FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Monday, April 4, 2022

Russian intelligence food habits leaked from food delivery app data breach

Russian food delivery app Yandex Food recently became a victim of a cyberattack that led to the leak of phone numbers, addresses, names, and delivery locations of over 58k users.

The incident took place on March 1st this year and investigations revealed the leak occurred because of a lack of awareness of cyber hygiene in one employee of Yandex Food, a business unit of the Russian internet firm, Yandex.

Roskomnadzor has responded to the incident and released a press statement that the company has to pay a penalty of 100,000 rubles for exposing its user information to hackers.

Meanwhile, investigations made by researchers from Netherlands-based business firm Bellingcat revealed that the leaked info contained information regarding those working for intelligence service and their day-to-day food habits and the parcel delivering address details.

That means any hacker could have accessed and copied the information and use that data to launch poisoning attacks, like the one witnessed in the death of opposition leader Alexey Navalny.

Bellingcat is into investigative journalism opines that such data leaks could lead to the disclosure of sensitive information, such as the food habits of military and intelligence officials. And that could further lead to potential poisoning campaigns such as the Federal Security Service (FSB) plan to assassinate Navalny, with a poisonous substance.

Yandex has issued an apology and assured us it will take all necessary measures to eradicate such incidents in the future.

What if the names and email addresses lead to information leak blunders, such as vehicle registration number leaks?

One can just search the contact details belonging to the Russian Main Intelligence Directorate(GRU) by knowing their email address and name.

 

The post Russian intelligence food habits leaked from food delivery app data breach appeared first on Cybersecurity Insiders.


April 04, 2022 at 03:53PM

Sunday, April 3, 2022

Changes to the CISSP Exam Length Coming Soon

Guy-On-LaptopBeginning June 1, 2022, additional pretest items and time will be added to the CISSP exam for the Computerized Adaptive Testing (CAT) format. 

The current CISSP CAT exam contains 25 pretest (unscored) items. The addition of 25 more items will bring the total count to 50 pretest items. With these added items, the minimum and maximum number of items candidates will need to respond to during the exam  Corp-CISSP-Logo-Square_Markwill increase from 100-150 to 125-175. To allow for these additional items, the maximum exam administration time will increase from three to four hours.  

Pretest items enable (ISC)² to continue expanding our item bank to strengthen the integrity and security of the CISSP for all those who earn the certification. The additional 25 pretest items will be evaluated for inclusion as operational (scored) items in future exams. The pretest items will be indistinguishable from operational (scored) items and should be considered carefully to select the best possible answer. Responses to pretest items will not impact scores or the pass/fail result of the examination.

There are no other changes to the content of the CISSP exam. The domains and domain weights contained within the CISSP exam outline have not changed. These changes impact candidates who are scheduled for the CISSP CAT exam on or after June 1, 2022 

If you wish to change your examination date, you may do so by contacting Pearson VUE. All policies regarding exam rescheduling remain in effect.  

For more information, visit www.isc2.org/notice/CISSP-Exam-Length or contact our Exam Administration team at examadministration@isc2.org. 

The post Changes to the CISSP Exam Length Coming Soon appeared first on Cybersecurity Insiders.


April 03, 2022 at 09:09PM

Dispersive Holdings Announces Version 4.3 Network Fabric, Showcasing New User Experience

ROSWELL, Ga.–(BUSINESS WIRE)–Dispersive Holdings, Inc. (Dispersive), an emerging cybersecurity leader in the Zero Trust and Secure Access Service Edge (SASE) space, announced general availability of version 4.3 of its converged cloud-native network fabric. Dispersive’s patented battlefield-inspired technology helps enterprises and governments establish active-active multipath VPN connections that are ultra-secure, and highly performant. Dispersive enables highly available mesh connectivity across any user, IoT device, location, or cloud infrastructure that is simple to setup and easy to operate.

The 4.3 release includes a new client with added features for Windows computers, Apple devices and Android smartphones that enhance user experience and productivity. Speed improvements come hand-in-hand with an intuitive look and feel that will simplify life for both end users and network administrators. The web and API-based provisioning tools for the DispersiveCloud™ SaaS offering have been completely re-architected to enable better management that is easier, comprehensive and more granular.

