year of Outstanding Growth

SAN ANTONIO–(BUSINESS WIRE)–Security Awareness Training and Human Risk Management company AwareGO today announced company milestones achieved and overall performance for 2021, including record year-over-year online revenue growth of 219%, enterprise revenue growth of 156%, and total revenue growth of 116%.

“AwareGO is unparalleled in the industry when it comes to making a client’s workforce cyber-secure through training and awareness-building that produces measurable and positive impact,” said Chief Executive Officer Dr. Ari Jónsson. “Our solution offers a pioneering way to measure employee awareness and behavior across a range of cyber security threat areas, combined with a unique approach to training that is loved by users and proven to increase cyber security awareness and change behavior. This leaves the company very well positioned to continue the rapid growth of its customer base and revenue in 2022. We are looking forward to an exciting year that is already off to a fantastic start.”

Company and Culture

In August, AwareGO welcomed its new chief executive officer (CEO), former NASA Ames Center research scientist and Stanford alumni, Ari K. Jónsson, Ph.D. Jónsson will be leading the company through its next phase of rapid growth and expansion, which includes a future Series A funding round to support the company’s product development and to scale its global sales and marketing efforts. Former CEO and company co-founder Ragnar Sigurdsson remains with the company as head of Research and Development.

AwareGO continues to experience steady growth across the globe. Today, the company has 26 full-time employees across the USA, Iceland, the Czech Republic, and Croatia. Eyrir Venture Management is the company’s largest financial backer, supporting the company diligently for nearly three years.

Customer Growth and Retention

AwareGO continued to demonstrate a near-perfect customer retention rate of 99%. Monthly active users grew by 200% and monthly recurring revenue grew by 116%. Over half of AwareGO’s customers come from industries that are number one targets for cybersecurity attacks, including finance and insurance as well as manufacturing and energy.

In the oil and gas industry, as corporate leaders have begun to recognize the importance of assessing and managing human risk in cybersecurity and properly training the workforce, they have increasingly found AwareGO’s solution to be the right fit to address those issues.

Additionally, AwareGO’s small-and medium-sized enterprise (SME) clients appreciate the ease with which they can implement AwareGO; the ability to purchase the entire solution online means that assessment and training can start immediately and at the company’s convenience. As a result, AwareGO experienced over 200% growth in the SME sector.

AwareGO Launches Groundbreaking Human Risk Assessment

In 2021, AwareGO made significant investments in product development. In December, the company launched its new and industry-leading product, Human Risk Assessment (HRA) for Enterprise. Created by cybersecurity experts, behavioral scientists, and interaction designers, the product continuously observes top human threat vectors, identifies vulnerable departments and roles, and offers actionable insights to create informed security strategies to improve a company’s overall cyber defense and reduce cybersecurity risks.

AwareGO’s HRA product-market fit and scalability has already been implemented by a multi-billion global food company, which rolled out the solution for use and testing to more than 70,000 of its employees and contractors. AwareGO has continued to improve HRA’s already exemplary performance through additional training content production in the form of more than 70 microlearning videos and assessment questions for new and established threat areas. In addition, HRA now supports 18 languages, 9 of which are fully localized.

Partner Program

AwareGO’s partner program has also already garnered positive attention and engagement, with program revenue growing close to 75%. The company currently has 30 partners in its network and is providing services to well over 300 companies through the network.

Awards

AwareGO was the recipient of numerous industry accolades in 2021:

  • Gartner: Representative Vendor in the 2021 Gartner Market Guide;
  • SC Awards Europe 2021: Highly Commended, Best Behaviour Analytics/Enterprise Threat Detection Category;
  • Global InfoSec Awards for 2021: Winner, Editor’s Choice Award in Cybersecurity Education for Enterprises;
  • CyberTech100 2021: Included in the list of the world’s top 100 most innovative CyberTech companies that every financial institution needs to know about in 2021.

Plans for 2022

Heading into the coming year, AwareGO will continue to focus on growing the company and strengthening its HRA solution. The goals for company growth will include pursuing a round of Series A funding, enacting a stronger market push, and expanding the U.S sales team as well as the customer success and engineering teams.

AwareGO’s HRA product improvements will include stronger integration with phishing simulation, attack surface management, security information and event management, and managed security service providers and learning management system platforms. Along with HRA’s existing ease of integration, these enhancements will help businesses add human risk measurement into their cybersecurity strategies and to build up resilience.

About AwareGO

AwareGO is a global provider of human cyber risk and awareness solutions that help enterprises, and SMEs identify, quantify and remediate the human risk factor when it comes to cybersecurity. To date, AwareGO has successfully trained more than 8 million employees worldwide. Based in Iceland, the company has locations in the United States, Czech Republic, and Croatia. For more information, visit awarego.com.

The post Security Awareness Training and Human Risk Management Company AwareGO Achieves Year of Outstanding Growth appeared first on Cybersecurity Insiders.


