"NSA Jointly Releases Guidance for Mitigating Active Directory Compromises"

"NSA Jointly Releases Guidance for Mitigating Active Directory Compromises"

"The National Security Agency (NSA) joins the Australian Signals Directorate’s Australian Cyber Security Centre (ASD ACSC) and others in releasing the Cybersecurity Technical Report (CTR), 'Detecting and Mitigating Active Directory Compromises.' The guidance provides prevention and detection strategies for the most prevalent techniques used to target Active Directory (AD). Gaining control over AD gives malicious actors privileged access to all systems and users managed by AD, according to the CTR.

Submitted by Gregory Rigby on

"NIST Scraps Passwords Complexity and Mandatory Changes in New Guidelines"

"NIST Scraps Passwords Complexity and Mandatory Changes in New Guidelines"

According to new guidelines published by the National Institute of Standards and Technology (NIST), using a mixture of character types in your passwords and regularly changing passwords are officially no longer best password management practices.  NIST’s latest version of its Password Guidelines suggests credential service providers (CSPs) stop recommending passwords using several character types and to stop mandating periodic password changes unless the authenticator has been compromised.

Submitted by Adam Ekwall on

"Data Breach at MC2 Data Leaves 100 Million at Risk of Fraud"

"Data Breach at MC2 Data Leaves 100 Million at Risk of Fraud"

Security researchers at Cybernews have recently uncovered a massive data leak exposing the personal information of over 100 million US citizens.  The breach is attributed to a misconfigured database at background check firm MC2 Data, which allegedly left 2.2TB of sensitive data accessible online without password protection.

Submitted by Adam Ekwall on

"Police Are Probing a Cyberattack on Wi-Fi Networks at UK Train Stations"

"Police Are Probing a Cyberattack on Wi-Fi Networks at UK Train Stations"

U.K. transport officials and police recently announced they are investigating a “cybersecurity incident” that hit the public Wi-Fi networks at the country’s biggest railway stations.  Passengers trying to log onto the Wi-Fi at stations including Manchester Piccadilly, Birmingham New Street, and 11 London terminuses on Wednesday evening were met by a page reading “We love you, Europe,” followed by an anti-Islam message listing a series of terror attacks.  Network Rail, which manages the stations, said the Wi-Fi had been switched off and no passenger data was taken.

Submitted by Adam Ekwall on

"Google Sees Drop in Memory Safety Bugs in Android as Code Matures"

"Google Sees Drop in Memory Safety Bugs in Android as Code Matures"

Google recently announced that its secure-by-design approach to code development has significantly reduced memory safety vulnerabilities in Android.  Google has been battling memory safety issues in both Android and Chrome for years, including by migrating them to memory-safe programming languages, such as Rust, and the effort has paid off.

Submitted by Adam Ekwall on

"AI Can Now Bypass CAPTCHA, and That's a Serious Problem for Online Security"

"AI Can Now Bypass CAPTCHA, and That's a Serious Problem for Online Security"

Researchers from ETH Zurich have discovered a way to beat CAPTCHA puzzles through the use of Artificial Intelligence (AI), which has sparked further concern regarding online security. CAPTCHA, which stands for "Completely Automated Public Turing Test to Tell Computers and Humans Apart," has been a well-established method for distinguishing humans from bots. However, the researchers' new AI system could solve image-based puzzles as effectively as humans, if not better. This article continues to discuss the study "Breaking reCAPTCHAv2."

Submitted by Gregory Rigby on

"Cyber Shields Up! - Research on Network Intrusion Detection Model That Integrates WGAN-GP Algorithm and Stacking Learning Module"

"Cyber Shields Up! - Research on Network Intrusion Detection Model That Integrates WGAN-GP Algorithm and Stacking Learning Module"

Xiaoli Zhou of the School of Information Engineering at Sichuan Top IT Vocational Institute in Chengdu, China, conducted a study on integrating data augmentation and ensemble learning methods to improve the accuracy of Intrusion Detection Systems (IDS). Zhou focused on a Wasserstein Generative Adversarial Network with Gradient Penalty (WGAN-GP), an advanced version of the standard Machine Learning (ML) model capable of creating realistic data through a competition between two neural networks.

Submitted by Gregory Rigby on

Cyber Scene - Up In the Air

Cyber Scene - Up In the Air

By krahal

With a nod to Charles Dickens, this Cyber Scene will take us to the tale of two grounded US cities—Washington DC and New York City, even as debates, be they financial or foreign affairs, are fully in best or possibly worst ethereal times.

Submitted by Gregory Rigby on
Subscribe to