First the good news: according to a published report there were more than 16,000 software vulnerabilities disclosed during the first nine months of this year. Now, that’s quite a few vulnerabilities that could enable attackers, exploits, and malware to scurry onto an enterprise environment. However, it is 7 percent fewer vulnerabilities than 2017.
All about Virtualization and Cloud Security | Recent Articles:
Last year the OWASP Top 10 committee was prophetic in at least one of its inclusions in the update to its industry benchmark list. For the first time, the group included insecure APIs as one of the most common attack vectors that developers need to avoid adding to their code when creating software. Looking back on 2018, you can see why they sounded the warning.
Mariottt International has suffered what can be considered one of the largest data breaches in history, trailing only the 2013 Yahoo breach. The world’s largest hotel chain said some 500 million customer records were compromised.
This year’s online holiday shopping season was kicked off to tremendous fanfare, as deal hunters went crazy last week with record-breaking spending. According to USA Today, holiday sales on Cyber Monday topped $7.9 billion in just the US alone. Meanwhile, mega retailer Amazon reported that Cyber Monday was the single biggest global shopping day in its company history—people ordered more than 18 million toys from Amazon on Cyber Monday and Black Friday combined.
If your organization has a healthy cybersecurity culture, consider yourself lucky — less than five percent of organizations do.
Phishing remains a key attack vector for bad actors to compromise not just individual user accounts, but also to establish a foothold in the entire infrastructure of a given organization. This is possible because attackers know one thing very well: a company’s first line of defense, its staff, is also its weakest security layer.
In May 2017, the WannaCry ransomware took copious amounts of data hostage and demanded hefty sums in exchange for the decryption keys. The contagion, allegedly the work of North Korean hackers, spread like wildfire, infecting countless systems worldwide and dealing billions of dollars in damages. Some victims ceded to the attackers’ demands, but few got their data back.
The BYOD Paradox: Personal Devices Expose Businesses to Cyber-Risk, But Employees Don’t Want Bosses Controlling Their Gadgets
BYOD programs have had a mixed track record over the years. Some say they increase mobility, flexibility, efficiency and collaboration, leading to a more productive workforce overall. Other businesses still shun the practice outright.
Building a Multi-Cloud Strategy? Be Sure to Address the Security and Management Challenges
Many organizations today are adopting a multi-cloud strategy, using services from several cloud providers and deploying offerings such as software-as-a-service (SaaS), platform-as-a-service (PaaS), and infrastructure-as-a-service (IaaS) to meet a variety of business needs.
Lack of Political Leadership in UK Jeopardizes Cyber Security of Critical Sectors, Report Says
The lack of political leadership to face targeted attacks is contributing to the poor job the UK is doing on its national security strategy, says a UK government report discussing the cyber security of the nation’s critical national infrastructure.
The advanced attack targeting Pakistan described by Cylance mentions an evasion technique that incapacitates the security solutions provided by 8 vendors. Bitdefender products have been successfully blocking this threat since 2016. We conducted our own analysis of this malware and we have new findings to share.
EU data protection legislation aims to give users more control over their personal data, and threatens companies with fines for collecting data without user consent and for data breaches. Countless companies have been struggling to become GDPR compliant, but it seems major tech players may not have taken it seriously. After Facebook and Google drew criticism for violating EU’s data protection law, it is now Microsoft’s turn to take the heat.
Cloud Security
Subscribe to Blog Updates
Posts by Categories
- Advanced Persistent Threat (3)
- APT (2)
- artificial intelligence (1)
- biometrics authentication (1)
- breach (2)
- bug bounty (1)
- BYOD (28)
- CIO (7)
- CIOs (5)
- CISO (15)
- Cloud Security (117)
- connected care (1)
- container security (1)
- corporate hijacking (2)
- credit card (3)
- cryptocurrency (7)
- cryptojacking (8)
- cryptomining (4)
- cyber insurance (2)
- Cyber Security Awareness Month (5)
- cyber-attack (5)
- cybersecurity awareness (20)
- data breach (30)
- Data Protection (75)
- data protection act (3)
- datacenter (3)
- DevOps (9)
- EDR (3)
- endpoint detection and response (1)
- Endpoint Protection & Management (15)
- Enterprise Security (420)
- Equifax (2)
- Events (4)
- financial services (15)
- garter (1)
- GDPR (14)
- GDPR, Data Protection (7)
- General Data Protection Regulation (4)
- government alert (1)
- Healthcare (4)
- hyperconverged infrastructure (1)
- hypervisor (15)
- hypervisor introspection (10)
- identity theft (4)
- Industries (32)
- insider threats (11)
- Integration (2)
- IoT (10)
- IoT botnet (2)
- IoT, Policy, security (9)
- IT Compliance & Regulations (32)
- Linux (1)
- Machine Learning (7)
- malware, threats (12)
- memory introspection (12)
- Microsoft (3)
- Network Protection (9)
- power grid (3)
- ransomware (7)
- ransomware, HVI (3)
- report (1)
- Security as a Service (15)
- Security Threats (57)
- SMB Security (41)
- Software-defined-datacenter (5)
- telecommunications (2)
- Virtualization & Data Center Security (69)
- vulnerability disclosure policy (1)
- WDATP (1)
Latest Tweets
Tweets by @Bitdefender_EntPosts by Month
- February 2019 (14)
- January 2019 (19)
- December 2018 (19)
- November 2018 (23)
- October 2018 (22)
- September 2018 (22)
- August 2018 (23)
- July 2018 (24)
- June 2018 (22)
- May 2018 (28)
- April 2018 (23)
- March 2018 (22)
- February 2018 (19)
- January 2018 (19)
- December 2017 (13)
- November 2017 (17)
- October 2017 (19)
- September 2017 (18)
- August 2017 (16)
- July 2017 (17)
- June 2017 (16)
- May 2017 (17)
- April 2017 (15)
- March 2017 (16)
- February 2017 (13)
- January 2017 (14)
- December 2016 (11)
- November 2016 (14)
- October 2016 (11)
- September 2016 (10)
- August 2016 (15)
- July 2016 (12)
- June 2016 (15)
- May 2016 (10)
- April 2016 (13)
- March 2016 (15)
- February 2016 (14)
- January 2016 (6)
- December 2015 (6)
- November 2015 (9)
- October 2015 (8)
- September 2015 (11)
- August 2015 (8)
- July 2015 (10)
- June 2015 (3)
- May 2015 (8)
- April 2015 (6)
- March 2015 (5)
- February 2015 (7)
- January 2015 (8)
- December 2014 (8)
- November 2014 (9)
- October 2014 (8)
- September 2014 (9)
- August 2014 (9)
- July 2014 (8)
- June 2014 (8)
- May 2014 (6)
- April 2014 (8)
- March 2014 (5)