“Customers are struggling with single point security solutions as part of their journey to cloud and looking for a partner-led infrastructure solution that can address a variety of needs,” said Justin Knight, Head of PliantCloud™, MSP and Cloud Services Division of Alliance Technology Group, a North American Systems Integrator & IT Solutions/Services company specializing in IT infrastructure, physical & cyber security, storage, systems and networking. “Dispersive’s multipath VPN network fabric can enable site-to-site and secure remote access, as well as cloud back-up and recovery use cases. Their zero-touch provisioning approach can enable rapid time-to-value by reducing deployment times and effort.”

“With our relentless focus on delighting the customer and user productivity, we believe this release will be a game changer for both Dispersive partners and customers,” said Rajiv Pimplaskar, President and CEO, Dispersive. “Our MSP, SI and VAR partners can quickly onboard new customers, be agile and scale their business and market operations faster.”

Dispersive 4.3 will be generally available to governments, enterprises and Dispersive partners in May 2022.

About Dispersive Holdings

An emerging cybersecurity leader in the Zero Trust space, Dispersive delivers the Secure Access Service Edge (SASE) vision with a converged cloud-native network fabric that is ultra-secure, operationally flexible, and up to 10 times faster. Dispersive’s battlefield-inspired patented technology creates virtual active-active multipath networks with rolling encryption keys and granular access controls to connect digital businesses, products, and users across any infrastructure or service edge. Government, enterprises, and channel partners can implement the solution quickly with zero touch provisioning even across multi-cloud environments to secure against new and emerging threats, including nation state actors. For more information, visit www.dispersive.io or follow on LinkedIn @Dispersive

The post Dispersive Holdings Announces Version 4.3 Network Fabric, Showcasing New User Experience appeared first on Cybersecurity Insiders.


April 03, 2022 at 09:09PM

Saturday, April 2, 2022

Tips from a CISO: How to Create a Security Program

By Marco Túlio Moraes, CISSP, Director of Information Security, CISO at OITI. Marco is an executive with +20 years of experience in technology, risks and infosec, with 10 years of international experience. He has a multi-industry background in financial, tech, health, retail/marketplace, startups and utilities. Marco developed one of the first cybersecurity programs in Brazil and works as a career mentor, speaker, security evangelist and board advisor.

TIPS FROM A CISODeveloping a security program sometimes feels like trying to solve a 3,000 piece jigsaw puzzle while some people are trying to disturb your focus and the clock is ticking. To make the challenge harder, the big picture you are trying to mirror is constantly evolving.

The common challenges of the CISO go far beyond applying subject matter expertise and require us to apply leadership, strategy, and communication skills to guide the organizational culture and promote business prosperity. Understanding the business, managing stakeholders' expectations, and setting the same risk awareness level across the company are just some examples of the challenges that a CISO needs to address. On the SME role, we usually start with risk assessments and gap analysis, followed by a formal cybersecurity program plan.

No matter how much effort we apply to create the plan, there is always a moment when you realize that the big picture you were mirroring no longer brings value to the business. Mergers and acquisitions, new competition, new applications of tech, and internal business strategy changes disrupt the business landscape, and thus, plans must be adaptive and sustainable. On top of the changing business landscape, new cyber incidents, emerging high risks, new regulation due dates, or global events, like COVID-19, give way to a changing security program.

How to Develop a Sustainable and Adaptable Security Program?

The first thing is to set up the right foundational pillars. Since we know that changes are a constant in the CISO ecosystem, we should consider it a part of the game plan and set strategies to help detect and respond as early as possible. I propose that security executives focus their strategies on some specific perspectives:

1. Business awareness

Understand the business should not be a one-shot activity but a constant in the CISO job. Understanding business goals, products, services, challenges, and strategies help the security team do their traditional tasks while supporting business objectives. However, it should also allow the CISO to position themselves as a part of the business, enabling the organization to assess risk and make smart decisions based on the business and cybersecurity landscape.

