Showing posts with label threats. Show all posts
Showing posts with label threats. Show all posts

Wednesday, 17 February 2016

10 Mistakes to Avoid to Make Open Source More Secure

Open source is becoming more popular in the enterprise. But so are open-source vulnerabilities. Here is how you can prevent open source-related mishaps in 2016.
 
It's no secret that open source is becoming more popular in the enterprise. Organizations from service companies to manufacturers to banks are tapping open source to take advantage of factors such as lower development costs, faster time to market and simplified application deployment through containers. Mission-critical performance is no longer a major hurdle. But there's another issue with open source that is sticking in enterprises' craw—and will continue to stick throughout 2016 and beyond. That issue is security. More than 6,000 new open-source vulnerabilities have been reported since 2014. Given the fact that, according to various surveys, 98 percent of companies are using open-source software they don't even know about, it stands to reason that enterprises don't have a good handle on how to defend against this growing threat. Most organizations lack automated processes for selection and approval of new open source as it enters a code stream, as well as inventorying and tracking the use of open-source software within their code base and Linux containers. Identification of or monitoring for known open-source vulnerabilities (like Heartbleed and ShellShock) is another issue many organizations now face as their use of open source grows. Based on interviews with eWEEK, Black Duck, a provider of software that identifies open-source components and maps known open-source security vulnerabilities, offers some advice about issues enterprises should consider to prevent open source-related mishaps in 2016.

Watch the slide show 

Thursday, 2 July 2015

9 Productivity Tricks for the Time-Crunched Security Professional

Security professionals are a busy bunch. Thanks to sophisticated threats, limited resources, product complexities, compliance demands and business objectives, you already are being pulled in what probably feels like a thousand directions - and that's on a good day.

Your job may never slow down. But when confronting these challenges, you can implement clever solutions that will help boost your time management, efficiency and performance to get things done. Much of the advice out there for improving productivity is repeated over and over (arriving at the office early, limiting meetings, taking regular "fresh air" breaks) - but much less available are suggestions specific to security careers.

Here are nine actionable "hacks" that will help you pick up your game and optimize your infosec routine, all while sharpening both your hard and soft skills in the process.

Efficiency tools
Outsource resource-consuming work
Threat feeds and lists
Data breach repositories
Security stats
Virtualization
Coding
ModSecurity
McCumber cube

Read the full post

Wednesday, 21 January 2015

How cloud computing - and other new technology - could lead to the destruction of humanity

Back in 2000, technologist Bill Joy, one of the co-founders of Sun Microsystems, penned a feature for Wired magazine that caused a storm. Although Joy could boast a CV packed with technology breakthroughs, "Why the future doesn't need us" saw him cast as a neo-Luddite.

In it, he postulated that far from ushering in an age of comfort and leisure, new and advanced technology posed a potential threat to humanity. He cited nanotechnology with "uncontrolled replicators", genetic engineering, and robotics, to name just three, that separately or collectively posed a mortal threat to humanity if mis-used or mis-applied.

If Joy were writing the same article today, he would no doubt add cloud computing to the list of threats: networks of servers controlled by a small group of companies - which will only get smaller with consolidation - that will increasingly communicate with each other so that organisations can run applications across disparate clouds.

Read the full article

Monday, 24 September 2012

Cloud computing: What does it really mean for IT jobs?

As adoption of cloud computing services takes off, some argue demand for certain IT jobs will all but disappear.

Just as manual labourers were replaced by the machines of industry in the 19th century so certain IT roles will be swept away by cloud computing.

That’s the argument put forward by Gartner research director Gregor Petri - who believes that many roles managing IT infrastructure will all but disappear.

Manual management of IT infrastructure - for instance provisioning additional storage, servers or network capacity for a particular application - will increasingly be automated as software layers in the cloud automatically divert IT resources to where they are needed, he said.

“It is very much like industrialisation,” he said.

Read the full post

Beauty lies in the ‘domain’ of the highest bidder

Icann, the global authority dealing with domain names, is hastening the threat of monopolisation on the internet through its new scheme to sell generic words.

L’Oréal has applied for the top level domain (TLD) .beauty to the Internet Corporation for Assigned Names and Numbers (Icann), the global authority dealing with domain names on the Internet. TLDs are what we see on the right side of the dot in domain names — for example, .com and .net. If L’Oréal gets .beauty, which seems very likely, it will be able to reserve this top level domain name just for its own use. Unlike .com, .org, .net etc, which are public TLDs, .beauty will be a private TLD. What this means is that, for instance, “Raji Curls,” a beauty salon, will not be able to ask for www.rajicurls.beauty, as one could have in the case of .com. L’Oréal will have the exclusive use of .beauty, as its private property. If L’Oréal were to seek a trademark for “beauty,” it will be flatly refused. The word is too generic for anyone to be given monopoly rights over it. It is therefore surprising that L’Oréal should be able to get global monopoly rights on .beauty, just because it is willing to pay $1,85,000, the application fees for new TLDs, to Icann.

Read the full story

Tuesday, 28 August 2012

IT's 9 Biggest Security Threats

Years ago the typical hacking scenario involved a lone attacker and maybe some buddies working late at night on Mountain Dew, looking for public-facing IP addresses. When they found one, they enumerated the advertising services (Web server, SQL server, and so on), broke in using a multitude of vulnerabilities, then explored the compromised company to their heart's content. Often their intent was exploratory. If they did something illegal, it was typically a spur-of-the-moment crime of opportunity.

My, how times have changed.

When describing a typical hacking scenario, these days you must begin well before the hack or even the hacker, with the organization behind the attack. Today, hacking is all crime, all the time, complete with bidding markets for malware, crime syndicates, botnets for hire, and cyber warfare gone amok.

Here are the nine biggest threats facing today's IT security pros as outlined by Roger A. Grimes.

Threat No. 1: Cyber crime syndicates
Threat No. 2: Small-time cons -- and the money mules and launders supporting them
Threat No. 3: Hacktivists
Threat No. 4: Intellectual property theft and corporate espionage
Threat No. 5: Malware mercenaries
Threat No. 6: Botnets as a service
Threat No. 7: All-in-one malware
Threat No. 8: The increasingly compromised Web
Threat No. 9: Cyber warfare

Read the full post