This week, in the security market, we talk about next NEXT gen anti-virus, how Okta can (apparently) do no wrong, and a VC firm imploding. Then we discuss how smartphones and speakers are allegedly being used to spy on us, and the future of privacy and consumer tech products. The latest SSH vuln is much less concerning than media outlets and academ...
Firmware security is a deeply technical topic that's hard to get started in. In this episode of Below the Surface, Xeno will discuss some past work in firmware security, and how he has organized resources such as a low level timeline (with over 300 talks), and free MOOC classes, to help teach people about firmware security. Segment Resources: https...
Older defensive security technologies often fail to protect endpoints because of their limited ability to change as attacks change. What’s needed is a way for endpoint security defenses to adapt to evolving attack techniques. That’s where context-sensitive endpoint defense comes into play.
CyberScoop reports that tech manufacturers have been urged by the Cybersecurity and Infrastructure Security Agency to remove default passwords from their software and devices following the widespread exploitation of Unitronics' programmable logic controllers that impacted water utilities across the U.S. "Studies by CISA show that the use of default credentials, such as passwords, is a top weakness that threat actors exploit to gain access to systems, including those within U.S. critical infrastructure," said CISA.
The Chinese threat group used the newly discovered KV-botnet, made up of compromised SOHO devices, as a stealth data transfer network during attacks on U.S. and Asian targets.
Hundreds of outdated Fortinet, Cisco, and Netgear small office home office routers, some of which were in high-value networks, have been leveraged by Chinese advanced persistent threat operation Volt Typhoon to form the sophisticated KV-botnet and establish a covert data transfer network, reports SecurityWeek.