2. Strategic positioning

Understanding the kind of value the information security program can provide to the business is essential for the buy-in and support of your program. Given the digital business transformation movement, cyber and information security are now starting to be seen as essential business components, which helps the CISO go far beyond sustaining and protection roles, to that of a business developer and enabler. Achieving this maturity level requires that the CISO maintain a strategic mindset.

3. Engagement

The security program should not be a one-person challenge. The department should engage everyone who can contribute to disseminating the security culture across the organization. Defining the strategy together with key stakeholders and leading the business to some of these initiatives helps create buy-in and program effectiveness, besides framing the risk ownership and accountability culture.

4. Build a strong team

Having a challenged, passionate, and skilled team will help the organization drive any technical changes that should be addressed while keeping stakeholders and the entire organization connected to the reviewed strategy. A team with guidance, autonomy, and constant feedback is an essential pillar to the success of the security program on both technical expertise and leading, influencing, and proposing changes to the company. A strong team also represents the needed technical know-how the organization will have to better manage risks.

5. Communication

Leading a security program is much more than defining the right tools, processes, and governance to achieve a specific goal. It is guiding an organizational culture on security aspects. Many times it is to transform a company’s mindset and lead organizational changes. Communication is the key link between giving the right message and listening to what is being communicated. Changes take time and require continued interactions to make them sustainable.

Moving the information security discipline beyond the purely technical perspective to be a part of the business demands that CISOs wear multiple hats. This means that mitigating risk will not be the only option and, at the end of the day, the security department should be working not as a company guardian but as an important business unit that is resilient and adaptable to change. This way, whatever happens in the business or the risk landscape, security will continue to play their part in enabling business.

The post Tips from a CISO: How to Create a Security Program appeared first on Cybersecurity Insiders.


April 03, 2022 at 09:08AM

Meet the Young Women Tackling Gender Bias in Cybersecurity

Screen Shot 2022-03-16 at 3.32.07 PMTo celebrate Women’s History Month in March, four female security leaders met for a wide-ranging panel discussion on how they’ve broken through gender biases to forge their career paths, as well as what’s needed to help young women in the cybersecurity profession succeed. This (ISC)² Think Tank webinar is part of the organization’s multi-year commitment to DEI which includes a new DEI series featuring diverse voices and perspectives within cyber and aimed at helping to build a more inclusive cyber profession.

The panel was moderated by Sharon Smith, CISSP, cybersecurity strategy and advisory consultant, and included:

  • Ebony Stevens, (ISC)² Security Engineer
  • Weijia Yan, an InfoSec student at Carnegie Mellon University
  • Megan West, X-Force Cybersecurity Incident Response Consultant at IBM

Each panelist is at a different phase in her career. Yan is currently studying cybersecurity and hoping to pursue a career after she graduates, while Smith has more than 15 years’ experience working in security, and Stevens and West are young women relatively new to the industry. That said, they shared a number of common experiences and strategies on how women can continue to advance.

You Still Need To Prove Them Wrong

Smith kicked off the panel by noting that it was time to celebrate the extraordinary growth of women in the industry, and that while she evolved into her cyber career, she was pleased to see younger women pursuing cybersecurity “on purpose.”

“When I first started my career in security, I never had to wait in line for the bathroom at tradeshows and was pleasantly surprised by that change on my last business trip,” Smith added. “That said, even with 700,000 people added to the security industry in 2020, there’s still a long way to go. Women and people of color continue to be underrepresented.”

West pursued a graduate degree in cybersecurity, and when she started her first job, she was the only woman on a Fortune 100 global security team of about 40 people. She was still the only woman when she left four years later.

“In my first cybersecurity role, a coworker told me that the only reason I was hired is because ‘they’ needed a female on the team. He was insinuating that I was a diversity hire, and not hired because of my potential, ability and skill sets,” she said. “I was much younger and this was an older person I looked up to. But I took it as a challenge and let it light a fire underneath me.”

