Why Most Companies Don’t Have Control Over Password Security

Why Most Companies Don’t Have Control Over Password Security

Many people have developed a psychological picture of what a cyber-attack consists of. There’s a tendency to assume a complex, thrilling attack is executed by highly-technical individuals who have penetrated a network to access ironclad sensitive data. The reality, however, is much different.

Read More

The Newest Type of Phishing Attack: Cloud-Based Documents

The Newest Type of Phishing Attack: Cloud-Based Documents

Phishing has become a well-known term, even showing up in prime-time commercials and rolling off the tongue of tech-savvy, scam-weary seniors. Despite the widespread awareness of phone, email, and even in-person phishing scams, new and creative attacks remain the bane of security staff. The latest phishing threat gaining traction? Cloud-based documents.

Read More

IoT, Medical Devices, and Cybersecurity Concerns

IoT, Medical Devices, and Cybersecurity Concerns

Not so long ago, medical devices required only physical security considerations—only those who had access to the device could access the device’s data. However, through the Internet of Things (IoT), medical devices’ connectivity to the cloud has put them in the cross-hairs of cyber attackers.

Read More

A Look Inside the Cybercrime-as-a-Service Industry

A Look Inside the Cybercrime-as-a-Service Industry

There’s a skills-gap and specialist shortage in the cybercrime industry. You read that correctly. Cybercriminals are looking for new recruits to fill positions in the rapidly growing cybercrime as a service (CaaS) industry. Although it sounds like something out of a low-budget science fiction flick, CaaS is very real and thriving.

Read More

Selling a Social Engineering Attack

Selling a Social Engineering Attack

Social engineering techniques are not only becoming more common but also more sophisticated. Attackers seem to be taking notes from Marketing 101, ensuring that their lures strike a chord with their victims with emails that include customized messages with very official looking logos and layouts, fraudulent phone calls that cite actual employee names and titles, and even well-rehearsed seemingly innocuous facility access attempts.

Read More

SSL Configuration Best Practices Part 2: Server Certificates

SSL Configuration Best Practices Part 2: Server Certificates

Secure Sockets Layer (SSL) configuration is a critical component of defending publicly accessible web applications against man-in-the-middle and other attacks. This second of a three-part series on SSL configuration best practices explores SSL server certificate best practices.

Read More