Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Tuesday, December 24, 2019

Portshift syncs Kubernetes policies to container vulnerabilities in CI/CD pipelines for remediation

Portshift announces its new capability that delivers runtime policies for vulnerability remediation, allowing more secure workload communications. Portshift’s risk mitigation engine  connects Kubernetes network policies with discovered vulnerabilities in production workloads, allowing to mitigate the risk potential of vulnerable containers till its replacement with new version that remove the vulnerable component.


With Portshift, the company has taken DevSecOps to the next level with a platform that connects identified vulnerabilities with the identity of the workload, providing a measured balance that prevents workload communications based on the risk level and the potential threat to certain applications.


The technology has the ability to block traffic based on the vulnerability level discovered, providing a single picture for complete visualization of these processes during runtime. This provides protection that is matched to the DevOps applications in production.

According to a 2019 Gartner report, “Security can’t be an afterthought. It needs to be embedded in the DevOps process, which Gartner refers to as “DevSecOps…Integrate an image-scanning process to prevent vulnerabilities as part of an enterprise’s continuous integration/continuous delivery (CI/CD) process, where applications are scanned during the build and run phases of the software development life cycle.”


Portshift mitigates vulnerabilities with greater sophistication. Available as part of the company’s identity-based cloud native workload security and risk management platform, the technology ensures that Kubernetes environments are protected from development to runtime. With Portshift, app security is simplified and speeded-up by replacing multiple fragmented firewalls, security groups, and ACLs with automated identity-based workload security that is decoupled from the network infrastructure.


When unknown, and possibly malicious workloads are detected, they are quickly identified and rapidly removed using Portshift’s innovative DevOps security platform. The company’s workload management processes offer an alternative to the use of IP addresses, ports and firewalls to secure the network perimeter as it addresses the unique security requirements of cloud-native microservices running in containers both inside and outside of the network perimeter.


“With the availability of this identity-based approach, we are actively collaborating with industry leading vulnerability scanning providers including Twistlock, Aqua and Clair to move the industry forward,“ said Zohar Kaufman, co-founder and VP, R&D for Portshift. “Having Portshift’s information-rich view of containers in real time will be exceedingly important in 2020 as more determined hackers continue their efforts to attack earlier in the development process in order to exploit vulnerabilities before they are addressed by DevSecOps.“

Saturday, December 21, 2019

Asigra’s latest program defends public/non-profit organizations against cyber-attacks targeting backup data

Asigra announced a new program focused on defending the backup repositories and data of Canadian public and non-profit organizations against cyber-attacks. The purpose of the program is to ensure the recovery of data that otherwise may have become compromised as a result of malicious malware or ransomware Attack-Loops that prevent the recovery of mission-critical data and often put large volumes of personally identifiable information (PII) at risk.

Cyber-attacks on public/non-profit organizations have put citizen data at risk like never before as new variants of ransomware and other attacks continue to infiltrate and expose sensitive data to unknown and possibly criminal entities.


In a recent attack covered by the Toronto Star, medical test provider LifeLabs agreed to pay the ransom of attackers in order to retrieve millions of customer records. In a statement, the organization said, “The personal information of over 15 million customers was compromised, mostly in British Columbia and Ontario, including name, address, email, login, passwords, date of birth, health card number and lab test results.”

Like many organizations dealing with a cyber-attack, the last resort for recovery relies on a functioning disaster recovery or backup solution in place. Unfortunately, hackers have now designed ransomware and other malware to seek out secondary storage systems (aka: disaster recovery and backup data) in order to compromise a clean retrieval of the information. 


As a result, these organizations no longer have a way to reinstate their data, and therefore are faced with either relinquishing or paying a ransom which can be exceptionally high for public and non-profit entities.

As a Canadian company, Asigra is planning to help protect these organizations by partially donating a large percentage of its cybersecurity-enabled backup technology to Canada’s extensive list of public and non-profit organizations. Those establishments in the country that can issue a tax-deductible receipt may contact Asigra to receive the company's complete anti-ransomware/backup software suite with the cost covered in large part by a donation-in-kind.

Asigra’s cloud-based data recovery platform is unique in the industry for converging data protection and cybersecurity for effective malware/ransomware detection and prevention that ensures safe, secure and reliable data recovery. 


