Watch the slide show
Showing posts with label vulnerabilities. Show all posts
Showing posts with label vulnerabilities. Show all posts
Wednesday, 17 February 2016
10 Mistakes to Avoid to Make Open Source More Secure
Open
source is becoming more popular in the enterprise. But so are
open-source vulnerabilities. Here is how you can prevent open
source-related mishaps in 2016.
It's no secret that
open source is becoming more popular in the enterprise. Organizations
from service companies to manufacturers to banks are tapping open source
to take advantage of factors such as lower development costs, faster
time to market and simplified application deployment through containers.
Mission-critical performance is no longer a major hurdle. But there's
another issue with open source that is sticking in enterprises' craw—and
will continue to stick throughout 2016 and beyond. That issue is
security. More than 6,000 new open-source vulnerabilities have been
reported since 2014. Given the fact that, according to various surveys,
98 percent of companies are using open-source software they don't even
know about, it stands to reason that enterprises don't have a good
handle on how to defend against this growing threat. Most organizations
lack automated processes for selection and approval of new open source
as it enters a code stream, as well as inventorying and tracking the use
of open-source software within their code base and Linux containers.
Identification of or monitoring for known open-source vulnerabilities
(like Heartbleed and ShellShock) is another issue many organizations now
face as their use of open source grows. Based on interviews with eWEEK, Black Duck,
a provider of software that identifies open-source components and maps
known open-source security vulnerabilities, offers some advice about
issues enterprises should consider to prevent open source-related
mishaps in 2016.
Watch the slide show
Watch the slide show
Labels:
2016,
mishaps,
mistakes,
open source,
security,
threats,
tips,
vulnerabilities
Friday, 29 January 2016
Fitness Tracker Vulnerabilities and How to Deal with Them
If Fitbit Charge users were wearing their fitness trackers when they heard the news about Fitbit user accounts being hacked, they probably saw their heart rates increase. On January 6, 2016, BuzzFeed News broke the story on how cybercriminals hacked multiple Fitbit user accounts. They changed email addresses and usernames as well as tried to swindle Fitbit out of replacement items under warranty.
The cybercriminals also gained access to Fitbit users' data, according to BuzzFeed News. The data includes activity-related metrics, such as the number of steps taken and calories burned. It also includes where users are performing those activities and what time they usually go to sleep if their devices have Global Positioning System (GPS) and sleep-tracking functionality.
This cyberattack begs the question: What are the fitness trackers' vulnerabilities and how can you deal with them? To answer it, you first need to know how they work.
The cybercriminals also gained access to Fitbit users' data, according to BuzzFeed News. The data includes activity-related metrics, such as the number of steps taken and calories burned. It also includes where users are performing those activities and what time they usually go to sleep if their devices have Global Positioning System (GPS) and sleep-tracking functionality.
This cyberattack begs the question: What are the fitness trackers' vulnerabilities and how can you deal with them? To answer it, you first need to know how they work.
How Fitness Trackers Work
Fitness trackers use various sensors that continuously generate data about the wearer. Because the devices need to be small and lightweight, they do not store or process this data. Instead, they typically use short-range wireless transmissions to send the data to smartphones (or computers) for storage. Apps on these devices analyze the data and display the results. Oftentimes, these apps also send a copy of the data to cloud-based servers hosted by the fitness tracker vendors. Besides storing the data, the vendors sometimes offer additional services, such as more detailed analyses.
Because fitness trackers work this way, there are security vulnerabilities on several fronts:
When the data is sent to the smartphone
When the data is sent to the vendor's cloud servers
When the data is stored in the cloud
Fitness trackers use various sensors that continuously generate data about the wearer. Because the devices need to be small and lightweight, they do not store or process this data. Instead, they typically use short-range wireless transmissions to send the data to smartphones (or computers) for storage. Apps on these devices analyze the data and display the results. Oftentimes, these apps also send a copy of the data to cloud-based servers hosted by the fitness tracker vendors. Besides storing the data, the vendors sometimes offer additional services, such as more detailed analyses.
Because fitness trackers work this way, there are security vulnerabilities on several fronts:
When the data is sent to the smartphone
When the data is sent to the vendor's cloud servers
When the data is stored in the cloud
Labels:
fitness trackers,
health,
security,
vulnerabilities,
wearables
Friday, 22 June 2012
Trustwave 2012 Global Security Report
Expert Analysis from Trustwave SpiderLabs on Today's Data Security Threats
The Trustwave 2012 Global Security Report highlights top data security risk areas, offering predictions on future targets based on analysis and perceived trends. In 2011, one of the most notable trends was the targeting of customer records; 89% of attacks were focused on obtaining personally identifiable information, credit card data and other customer data. The report discusses this trend and many more, and defines how companies across the globe are leaving themselves open to data security threats.
By learning from others’ data vulnerabilities, and applying tactical and strategic change outlined in this report, any organization will be better able to reduce data threats and loss.
Labels:
data security,
reports,
security,
tips,
trustwave,
vulnerabilities
Subscribe to:
Posts (Atom)