In this informative blog, McAfee experts weigh in on the processes, legislation, and requirements that affect every company’s risk and compliance posture. From audits to reporting, this blog helps you keep up to date on issues and advancements, and informs you of the latest McAfee risk and compliance product updates.
Late last week, reports began to surface that the Israeli police (along with other regional law enforcement) were targeted by a malware attack. The entry vector was described as a phishing campaign sent from Benny Gantz (head of the Israeli Defense Forces). Initially, details and indicators around the malware were beyond sparse. Aside from the FROM: address, Read more…
Tags: antivirus, Cyber Security Mom, Endpoint Protection, global threat intelligence, internet security, Israel, labs, malware, McAfee Labs, Network Security, phishing, security, spam, ValidEdge, web protection, XtremeRAT
News broke today of a large data breach against Yahoo Voices, resulting in more than 400,000 username/password combinations being posted in clear text. The compromise involved a basic SQL-injection attack against an exposed Yahoo server (dbb1.ac.bf1.yahoo.com). Similar to other recent events, the account data was reportedly stored in an unencrypted state. We see this type of attack Read more…
Tags: Database, sql attacks, SQL Injection, Yahoo!
See March 15 and 16 updates at the end of this blog. —————————————————- The March Security Bulletin release from Microsoft was relatively light in volume. Out of the six bulletins released, only one was rated as Critical. And for good reason. MS12-020 includes CVE-2012-0002. This flaw is specific to the Remote Desktop Protocol (RDP) present on Read more…
Tags: Cyber Security Mom, Cybercrime, data breach, Data Protection, Endpoint Protection, enterprise, global threat intelligence, labs, malware, McAfee Labs, Microsoft Security Bulletin, MS12-020, Network Security, Risk and Compliance
In early April, I wrote about the famed “LizaMoon” SQL-injection attacks. I said it then, and I’ll say it again now: SQL-injection (SQLi) attacks are a constant. Some of these attacks are more visible than others. Some adversaries find intelligent ways to hide their tracks so as not to splatter evidence of their misdeeds all over various search Read more…
Tags: Cybercrime, Data Protection, database security, enterprise, lizamoon, malware, mass sql injection, Network Security, sql attacks, SQL Injection, urchin.js
I am excited to share that McAfee has officially announced its intent to acquire privately owned NitroSecurity. NitroSecurity is a leading provider of security information and event management (SIEM) solutions that offers complete visibility and situational awareness to protect critical information and infrastructure. With NitroSecurity’s technology and talent, McAfee can expand its reach into the fast Read more…
Visit any news site on the Web, and undoubtedly you’ll come across a barrage of articles publicizing the details of yet another data breach. With the prominence of SQL injection attacks, and malicious insiders and hackers exploiting sensitive data stored on unpatched and vulnerable databases, enterprise organizations have found themselves reevaluating their security strategies. Following Read more…
If we look at the evolution of hacking, certain techniques never go out of style, but we’re at the beginning of a big shift in terms of the targets. The threat landscape has evolved beyond PCs, tablets, and smartphones to a whole new battleground: connected devices all around us. According to Ericsson, there will be Read more…
Tags: black hat hackers, cyber attack, embedded, Hacking Exposed, Risk and Compliance, security, white hat hackers
Every week we see similar stories permeating the news – large enterprises falling victim to data breaches and finding themselves at the mercy of hackers looking to access and exploit sensitive customer data for personal or monetary gain. The impact of just one of these events can be devastating; for large enterprises, the short-term effect Read more…
Tags: data breach, enterprise, risk, security, SMB
The recent security breach at Lockheed Martin confirmed that the attacks we saw with Operation Aurora, identified by McAfee, and Stuxnet are just the beginning of a new era of targeted attacks. Cybercriminals are now executing the perfect plan to get closer to their target without raising any red flags. In the case of Operation Read more…
Tags: Lockheed Martin, malware, Night Dragon, Operation Aurora, Stuxnet, targeted attacks, Whitelisting, Zero-Day
Advanced persistent threats like we’ve seen with Stuxnet and Night Dragon target the manufacturing and process industry, including national critical infrastructure. The industrial revolution started our reliance on automation. However as the industry became more integrated, modular and adaptable to broader industrial processing it also grew more vulnerable and susceptible to attack. Adding further complication Read more…
Tags: Advanced Persistent Threat, critical infrastructure, data breach, McAfee Application Control
Posts in Risk Compliance