Smith noted that it’s extremely important to keep a “prove you wrong” attitude while asking Stevens about her own journey into cybersecurity. Stevens had been finishing up her undergraduate degree when one of her professors suggested that if she took the PMP exam, it would help secure her a cozy and well-paid career in Governance, Risk and Compliance (GRC).

“I realized, though, that I really want to be an engineer and do technical work,” Stevens said. “As a small act of rebellion, I didn’t take the PMP exam. I’ve been pursuing certifications.”

Yan had to push back against her own family to pursue her education in cybersecurity. Her parents wanted her to pursue Law because they felt it was more stable.

“I wanted a career in cybersecurity, and I wanted to prove to my mom that I could do it,” she said. “I took the Security+ certification exam and after 30 days of grinding and studying, when I showed it to my mom, she was able to see my potential, determination and passion for cybersecurity. I’m very fortunate to now have my family’s support.”

Pedigree is Great When You Have It, But You Probably Already Have Cybersecurity Skills

All the panelists highlighted the industry’s ongoing issue with job titles and stressed the importance of being able to communicate how a nontraditional background can translate into cybersecurity.

“There is a huge disconnect between hiring managers and HR and cybersecurity job descriptions,” said West. “People look at these and get intimidated by them because they don’t meet all the qualifications. Apply anyway. The worst thing that can happen is that they don’t get back to you. The best thing to happen is that someone takes a chance, and you can speak effectively about why you are a good fit for that role. Being a great communicator is half the battle. Being able to explain to the hiring person what you can bring to the table and how you plan to achieve the qualifications is much more impressive.”

“We feel like we have to check every box,” added Smith. “But you can be creative about how you get in front of people.”

Create Your Own Space and Pull Up Your Chair

Each panelist stressed the importance of tackling imposter syndrome and creating opportunities for yourself. Yan watched a video on ethical hacking in middle school and fell in love with cybersecurity. During her undergraduate work, she founded the Texas A&M chapter of Women in Cybersecurity, driving membership growth from three to more than 30 annually and is looking to replicate her success at Carnegie Mellon.

West, who is known online as Cybersecurity Meg, created her social media presence, after studying for her CISSP exam and desiring content “taught by people that looked like me or had backgrounds similar to me.”

West also created her own job description after she realized that she was handling 95% of incident response for a global Fortune 100 company without the appropriate title and pay. She went to her management with data that demonstrated the work she was doing, the improvement to the company’s bottom line and similar roles at other companies.

“It’s so cliche, but that phrase ‘if there’s no chair for you at the table, pull yourself up’ works,” she said. “You don’t need to wait for someone to make an opportunity for you.”

Smith reiterated the need for self-advocacy, while Stevens highlighted how saying ‘no’ can help lead to career success and offers a platform for dictating what work you can and want to do.

Mentor The Next Up and Comers

All of the panelists highlighted the importance of mentorship, but many pointed out that this doesn’t necessarily mean having a formal training program. West suggested seeking out people you look up to, and Stevens noted that informal, fluid conversations allow you to “make mistakes in a more graceful manner. You’re being taught something, but you also work through the problem conversationally.”

Smith added that women should be proactive about reaching out to people they admire, and that “success leaves clues. Look at what other successful people have done and replicate it.”

Yan mentioned that she has relied on conferences to connect with InfoSec experts, and that she is looking to repeat this.

“It brings me joy to connect people. When they come together, it makes me feel better,” she said. “My mentors did a lot for me and I wanted to pass it along.”

The session ended with each panelist reiterating that diverse teams help organizations look at problems from different perspectives, and they are what is needed to tackle today’s complex cybersecurity issues.

The post Meet the Young Women Tackling Gender Bias in Cybersecurity appeared first on Cybersecurity Insiders.


April 02, 2022 at 09:08PM

Friday, April 1, 2022

GOING FOR (ISC)² CERTIFICATION? GET THE FACTS BEFORE YOU CHOOSE A TRAINING PROVIDER

CISSP-CCSP_FactsWhen it comes to deciding on a training provider for CISSP and CCSP exam prep, it can be difficult to separate myth from reality as you research your options. World-class (ISC)² certifications like CISSP and CCSP are highly regarded in cybersecurity, and countless companies offer training. But not all course providers are equally qualified to get you ready for exam day.

