FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Sunday, October 27, 2019

The Four Pillars of CASB: Visibility

This post was originally published by Juan Lugo.

Due to the potential for data leakage in the cloud, the use of CASBs (cloud access security brokers) is needed in order to maintain visibility over data that has gone beyond the reach of on-premises tools. Bitglass enables organizations to monitor cloud applications through one portal which offers complete oversight on all activities as well as thorough analytics.

Read more here: https://www.bitglass.com/blog/four-pillars-casb-visibility 

The post The Four Pillars of CASB: Visibility appeared first on Cybersecurity Insiders.


October 27, 2019 at 06:29PM

PCI COMPLIANCE IN AWS – SIMPLIFIED

This post was originally published by (ISC)² Management.

Payment Card Industry Data Security Standards or PCI DSS, are a set of 12 requirements with over 300 controls which apply to any organization which stores, processes or transmits credit card data. Today, I will attempt to add some clarity around PCI compliance within AWS

Read more here: https://blog.isc2.org/isc2_blog/2019/10/pci-compliance-in-aws-simplified.html

The post PCI COMPLIANCE IN AWS – SIMPLIFIED appeared first on Cybersecurity Insiders.


October 27, 2019 at 06:17PM

FILLING THE NEED OF HEALTHCARE CYBERSECURITY PROFESSIONALS REQUIRES COLLABORATION

This post was originally published by (ISC)² Management.

It is widely known within the cybersecurity field that there is a severe talent shortage. Organizations across all industries are facing major challenges in staffing their security teams to protect themselves from cyber threats. Healthcare, along with finance and retail, is one of the most commonly-targeted industries by cybercriminals.

Read more here: https://blog.isc2.org/isc2_blog/2019/10/filling-the-need-of-healthcare-cybersecurity-professionals-requires-collaboration.html

Photo:https://ift.tt/1eK4mQm

The post FILLING THE NEED OF HEALTHCARE CYBERSECURITY PROFESSIONALS REQUIRES COLLABORATION appeared first on Cybersecurity Insiders.


October 27, 2019 at 06:11PM

Friday, October 25, 2019

Reviewing best practices for IT asset management in the cloud

It used to be that businesses needing their own large computer networks had to do everything themselves. They had to buy all of their servers, all of their networking appliances. They needed the physical space on premises for all of their datacenters, the HVAC people to keep everything cool, and the massive electricity bills to keep all of that going.
But in the past several years, the growth of cloud services has been exponential. It’s great for the enterprise because depending on a business’s specific needs, they can either have everything but their local area network on the cloud, or they can have some hybrid of their own on premises network and a cloud provider or two, fully integrated. Either way, they can put at least some of their networking needs in the hands of a cloud provider such as AWS, Microsoft Azure, or Google Cloud….

Kim Crawley Posted by:

Kim Crawley

Read full post

      

The post Reviewing best practices for IT asset management in the cloud appeared first on Cybersecurity Insiders.


October 26, 2019 at 09:09AM

Get ready for a Cyber Cold War in 2020

A recent study made by Cybersecurity firm Checkpoint says that the year 2020 will witness a cyber cold war between the countries of the west and the east. This indicates that adversary nations of the United States such as Russia and China will form a coalition to develop technologies to show their valiance in the online world.

At the same time, the Israel based company predicted that the spread of Fake News will increase before the US 2020 elections which might be propelled by intelligence agencies of Russia and China. The software solutions provider says that foreign nations will try their best to influence the 2020 elections by using sophisticated technologies such as Artificial Intelligence.

Furthermore, utilities will be severely targeted before the elections say the researchers of Checkpoint as adversary nations will try to cause damage to the populace by disrupting power services and water distribution infrastructure.

