Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

Fresh evidence on IT security threat

Posted on February 25, 2013December 30, 2021 by admini

HTTP proxy, used both as a security component and to evade controls, exhibited the 7th highest volume of malware logs.

René Bonvanie, chief marketing officer at Palo Alto Networks, said: “Correlating threats with specific applications allows security teams to directly see and control risks in their networks.”

Matt Keil, senior research analyst at Palo Alto Networks and author of the report said:”The volume of exploits targeting business critical applications was stunning and serves as a data centre security wake-up call. These threats will continue to afflict organisations until they isolate and protect their business applications by bringing threat prevention deeper into the network.”

Custom or unknown applications are defined as either TCP or UDP based applications that are custom (internal to the organization), unrecognised commercially available, or a threat.

Link: http://www.iwr.co.uk/information-management-and-technology/3011498/Fresh-evidence-on-IT-security-threat

Read more

New RSA Solutions To Help Bring Faster Incident Response That’s Better Aligned to Business Risk

Posted on February 25, 2013December 30, 2021 by admini

.To achieve these goals security teams must not just employ better security analytics to help identify advanced threats, but also must have the tools and threat intelligence to understand which security alerts represent the highest risk to the business, and what assets require the greatest protection.

RSA’s new solutions are expressly designed to align the efforts of the security and business teams to better protect the critical assets of an organization. Built on the proven architectures of the RSA Archer® Governance, Risk and Compliance (GRC) platform and RSA(®) Data Loss Prevention (DLP) suite, these new solutions combine with the RSA Security Analytics platform to help next generation Security Operations Centers address multiple dimensions of advanced threats.

Along with these new solutions, RSA is also releasing the latest version of RSAArcher(®) Threat Management 4.0 software that is designed to prioritize security projects based on risk and threat scores by aggregating and fusing threat intelligence feeds with vulnerability scan results from multiple sources. “Prioritizing the security alerts that have the most potential risk to the organization is critical in ensuring maximum protection for sensitive assets and information. … We built these new solutions on the proven RSA Archer GRC platform, which not only makes them very functional out-of-the-box but also helps organizations already using RSA Archer technology to extract more value out of their GRC investments.”

The new solutions from RSA can help align the efforts of security and business groups in order to be more efficient and better address the security incidents and threats that have the biggest potential to impact the business.”

Link: http://pn.newsblaze.com/release/2013022505310600027.pnw/topstory.html

Read more

The security threat of evasive malware

Posted on February 25, 2013December 30, 2021 by admini

The report finds that stalling codes are particularly troublesome because they “can no longer be handled by traditional sandboxes (even if the trick is known).”

“Current sandboxes have a lack of visibility into the execution of a malware program,” said Giovanni Vigna, CTO of Lastline. “To detect this new breed of evasive threats, a sandbox needs to have visibility and must be able to do this stealthily.

Link: http://www.net-security.org/malware_news.php?id=2423

Read more

Sourcefire anti-malware appliance aims to stop APTs in their tracks

Posted on February 25, 2013December 30, 2021 by admini

The firm said the combination of services will offer companies unmatched visibility across their network, letting them dynamically see how malware enters, infects and moves thus letting them intelligently respond to the threat.

“Sourcefire’s threat-centric approach to security gives organisations continuous visibility, analysis and control across their environment and along the full attack continuum – before, during and after an attack.”

Sourcefire is one of many companies to warn businesses that they must implement more robust network monitoring tools if they want to defend themselves from hackers.

BAE Systems recently told V3 that firms’ current lack of knowledge regarding what’s going on in their systems is giving hackers an advantage, by letting them shift tactics whenever they are uncovered.

Link: http://www.v3.co.uk/v3-uk/news/2250158/sourcefire-antimalware-appliance-aims-to-stop-apts-in-their-tracks

Read more

Next-Generation Threat Protection From FireEye

Posted on February 25, 2013December 30, 2021 by admini

Multi-Vector Virtual Execution™ (MVX) Engine – The MVX engine is designed to capture and confirm today’s cyber attacks by detonating Web objects, files, suspicious attachments, and mobile applications within instrumented virtual environments. It is the leading signature-less technology that can be used across threat vectors to automate the discovery and forensic analysis of malicious code resulting in multi-vector dynamic threat intelligence on attacks specific to an organization.

By exchanging anonymized threat intelligence through the DTI cloud, participants gain contextual visibility of global attacks and can strengthen their collective security with the latest protections and neutralize attacks before they cause catastrophic damage.

Partner Interoperability via APIs and Standards-based Threat Intelligence Metadata – Partner integrations utilize the FireEye APIs to address the network visibility, endpoint validation, and enforcement options needed by today’s organizations. In addition, FireEye will be publishing a standards-based threat intelligence metadata exchange format that enables FireEye and third-party security solutions to interoperate and automate key cyber security workflows.

“Dynamic threat intelligence is critical to combating advanced threats from adversaries that may already be inside your network,” said Mark Seward, senior director of security and compliance at Splunk Inc.

“FireEye is the security platform organizations can rely upon for protection against today’s new breed of cyber attacks,” said David DeWalt, FireEye chairman and CEO. “We have enabled flexible options so customers can integrate our dynamic threat intelligence into their existing security infrastructure to automate the threat response and rapidly neutralize today’s cyber attacks.”

Link: http://www.webhostmagazine.com/2013/02/next-generation-threat-protection-from-fireeye/

Read more

Urgency grows to blend cyber, physical combat

Posted on February 22, 2013December 30, 2021 by admini

“We’re pulling in cyber and physical folks to do joint assessments, looking at what are the cyber vulnerabilities, what are the physical vulnerabilities, how do they relate to each other, and importantly, what are the cascading effects?”

An alignment of policies and actions in cybersecurity is happening across the government, recently evidenced by mandates for cooperation and information-sharing rolled out in President Barack Obama’s executive order and accompanying presidential policy directive. On the military side, a parallel alignment is taking place as well, but it has required a careful consideration of core missions and how to meet their requirements, according to one Defense Department official.

“So one thing we needed to do in defining the missions…we needed to align forces, capability and capacity to each one of the missions.”

Those missions – defending national security against cyber threats, securing the DOD information network and supporting combatant commands – are still being tweaked at CyberCom, now in its third year of full operation.

Link: http://fcw.com/articles/2013/02/22/cyber-conventional-war.aspx

Read more

Posts navigation

  • Previous
  • 1
  • …
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • …
  • 421
  • Next

Recent Posts

  • AI/ML News – 2024-04-14
  • Incident Response and Security Operations -2024-04-14
  • CSO News – 2024-04-15
  • IT Security News – 2023-09-25
  • IT Security News – 2023-09-20

Archives

  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2025 CyberSecurity Institute | Powered by Superbs Personal Blog theme