Vulnerability Allows Remote DoS Attacks Against Apps Using Linphone SIP Stack

Vulnerability Allows Remote DoS Attacks Against Apps Using Linphone SIP Stack

A serious vulnerability affecting the Linphone Session Initiation Protocol (SIP) client suite can allow malicious actors to remotely crash applications, industrial cybersecurity firm Claroty warned on Tuesday. SIP is a signaling protocol designed for initiating, maintaining and terminating communication sessions. The protocol is often used for voice, video, instant messaging, and other types of applications….

Federal Departments Ordered to Improve Logging Capabilities

Federal Departments Ordered to Improve Logging Capabilities

Governance & Risk Management , Government , Incident & Breach Response OMB Memo Describes Steps Agencies Must Take to Report Cyber Incidents Scott Ferguson (Ferguson_Writes) • August 31, 2021     Acting OMB Director Shalanda Young (Photo: U.S. Senate Banking Committee) The White House is ordering U.S. agencies to improve their logging capabilities to better…

SEC Sanctions Several Companies Over Email Account Hacking

SEC Sanctions Several Companies Over Email Account Hacking

The U.S. Securities and Exchange Commission (SEC) this week announced sanctions against several companies over cybersecurity failures that resulted in email accounts getting hacked and the exposure of customer information. A total of eight entities belonging to three companies have been sanctioned by the SEC, including Cetera (Advisor Networks, Investment Services, Financial Specialists, Advisors, and…

Afghanistan: Taliban asked if there will be a place for women in new government

Afghanistan: Taliban asked if there will be a place for women in new government

A Taliban spokesman has been asked if women and ethnic minorities will have a place in the new Afghan government. In an interview with BBC Pashto, the deputy head of the Taliban political office in Qatar said women could continue in their work but in the top posts or cabinet there “may not” be a…

SEC Sanctions 8 Firms for ‘Deficient Cybersecurity Procedures’

SEC Sanctions 8 Firms for ‘Deficient Cybersecurity Procedures’

Finance & Banking , Industry Specific , Security Operations Regulator Cites Email Takeovers, Inadequate Incident Response Dan Gunderman (dangun127) • September 1, 2021     (Photo: Securities and Exchange Commission via Flickr) The U.S. Securities and Exchange Commission sanctioned eight financial firms for alleged failures related to cybersecurity policies and procedures, each stemming from email…

Don’t use single‑factor authentication, warns CISA

Don’t use single‑factor authentication, warns CISA

The federal agency urges organizations to ditch the bad practice and instead use multi-factor authentication methods The Cybersecurity and Infrastructure Security Agency (CISA) has added the use of single-factor authentication to its brief list of bad practices that it considers to be exceptionally risky when it comes to cybersecurity. “Single-factor authentication is a common low-security…