News
  • "Researchers Trick Facial Recognition Systems"
    McAfee researchers were able to trick a facial recognition system into misclassifying one person as another person using Generative Adversarial Networks (GANs). GANs are neural networks that can create data similar to the data it is fed. In the study,…
  • "Security Gap Allows Eavesdropping on Mobile Phone Calls"
    Researchers from the Horst Gortz Institute for IT Security (HGI) at Ruhr-Universitat Bochum have shown that it is possible to decrypt the contents of telephone calls made via the LTE mobile network, 4G, which are supposed to be tap-proof. The decryption…
  • "Organizations Knowingly Ship Vulnerable Code Despite Using AppSec tools"
    Researchers at Veracode, while conducting a survey, found that nearly half of organizations regularly and knowingly ship vulnerable code despite using AppSec tools.  Among the top reasons cited by the organizations for pushing vulnerable code, were…
  • "Using Automated Security Protocols Reduce the Cost of Data Breaches, Report Says"
    According to IBM's annual "Cost of a Data Breach" report released in July,  the average losses incurred by the public sector worldwide per data breach is the lowest average cost compared to 17 other industries. Researchers examined the costs of data…
  • "How the International Space Station Enables Cybersecurity"
    Former NASA astronaut Pamela Melroy gave a presentation at the Aerospace Village within the DEFCON virtual security conference. She discussed cybersecurity lessons learned from human spaceflight and what cyber risks are faced by the International Space…
  • "Hackers Exploit Covid-19 Vaccine Interest As Cover For Attacks"
    Researchers at Check Point discovered that phishing emails with subject lines related to COVID-19 vaccines are now being used to trick recipients into downloading malicious files typically in file type forms of .exe, .xls, or .doc.  The researchers…
  • "Why Organizations Push Vulnerable Code in Their Application Security Program"
    A new report from Synopsys, titled "Modern Application Development Security," reveals that 48% of organizations intentionally push vulnerable code in their application security programs. According to the report, organizations push vulnerable code because…
  • "Securing Human Resources From Cyber Attack"
    CISOs need to make protecting HR data a high priority during the Covid-19 pandemic.  Since most employees are working from home, companies are even more susceptible to data breaches.  If compromised, the data stored by HR can do a devastating…
  • "Baking and Boiling Botnets Could Drive Energy Market Swings and Damage"
    A study conducted by researchers at the Georgia Institute of Technology suggests that botnets made up of electric ovens, hot-water heaters, electric vehicle chargers, air-conditioners, and other internet-connected high-wattage appliances, could be used…
  • "Researchers Find More Devices, Vendors Vulnerable to Ripple20"
    In June, JSOF researchers disclosed a set of 19 vulnerabilities, dubbed "Ripple20," that affect millions of connected devices, including those used in the healthcare industry. These vulnerabilities were found in Treck's widely adopted low-level TCP/IP…
  • "Qualcomm Bugs Open 40 Percent of Android Handsets to Attack"
    Researchers have found six serious bugs in Qualcomm’s Snapdragon mobile chipset.  The six bugs impact up to 40 percent of Android phones in use.  The flaws open up handsets made by Google, Samsung, LG, Xiaomi, and OnePlus to DoS and escalation-…
  • "Over 30 Vulnerabilities Discovered Across 20 CMS Products"
    Researchers from Micro Focus Fortify have discovered more than 30 vulnerabilities in Microsoft SharePoint, Atlassian Confluence, and 18 other popular Content Management Systems (CMSs). CMSs enable the creation and modification of digital content for web…