Showing posts with label Javvad Malik. Show all posts
Showing posts with label Javvad Malik. Show all posts

Wednesday, February 28, 2018

The user awareness landscape

Overall, technologies can be pretty straightforward to secure. Teach software not to execute a certain command, block a port, or alert on a set of conditions, and it will abide. Humans, on the other hand are not as easy to harden against attacks. These attacks are frequently delivered through emails, text messages, social media, or […]

The post The user awareness landscape appeared first on Security Boulevard.



from The user awareness landscape

Wednesday, January 31, 2018

What is AlienVault

It’s coming up on my 3 year anniversary at AlienVault – and after a conversation with a friend, it dawned on me that I don’t think I’ve ever really explained what AlienVault does. So, when I was in Austin this last week I recruited some of my colleagues to help make this short video to […]

The post What is AlienVault appeared first on Security Boulevard.



from What is AlienVault

Thursday, January 11, 2018

Carphone Warehouse fined

via IFTTT After its 2015 breach, the Information Commissions Office (ICO) has released a very thorough report which highlights a number of deficiencies in Carphone Warehouse’s security. I’ve summed up some of the key points in dramatic fashion The report well worth a read: http://ift.tt/2AM6B7B

The post Carphone Warehouse fined appeared first on Security Boulevard.



from Carphone Warehouse fined

Friday, January 5, 2018

Exploiting browser password logins

The cool researchers over at freedom to tinker found two scripts that exploit browsers built in login managers to retrieve and exfiltrate ID’s. Below is the email I sent, and the reply from OnAudience     The script that OnAudience uses can be found here if you have time, check out this tweet thread between […]

The post Exploiting browser password logins appeared first on Security Boulevard.



from Exploiting browser password logins

Threatcare secures $1.4m seed funding

Threatcare has announced a $1.4m seed round led by Moonshots Capital and includes Flyover Capital and Firebrand Ventures. The Austin-based company was founded in 2014 by CEO Marcus Carey. Its flagship product, Violet, is a SaaS-based offering that enables continuous security validation through attack simulations. For many security departments, the question they are often faced […]

The post Threatcare secures $1.4m seed funding appeared first on Security Boulevard.



from Threatcare secures $1.4m seed funding

Tuesday, January 2, 2018

Welcome to 2018

via IFTTT I thought I’d kick off the new year by poking around the news stories, surely not much could have happened. But quite a lot did unfortunately. In the video are the top 3 stories or headlines that caught my attention, but more importantly, I think we should make a pact to stop using […]

The post Welcome to 2018 appeared first on Security Boulevard.



from Welcome to 2018

Tuesday, December 19, 2017

Thales splashes out $5.7bn for Gemalto

M&A in the infosec world has waited for the holiday season to go all out splashing its cash. A flurry of activity has occurred at the tail end of the year with considerable consolidation. Proving that encryption and identity management is no slouch, Thales has made an eye-watering bid of $5.7bn to acquire Gemalto, a […]

The post Thales splashes out $5.7bn for Gemalto appeared first on Security Boulevard.



from Thales splashes out $5.7bn for Gemalto

Monday, December 18, 2017

A tale of two public companies

Infosec companies don’t always get the love they deserve from the markets once they IPO. As Barracuda Networks discovered despite posting respectable profitable growth. PE firm Thoma Bravo stepped in, paying $27.55 per share for Barracuda in a $1.6bn move taking it private. The market can be unforgiving, even when a company like Barracuda is […]

The post A tale of two public companies appeared first on Security Boulevard.



from A tale of two public companies

Wednesday, December 13, 2017

Infosecurity magazine Look back over the year

Honoured to be the guest editor for Infosecurity Magazine yesterday. It was a day of fun which involved several things: 1. The announcement was made, which included this video 2. I took over their twitter account for an hour (brave of them) 3. I submitted a guest editorial 4. Had a Q&A with the real […]

The post Infosecurity magazine Look back over the year appeared first on Security Boulevard.