On an additional note, Checkpoint’s technical team has predicted that the year 2020 will witness the following predictions related to cybersecurity. And they are -an increase in targeted ransomware attacks where healthcare, government, and educational institutes will be the main targets. At the same time, the company has emphasized the latest security measures which the FBI issued shortly and the law enforcement agency clearly states that in some cases, businesses should evaluate the options to protect their shareholders, employees, and customers and might find out ways to deal will ransomware attacks.

Also, the endpoint-security services offering firm predicts that phishing attacks will go beyond email to trick innocent mobile users to click on malicious links.

The post Get ready for a Cyber Cold War in 2020 appeared first on Cybersecurity Insiders.


October 25, 2019 at 09:09PM

Thursday, October 24, 2019

Mobile Security vulnerabilities found in World’s most popular travel apps

Zimperium which is a specialist in providing Mobile Security solutions has discovered in its latest survey that 100% of applications running on the Apple iOS store and 45% running on the Android-based play store failed to receive the pass marks for keeping their user data private. This includes almost all popular travel apps in the world.

Although the company did not disclose the names of the travel apps for reasons, it did mention in its report that the apps were the Top 30 ones which were ranking high with user downloads and on user reviews.

Thus, if one wishes to find out the names, then they can just type in “ top 30” travel apps on Google search and match the terms disclosed by Zimperium meeting data privacy and security standards.

Despite all the marketing trumpeting, researchers from Zimperium claim that the apps failed to perform when the industry’s benchmark for privacy was considered. What’s surprising in the find is that even iOS apps failed to pass the privacy test – despite Apple claiming that it’s a privacy-first company in America and across the world.

For instance, over 97% of Android-based apps and 73% of iOS apps were allowing developers and third parties to take screenshots of the full UI of the app, which makes them view data related to other apps downloaded on the phone. What’s more concerning is that 73% of apps from the find were also able to implement pinpoint location functionality, which allows location transmit of app users to ad companies.

The research made by the mobile security firm claims that more than 10% of apps access the call history of a user, and sometimes even contact lists.

Therefore, the research made by the mobile security firm confirms that developers and also companies offering app ecosystems have made little or no progress with security and privacy issues.

So, the next time when you click on a banner of a big travel company claiming to offer you’re a holiday season deal, you better keep a watch on the info you are providing- as privacy fears increased when big companies like Starwood Hotels, British Airways, and Air Canada were caught up in privacy and security related data scandals.

The post Mobile Security vulnerabilities found in World’s most popular travel apps appeared first on Cybersecurity Insiders.


October 25, 2019 at 11:04AM

City of Johannesburg and Elgin County hit by Ransomware Attacks

City of Johannesburg, a metropolitan in South Africa is said to be reigning under a cyber-attack were hackers have induced a malware into the network impacting websites, and all e-services & billing systems related to the city.

News is out that the hackers are demanding 4.0 bitcoins to be paid by Oct 28th of this year, otherwise, they are said to dump the encrypted data onto the dark web which might deteriorate the situation for the citizens by creating a compromise to their data privacy.

A hacker group dubbed as “Shadow Kill Hackers” is said to be behind the incident.

An initial probe by the law enforcement has revealed that the same group was also behind the DDoS cyber-attack which took place on several banks (like Absa and Standard Bank) early this week- giving us a thought that it was a highly coordinated cyber attack equipped with sophistication and launched by an adversary nation.

Disclosing the same via an official twitter handle, the city of Johannesburg authorities have urged the customers not to take make any transactions for the next few weeks on e-services.

In other incidents related to a ransomware cyberattack, Elgin County Police have issued a security warning to businesses operating across the region that some hacking groups where intending to encrypt their databases via malicious means.

The Elgin County OPP based on Ontario says that already a business or two were infected by the file-encrypting malware disrupting the operations for the past few days.

As the cybercrime unit of the Ontario Provisional Police (OPP) was investigating the malware incident, they issued a warning out of precaution.

The post City of Johannesburg and Elgin County hit by Ransomware Attacks appeared first on Cybersecurity Insiders.


October 25, 2019 at 11:01AM