4 ways to keep the cybersecurity conversation going after the crisis has passed
CISO Bill Brown knows how high-profile cybersecurity breaches like SolarWinds can raise alarm bells among executives and board members when they become headline news.
When medical device makers provide a software bill of materials for components contained in their products, it’s critical to make that voluminous security information actionable for healthcare customers, says Rob Suárez, CISO at medical device maker Becton Dickinson and Co., or BD. The Food and Drug Administration in draft guidance released in 2018 – which…
Application Security , Breach Notification , COVID-19 Experts Say Increase Owes to Lack of Funding, Virtual Learning Doug Olenick (DougOlenick) • March 15, 2021 U.S. public schools faced a record number of cyber incidents in 2020, with over 400 attacks reported. This led to a spike in school cancellations, as IT staff members…
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \evil.com/path. This vulnerability is only exploitable if an….
Cryptocurrency Fraud , Fraud Management & Cybercrime , Legislation & Litigation $70 Million Allegedly Lost to Schemes Such as Bitcoiin2Gen Touted by Steven Seagal Mathew J. Schwartz (euroinfosec) • February 25, 2021 Bitcoiin2Gen in 2018 said “Zen Master Steven Seagal” had become its “brand ambassador.” If there’s anything to put the final nail…
Breach Notification , Cybercrime , Fraud Management & Cybercrime Multiple Systems Impacted, Including Production and Shipping Capabilities Doug Olenick (DougOlenick) • March 11, 2021 The Molson Coors Beverage Co. reported Thursday it’s in the process of responding to an ongoing cybersecurity incident that has caused system outages throughout the brewer’s manufacturing process. See…
Application Security , Cybercrime , Cybercrime as-a-service Strikes Increase After ProxyLogon Proof-of-Concept Attack Code Released Akshaya Asokan (asokan_akshaya) • March 20, 2021 There has been a spike in web shells being detected, as ransomware gangs and other attackers increasingly target vulnerable Microsoft Exchange Servers following publication of proof-of-concept attack code for ProxyLogon, which…