Knowledge is power when it comes to choosing the right training. Too many companies put out false claims to win your business. Don’t believe the hype! They may promise high pass rates, for example — but the fact is, no one knows the exact questions on the exam, and no company can guarantee a pass rate.

To help you make an informed decision, let’s look at more training myths out there — and bust them! Read more.

The post GOING FOR (ISC)² CERTIFICATION? GET THE FACTS BEFORE YOU CHOOSE A TRAINING PROVIDER appeared first on Cybersecurity Insiders.


April 02, 2022 at 09:08AM

SentinelOne Leads MITRE Engenuity ATT&CK® with 100% Prevention, Detection, and Highest Scores

MOUNTAIN VIEW, Calif.–(BUSINESS WIRE)–SentinelOne (NYSE: S), an autonomous cybersecurity platform company, released its results from the fourth round of MITRE Engenuity ATT&CK® evaluations. SentinelOne is the only vendor to score highest among analytic detections for three consecutive years. Out of the 30 vendors evaluated, SentinelOne’s Singularity XDR achieved 100% prevention, 100% detection, the highest analytic coverage (108/109), and zero detection delays, demonstrating the platform’s ability to autonomously combat against the most sophisticated threat actors.

The fourth round of MITRE ATT&CK Evaluations evaluated vendors’ ability to protect against advanced attack techniques including Wizard Spider and Sandworm. Key MITRE evaluation results include:

  • 100% Prevention Across Operating Systems: Security teams demand technology that matches the rapid pace at which adversaries operate. SentinelOne Singularity XDR determines the precise moment when malicious activity occurs and takes autonomous action to stop and remediate threats, all without human intervention.
  • High-Quality Analytic Detections Create Context: There aren’t enough skilled cybersecurity professionals to combat the attack landscape alert by alert. SentinelOne Singularity XDR provides real-time correlation and context to minimize alert fatigue, empowering security analysts to turn data into stories, and stories into context.
  • Full Visibility with Zero Detection Delays: With a comprehensive view of the entire enterprise, SentinelOne Singularity XDR outperformed without any delayed detections, minimizing dwell time through automation.
  • Stand Out Simplicity: SentinelOne Singularity XDR summarized two days of testing into nine campaign level console alerts, showcasing the platform’s ability to correlate, contextualize, and alleviate SOC burdens with machine speed.

“Singularity XDR platform pushes the boundaries of autonomous technology to stop today’s most sophisticated cyber threats,” said Raj Rajamani, Chief Product Officer, SentinelOne. “Deploying solutions that keep enterprises one step ahead of attackers and address threats in real-time is critical for today’s threat landscape. Achieving 100% prevention, 100% detection, the highest analytic coverage, and zero detection delays in this year’s Wizard Spider and Sandworm MITRE assessment validates our ability to provide autonomous security across the enterprise.”

SentinelOne was one of the first endpoint companies to correlate alerts in-product with the MITRE ATT&CK framework, embrace the MITRE ATT&CK Endpoint Protection Product Evaluation, and incorporate the MITRE ATT&CK framework as the new threat hunting standard. As a leader across MITRE ATT&CK Evaluations for the third consecutive year, SentinelOne is committed to providing immediate and enriched threat context and visibility within the MITRE framework.

To learn more about SentinelOne’s results on the fourth round of MITRE Engenuity ATT&CK® evaluations, visit: https://www.sentinelone.com/lp/mitre/

About SentinelOne

SentinelOne’s cybersecurity solution encompasses AI-powered prevention, detection, response and hunting across endpoints, containers, cloud workloads, and IoT devices in a single autonomous platform.

The post SentinelOne Leads MITRE Engenuity ATT&CK® with 100% Prevention, Detection, and Highest Scores appeared first on Cybersecurity Insiders.


April 02, 2022 at 09:08AM