February 04, 2022 at 09:09AM

New Cloud Security Alliance Survey Finds Uneven Adoption of Emerging Technologies

SEATTLE–(BUSINESS WIRE)–The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today released the findings of its latest survey, Cloud Security and Technology Maturity. Commissioned by CyberRes, a Micro Focus line of business, one of the world’s largest enterprise software providers, the survey offers insight into organizations’ current and future plans regarding cloud strategy, security strategy, cloud services, and cloud-related technologies.

“Cloud is a continuously evolving space with new services, strategies, and technologies springing up seemingly overnight. It’s imperative, therefore, that organizations regularly change and adapt their approach to cloud and cloud security,” said Hillary Baron, lead author and research analyst, Cloud Security Alliance. “While many of the survey’s findings were in line with what we would expect, it was surprising that some technologies that have garnered the most hype are not, in fact, what organizations are planning to implement.”

Despite the introduction of the General Data Protection Regulation (GDPR) in 2018, privacy-by-design is in the development stage with two-thirds of the organizations (65%) either currently building or planning to build the strategies, while only eight percent of respondents indicated having a fully implemented privacy-by-design strategy. Similarly, the survey found that while blockchain and distributed ledger technology have been hyped for years, implementation rates have stagnated, likely as a result of high failure rates stemming from a lack of technical knowledge coupled with a high demand on resources. Quantum-safe security and 5G are also not seeing widespread implementation to date, with further analysis needed to analyze causes and predict a more robust implementation timeline.

“The results of this survey were just as notable for what it did find, as what it didn’t reveal. The growing popularity of artificial intelligence, machine learning, and Zero Trust, for instance, was definitely in keeping with what we have been hearing anecdotally across the industry, but there were also some surprises in what companies aren’t using. While multi-cloud adoption is strongly favored, many organizations are facing challenges in taking deployments to a next level. There is a higher need to provide security technologies that help alleviate these concerns,” said Satya Divadari, Head of Enterprise Security Architecture, CyberRes, a Micro Focus line of business.

Among the survey’s key findings:

  • Organizations are utilizing multi-cloud despite the challenges.
  • Although the concept of privacy-by-design was introduced over a decade ago, 26 percent of organizations have no plans to implement a privacy-by-design strategy, indicating low maturity in this space.
  • The top three cloud-related technologies that organizations plan to implement in the next two years are zero trust (60%), artificial intelligence (AI)/machine learning (43%), and serverless computing (42%).
  • Use of software-defined perimeter (47%), attack service management (45%), and Cloud Security Posture Management (45%) is expected to increase in the next two years.
  • The top technologies that organizations are not planning to use are blockchain (59%), quantum-safe security (54%), and 5G (49%).

The survey, which was conducted with CyberRes and CSA’s Bangalore Chapter, gathered 256 responses from IT and security professionals from various organization sizes, industries, locations, and roles. Sponsors are CSA Corporate Members who support the research project’s findings but have no added influence on the content development or editing rights of CSA research.

Download the full survey.

About CyberRes

CyberRes is a Micro Focus line of business. We bring the expertise of one of the world’s largest security portfolios to help our customers navigate the changing threat landscape by building both cyber and business resiliency within their teams and organizations. CyberRes is part of a larger set of digital transformation solutions that fight adverse conditions so businesses can continue to run today, keep the lights on, and transform to grow and take advantage of tomorrow’s opportunities.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA’s activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

The post New Cloud Security Alliance Survey Finds Uneven Adoption of Emerging Technologies appeared first on Cybersecurity Insiders.


February 04, 2022 at 09:08AM

Wednesday, February 2, 2022

Apple Inc pays $100,500 to hacker for hacking MacBook Webcam

Apple Inc, the American tech giant that produces iPhone, has paid $100,500 to a hacker for hacking MacBook Webcam. Ryan Pickren is the hacker who was rewarded well by the iOS giant as he brought to their issue a severe vulnerability that could have allowed criminals to sneak into the computing activities of Mac users.

Ryan said to have picked up the vulnerability from the safari browser of the MacOS allowing him/or the hacker to gain full access to a device through the multimedia permission application dubbed ShareBear. Thus, from here on, the threat actor gained access to all the info being exchanged via the browser that includes Gmail, iCloud, Facebook and PayPal credentials.

From the past few months, Apple has been well rewarding the security researchers who point out flaws in its device operations or software.

However, many of them still complain that the company doesn’t acknowledge their work on time as the other tech companies do and is showing a lot of slow response in addressing the flaws with relative fixes.

The company also limits its feedback on who will receive a bounty when they highlight it to the world. So, a majority of white hat hackers have shown their reluctance in picking up the flaws and instead are interested in selling their hard work to government agencies or firms offering hacking services.

Hope, the Tim Cook led Consumer Electronics American Company, mends its ways before it’s too late!

The post Apple Inc pays $100,500 to hacker for hacking MacBook Webcam appeared first on Cybersecurity Insiders.


February 03, 2022 at 10:21AM