Vulnerability

2020 State of the Phish

An in-depth look at user awareness, vulnerability and resilience INTRODUCTION Do you have a good sense of how well users understand cybersecurity terms and best practices? Do you know the top issues infosec teams are dealing with as a result of phishing attacks? How about the ways organizations are fi ghting phishing attacks and the […]

2020 State of the Phish Read More »

2020 Open Source Security and Risk Analysis Report

Welcome to the 5th edition of Synopsys’ Open Source Security and Risk Analysis (OSSRA) report. The 2020 OSSRA includes insights and recommendations to help security, risk, legal, and development teams better understand the open source security and license risk landscape. To help organizations develop secure, high-quality software, the Synopsys Cybersecurity Research Center (CyRC) publishes research

2020 Open Source Security and Risk Analysis Report Read More »

Kr00k – CVE-2019-15126

Kr00k – CVE-2019-15126 is a vulnerability that affected billions of devices, potentially causing the leak of sensitive data and opening a new attack vector for blackhats. Following the discovery of the vulnerability, ESET responsibly disclosed it to the affected chip manufacturers Broadcom and Cypress (and, initially, to Amazon). We also contacted ICASI to ensure that

Kr00k – CVE-2019-15126 Read More »

2019 IBM X-Force Threat Intelligence Index

Nearly a year has passed since Australia’s mandatory data breach notification regime came into force. Over the last quarter, the highest reported source of breaches involved human factors such as clicking on an attachment to a phishing email. This trend is in line with the global statistics revealed by the latest annual 2019 IBM X-Force Threat Intelligence Index report, which suggests that one third of attacks analysed by X Force IRIS globally involved compromises via phishing emails.

2019 IBM X-Force Threat Intelligence Index Read More »

Securing Small-Business and Home Internet of Things (IoT) Devices: Mitigating Network-Based Attacks Using Manufacturer Usage Description (MUD)

The guide’s example solutions demonstrate the effectiveness of the Internet Engineering Task Force’s Manufacturer Usage Description Specification in strengthening security for IoT devices on home and small-business networks.

Securing Small-Business and Home Internet of Things (IoT) Devices: Mitigating Network-Based Attacks Using Manufacturer Usage Description (MUD) Read More »

Cybersecurity Nexus (CSX) – Vulnerability and Exploitation Course (CVEC)

The Vulnerability and Exploitation Course (CVEC) provides students, who possess a basic understanding of penetration testing, a deeper understanding of vulnerability identification and exploitation capabilities. Students will work with real systems in real environments and will leverage real vulnerability analysis and exploitation tools in a live environment.

Cybersecurity Nexus (CSX) – Vulnerability and Exploitation Course (CVEC) Read More »