Visit our other websites:    Consumer IT    On CE    Mobile Channels    ECI news    rAVe Europe    Digital Signage News    

 

eSP - IT Solution Providers in Europe

  • Full Screen
  • Wide Screen
  • Narrow Screen
  • Increase font size
  • Default font size
  • Decrease font size

Security

iOS, OS X Malware Lurks in USB Wires

E-mail Print PDF
iOS, OS X Malware Lurks in USB Wires

Security experts at Palo Alto Networks warn of a new breed of malware targeting Apple products-- "WireLurker," a piece of software able to install malicious 3rd party apps on iPhones and iPads. 

"WireLurker monitors any iOS device connected via USB with an infected OS X computer and installs downloaded 3rd party applications or automatically generated malicious applications onto the device, regardless of whether it is jailbroken," Palo Alto Networks says. "This is the reason we call it “wire lurker”."

As mentioned above, the WireLurker is particularly nasty as it is the first able to crack through even non-jailbroken iDevices via enterprise provisioning. So far it appears to have only reached users in China, as it currently lurks in apps available in Maiyadi, a Chinese 3rd party app store. According to Palo Alto Networks 467 apps were infected during the last 6 months, potentially hitting hundreds of thousands of users. 

Read more...

IBM Takes on Cloud Security

E-mail Print PDF
IBM Takes on Cloud Security

IBM announces what it claims is first "intelligent security portfolio" for protection of data the cloud in the industry-- the IBM Dynamic Cloud Security Portfolio.

It features tools handling security across enterprise, private and public clouds, and mobile devices, with advanced analytics providing a "single-pane-of-glass" view ranging from the entire enterprise to individual mobile devices. Also included is the IBM Managed Security Services platform, which secures clouds from both IBM and other vendors, including Amazon Web Services and Salesforce.com.

As IBM puts it, the portfolio covers access authentication, data control, visibility improvement and cloud security operations optimisation, and is deployable either on-premise or in the cloud.

Read more...

ENISA Holds Biggest Security Exercise

E-mail Print PDF
ENISA Holds Biggest Security Exercise

ENISA tests the readiness the counter cyber-attacks of 200 organisations and 400 security professionals from 29 European countries in a day-long bi-annual exercise dubbed Cyber Europe 2014.

Described by the agency as the largest and most complex cyber-security exercise held in Europe, Cyber Europe 2014 brings together experts from both public and private sectors, including security agencies, national Computer Emergency Response Teams, ministries, telecoms, energy companies, financial institutions and ISPs. The scenario covers over 2000 incidents, such as DDoS attacks on online services, intelligence and media reports on attack operations, webs defacements, ex-filtration of sensitive information and attacks on critical infrastructure.

Being a distributed exercise, it involves several exercise centres across Europe coordinated by a central exercise centre. It also tests the EU-Standard Operational Procedures, a set of guidelines on the sharing of operational information on cyber crises.

Read more...

SSL Flaw Warning: POODLE

E-mail Print PDF
SSL Flaw Warning: POODLE

Google researchers discover a legacy SSL 3.0 protocol vulnerability, one potentially exposing users of newer Transport Layer Security (TLS) encryption protocols to risk-- Padding Oracle On Downgraded Legacy Encryption, aka POODLE.

Unlike its namesake, POODLE is not too cuddly. Instead, it allows man-in-the-middle attackers to access and read encrypted communications via padding oracle side-channel attack.

SSL 3.0 made its debut back in 1996, but remains a widely used cryptography protocol. Nearly all browsers support it, and use it as a fallback in case of HTTPS server bugs. Thus, network attackers can cause connection failures and trigger SSL 3.0 use in order to exploit the vulnerability.

Read more...

Sophos: Europe Demands Stronger Data Protection

E-mail Print PDF
Sophos: Europe Demands Stronger Data Protection

Ahead of upcoming EU data protection regulation reform, 84% of respondents of a Sophos survey agree Europe needs stronger data protection laws, but 77% do not believe their organisations comply with current regulation.

Conducted by Vanson Bourne, the research shows only 23% of participants believe their organisations comply with current regulation. Meanwhile 50% confess to either not knowing either not knowing what encryption is (7%) or whether their organisation has it (20%). Only 23% can confirm their organisations encrypts both employee and customer data.

When it comes to mobile device security 98% agree their data is more important than actual devices-- but 25% admit to storing corporate information on personal mobile phones and laptops, while 19% have lost a personal device at one point. At least 64% of respondents' organisations use password-protected mobile devices, but only 31% are aware of encryption functionality.

Read more...

Page 40 of 67