-
Intrusion Prevention Systems fail to spot AET attacks, University study finds
Many big-brand Intrusion Prevention Systems (IPS) consistently fail to block attacks that target vulnerabilities in web-based applications using Advanced Evasion Techniques (AETs), a University of Glamorgan study has found.
-
US government's use of deep packet inspection raises serious privacy questions
To protect the federal civilian agencies against cyberthreats, the Department of Homeland Security (DHS) is preparing to deploy a more powerful version of its EINSTEIN intrusion-detection system that?s supposed to detect attacks and malware, especially associated with e-mail. But since this version of EINSTEIN is acknowledged by DHS to be able to read electronic content, it?s raising privacy concerns.
-
South Korean cyberattacks used hijacked patch management accounts
The attackers who unleashed devastating hard-drive wiping malware on South Korean TV stations and banks earlier this week executed at least part of the attack by hijacking the firms' patch management admin accounts, the software vendor involved has said.
-
Phishing sites use whitelisting to keep out unwanted victims
Businesses increasingly use whitelisting to keep the bad guys out but now it turns out that criminals are employing the same tactics to target favoured victims, security firm RSA has reported.
-
Failure to detect abuse allows cloud computing instances to be used like botnets
Some cloud providers fail to detect and block malicious traffic originating from their networks, which provides cybercriminals with an opportunity to launch attacks in a botnet-like fashion, according to a report from Australian security consultancy firm Stratsec.
-
Georgia publishes photos of alleged Russia-based cyberspy
The country of Georgia has published two photos of a Russia-based hacker who, the Georgians allege, waged a persistent, months-long campaign that stole confidential information from Georgian government ministries, parliament, banks and NGOs.
-
Botnet masters hide C&C server inside Tor network
Security researchers from German antivirus vendor G Data Software have identified a botnet that is controlled by attackers from an Internet Relay Chat (IRC) server running as a hidden service inside the Tor anonymity network.
-
Chinese official says Samsung and Apple 'lack human care' at factories
Apple and Samsung are lacking in "human care" in their treatment of workers, a Chinese official said as he weighed in on the controversy surrounding working conditions at Chinese suppliers of the tech giants.
-
Hackers steal names and emails from 400 Sony mobile customers in China
Hackers accessed about 400 names and email addresses of Sony mobile customers in China and Taiwan, but the electronics giant insists that no credit card or banking information was compromised.
-
FinFisher spyware found running on computers all over the world
Corporate IT should monitor systems for signs of communication with command and control servers running FinFisher, as it can record Skype and other VOIP, as well as log keystrokes, steal files and bypass antivirus systems.