The advanced software includes initial zero-day Attack-Loop preventative technology using bi-directional cyber-threat detection, zero-day exploit protection, variable repository naming, and multi-factor authentication (MFA) for a full defensive suite against aggressive ransomware and other cyber-threats targeting backup data. This is complemented by FIPS 140-2 certification and military-grade data encryption to ensure enterprise-grade data security, making user data unreadable without the proper encryption key.

“The majority of cybersecurity analysts today agree that cyber-attacks are evolving from the perspective of what they target, how they impact organizations and the changing methods of attack,” said David Farajun, CEO, Asigra. “For the past year, we have seen an increasing number of cyberthreats begin to target the number one method of data recovery – the backup repository. As a specialist in this area, we have developed a very effective solution to fight against this and now offer the technology to public and non-profit organizations we share our data with.”

Tuesday, November 26, 2019

Dell Security lists essential tips to help keep cybercriminals at bay this holiday season

With the start of the holiday season, Dell Security expects consumers to be doing some online shopping. However, cybercriminals are also shopping around the same time.

The uptick in online shopping during the holidays leaves more chances for cybercriminals to steal data. This can happen in any number of ways – visiting compromised websites, clicking on phishing emails or fake social media posts, falling for holiday charity scams and even buying from fraudulent shopping sites. The methods vary and cybercriminals get more innovative each year, but their goal remains the same: steal personal and financial information.




Here are a few precautions that users must take to help protect their information while shopping online. Users must make sure that the website they are using is secure by looking at the URL. If it begins with https:// (there must be an “s” after http), then the website is secure and will encrypt information. Also, strive to use sites with reputable brands which are known and trusted.


Consumers must completely avoid using public computers for online shopping. Public computers, like those in libraries and hotel business centers, may contain malicious software that could steal personal information. At the same time, users must be wary of public Wi-Fi, which may not be secure and could provide easy access for criminals to intercept personal data.

Adoption of strong passwords is critical and important way to securing devices. Use a combination of numbers, letters and symbols to make password complex and difficult to guess, and don’t use names of family members, pets or birthdays. Caution must be exercised and never use the same password across multiple sites. Clients must resist clicking on bogus links and attachments in emails, tweets, social media posts and online advertising are ways cybercriminals can compromise the device. 


If it looks suspicious, delete it. Also, always hover over a link with the mouse and review the destination address carefully before you click.
Users must remain in the know with account alerts by activating fraud alerts with bank, credit cards, and credit bureaus to help detect suspicious activities like new payee, money withdrawal, high-value credit card transaction, activity in unusual locations, etc.

Another precaution users must take is to be sure to ship their new purchases to a secure location. If the user is aware that they won’t be home, ship to the office or to a neighbor to help prevent package theft. Also, packages left on a porch or otherwise in site of the public could be an indicator, users may be away from home and invite criminal activity.

Staying safe online will continue to require vigilance, and the convenience of online shopping will continue to come with risks. But by being diligent when shopping online, users can help combat cybercriminal activity during the holidays and year-round.

Monday, November 25, 2019

Nyotron releases RIPlace technique that renders ransomware invisible to security software

Nyotron announced it has discovered a new Microsoft Windows file system technique that enables cyberattackers to maliciously encrypt files in a way that existing anti-ransomware products cannot detect. The company has alerted security vendors of the threat it has named "RIPlace," and released a free tool that allows users to check their systems for exposure to the technique.



Ransomware has been around since 1989, yet remains one of the most common and successful attack types, causing billions of dollars in damages worldwide every year. 


The Verizon 2019 Data Breach Investigations Report (DBIR) states that ransomware accounts for nearly 24 percent of all incidents where malware was used last year, making it the second most common type of malware reported. 



The combination of timely patching and using modern antivirus solutions helps stop some ransomware. However, RIPlace can bypass these defenses by using a legacy file system "rename" operation. It takes only two lines of code for hackers to unleash this technique.



Nyotron's free tool enables users and organizations to check their systems for the RIPlace vulnerability. If the system is deemed to be at-risk, the tool provides solution recommendations.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...