Category: Security

Security is more important than ever. Cybersecurity has been a problem from the start of IT and it will be till the end. It all started with endpoint and network security, but today, we are also facing with cloudsecurity and managing employees to incorporate good security practices.

All these new technologies that help us innovate also helps cybercriminals and state sponsored hackers to get new tools they can use to get access to our systems, and in a worst case scenario, access to our most valuable data and business secrets. Also, with new legislation in place like GDPR, you need to make sure everything is secure, otherwise you just don’t lose your reputation, but you can also be fined by the government. Protecting IT-environments is more important than ever.

Endpoint Security

Your first line of defense is usually endpoint protection. The devices your employees work with need to be protected against ransomware and other malware which can bring lots and lots of trouble. This nowadays the most basic form of protection and many of the bigger vendors and suites can help you achieve this.

Network security

Network security is a bit more advanced, where you can manage which traffic goes across your network. You can also connect different networks together with e.g. SD-WAN. So, you can run protection software and share data between multiple locations. The trend we see in network protection on the datacenter side is to lock down the traffic by only allowing known, benevolent traffic sources. Regarding office networking, we see new initiatives like ZScaler coming up, where you tunnel all your staff over the network of ZScaler so they can analyse the traffic and block patterns that they marked as malicious. Especially for companies with employees that travel a lot, this is a smart solution.

Cloud security

Many thought that bringing workloads to the cloud would reduce their responsibility of doing security. It is now clear that this is not the case. Most cloud vendors practice the “shared responsibility” approach. This means that big hyperscalers can offer a first line of defense against well known threats and port scanners. For the more sophisticated attacks that are directly pointed at your servers, you need to have your protection in place.

Researchers use ChatGPT to generate malware and phishing mails

Researchers use ChatGPT to generate malware and phishing mails

Researchers used ChatGPT to write malware scripts and generate phishing emails. The AI model has since been updated to prevent abuse. ChatGPT is in the spotlight. OpenAI, the model's developer, recently made the technology publicly available. ChatGPT generates texts and code based on queries. In... Read more

date1 year ago
IBM discovers wormable vulnerability eerily similar to EternalBlue

IBM discovers wormable vulnerability eerily similar to EternalBlue

Researchers have identified a Windows code execution vulnerability that has the potential to rival EternalBlue, a Windows security issue used to ignite WannaCry, which took down computer networks around the world in 2017. The newly discovered vulnerability is listed as CVE-2022-37958. It allows ... Read more

date1 year ago
Ransomware hits Leiden University

Ransomware hits Leiden University

The internal secondment agency of Leiden University has been hit by ransomware. The Dutch university reported the attack to the national data protection authority. An internal statement for employees reveals that the salary processing system of Job Motion, an internal university secondment agen... Read more

date1 year ago
LogRhythm and SentinelOne integrate for greater insight

LogRhythm and SentinelOne integrate for greater insight

LogRhythm and SentinelOne have integrated their technology. This should give companies more insight into potential threats and allow them to respond to them immediately. According to the partners, the collaboration produces an integrated enterprise security solution to prevent, detect and respon... Read more

date1 year ago
NIST retires SHA-1 algorithm

NIST retires SHA-1 algorithm

The US government's National Institute of Standards and Technology (NIST) is officially retiring the Secure Hash Algorithm-1 for secure data processing. The protocol's second and third versions are more secure. NIST has announced that the SHA-1 encryption algorithm has officially reached its en... Read more

date1 year ago
Microsoft bans crypto mining from its online services

Microsoft bans crypto mining from its online services

Microsoft quietly banned crypto mining activities in Azure, Office 365, Dynamics 365 and Power Platform. Microsoft argues that preventing crypto mining preserves the performance of services for other customers and protects users from potential malicious activity associated with crypto mining. ... Read more

date1 year ago
NSA: cybercriminals actively exploit Citrix ADC and Gateway

NSA: cybercriminals actively exploit Citrix ADC and Gateway

US security and intelligence agency NSA warns that hackers are exploiting zero days in Citrix networking devices. The exploits abuse vulnerabilities in Citrix application delivery controller (ADC) and Citrix Gateway. According to the NSA, cybercrime group APT5 is actively exploiting a vulnerabil... Read more

date1 year ago
UK announces code of practice to strengthen app store security

UK announces code of practice to strengthen app store security

The UK's new code of practice incentivizes developers and publishers to implement stronger security measures. A code of practice to boost security safeguards throughout the app sector has been announced by the UK government. The new voluntary policy intends to better shield users from harmful ap... Read more

date1 year ago
1 83 84 85 86 87 276