from Infosecurity magazine Look back over the year

Monday, December 4, 2017

The attitudes of credential sharing

My staff log onto my computer on my desk with my login everyday. Including interns on exchange programmes. For the officer on @BBCNews just now to claim that the computer on Greens desk was accessed and therefore it was Green is utterly preposterous !! — Nadine Dorries (@NadineDorries) December 2, 2017 This tweet by member […]

The post The attitudes of credential sharing appeared first on Security Boulevard.



from The attitudes of credential sharing

Friday, October 27, 2017

Bsides Lisbon and the car door

I’m truly honoured to have been invited to keynote at Bsides Lisbon this year on November 10th. It’ll be the first time I’ve visited Portugal, and the first time I’ve keynoted at a Bsides. Ordinarily I’d probably be feeling a bit apprehensive of speaking at a conference that I haven’t even attended, let alone keynote […]

The post Bsides Lisbon and the car door appeared first on Security Boulevard.



from Bsides Lisbon and the car door

Monday, September 4, 2017

Ransomware uses

via IFTTT Someone asked me if there are any unusual or legitimate uses for ransomware. If you break down what ransomware is, it’s just encryption. But it’s more like “surprise” encryption where someone else does the encryption, and keeps the key. So, I present five unorthodox ways to use ransomware in this video. However, if […]

from Ransomware uses

Sunday, July 30, 2017

Hacking Conference Shirts

T-shirts are among the most popular giveaways at security conferences. They’re great, practical, and serve as walking advertisements. But if you go to enough conferences, you’ll usually find yourself accumulating far too many shirts. There are only so many shirts you can use to wear when working out, or doing DIY projects, or as rags […]

from Hacking Conference Shirts

Tuesday, May 16, 2017

Making Sense of WannaCry

Whenever a calamity befalls, it’s only natural for people to try and rationalise and identify the problem. As is now happening with the WannaCry ransomware outbreak that affected the UK’s NHS service, and other services in over 100 countries. People are discussing what should have been done to prevent it. On one hand, there’s a […]

from Making Sense of WannaCry

Tuesday, April 18, 2017

BankBot malware targets Android Apps

On 17 April (Monday) the strain, dubbed “BankBot”, was discovered in an application called “HappyTimes Videos” on Google’s Play Store. In addition, experts from Securify, a Dutch cybersecurity firm, recently found another infected app there, titled “Funny Videos 2017”. The Trojan is able to pose as legitimate services, mostly banks and financial institutions. However, once […]

from BankBot malware targets Android Apps

Intercontinental Hotel Credit Card Breach

The Intercontinental Hotels Group (IHG) has been forced to reveal yet another major data breach of customer card details over the latter part of 2016. In a lengthy missive on Friday, the group explained that an unspecified number of IHG hotels run as franchises were affected between September 29 and December 29 last year. via […]

from Intercontinental Hotel Credit Card Breach

IoT Botnet rivalry

Like Mirai, Hajime also scans the internet for poorly secured IoT devices like cameras, DVRs, and routers. It compromises them by trying different username and password combinations and then transferring a malicious program. However, Hajime doesn’t take orders from a command-and-control server like Mirai-infected devices do. Instead, it communicates over a peer-to-peer network built off protocols […]

from IoT Botnet rivalry

Rise in Healthcare Breaches

A sharp spike in the number of health care data breaches was recorded in March with 39 incidents taking place compromising more than 1.5 million patient record. via 1.5 million records lost in March health care industry data breaches 1.5m records lost in March health care industry data breaches represents a rather unsettling trend. While […]

from Rise in Healthcare Breaches

Get your Ransomware source code

The ransomware is provided as a C++ source code, paired with the necessary PHP web server scripts and a payment panel. via CradleCore Ransomware Sold as Source Code | SecurityWeek.Com As if the world didn’t have enough troubles with vanilla ransomware. They went ahead and created ransomware as a service (RaaS). But now they’ve gone […]

from Get your Ransomware source code

Monday, April 17, 2017

When disclosure is responsible

What originally appeared to be one of the most damaging releases in recent memory of “zero-day” exploits, or hacking tools that take advantage of previously unknown software vulnerabilities, fell from the sky with the shrieking ferocity of a MOAB bomb and landed with the soft thud of a dud. via Microsoft’s Quiet Patch of Shadow […]

from When disclosure is responsible