Medical device security improvements coming—but not anytime soon

Medical device security improvements coming—but not anytime soon

| | healthcare security
This article was originally published in Forbes. The cybersecurity of connected medical devices—notoriously poor for decades—should finally start to improve. That is genuinely good news. But it is tempered by the reality that it will not happen quickly. The long-overdue change is coming thanks to the federal Food and Drug ... Read More
CamuBot malware, SonarSnoop hacking and government backdoors | Synopsys

CamuBot malware, SonarSnoop hacking, and government backdoors

Taylor Armerding, Synopsys Software Integrity Group senior strategist, gives you the scoop on application security and insecurity in this week’s Security Mashup. What’s in this week’s Security Mashup, you ask? CamuBot malware is the new kid on the block, the sounds of hacking (SonarSnoop), and back to the government’s wish ... Read More
Gmail Confidential? Not so much

Gmail Confidential? Not so much

| | FEATURED, Privacy
According to privacy advocates, Google has a problem with truth in labeling. No, not about its surreptitious tracking of users who have turned their Location History off, which has sucked up most of the headline space over the past few weeks. This is about the rollout of their allegedly “confidential” ... Read More
Fixing the CVE program, your personal data checking out and taking flight | Synopsys

Fixing the CVE program, your personal data checking out and taking flight

Taylor Armerding, Synopsys Software Integrity Group senior strategist, gives you the scoop on application security and insecurity in this week’s Security Mashup. What’s in this week’s Security Mashup, you ask? Fixing the CVE program, your personal data has already “checked out,” and it even “may potentially” have taken flight. Watch ... Read More
These hacks brought to you by ‘leaky’ APIs

These hacks brought to you by ‘leaky’ APIs

“Leaky” is almost never a good thing. The whole idea, in just about any case, is to make things that don’t leak and to plug things that do. And that’s true of cyber security, as demonstrated by a couple of recent incidents involving leaky APIs (application programming interfaces). Hacked at ... Read More
SamSam ransomware keeps striking—victims still unprepared

SamSam ransomware keeps striking—victims still unprepared

“You can pay (a little) now or you can pay (a lot) later” is a very old line—a pitch for oil filters almost 40 years ago. Unfortunately, it remains relevant in cyber security, especially when it comes to ransomware. And especially when that ransomware is the potent, pernicious SamSam. The ... Read More
A test hack, don't let Ghostscript haunt you, and a helpful hacker | Synopsys

A test hack, don’t let Ghostscript haunt you, and a helpful hacker

Taylor Armerding, Synopsys Software Integrity Group senior strategist, gives you the scoop on application security and insecurity in this week’s Security Mashup. What’s in this week’s Security Mashup, you ask? Not a real hack, but maybe a test hack, don’t let Ghostscript haunt you, and a helpful hacker. Watch this ... Read More
Survey: Data management is an afterthought in cloud migration

Survey: Data management is an afterthought in cloud migration

Moving virtualized workloads to the cloud is either a reality or a near-term goal for an overwhelming majority—90%—of 170 organizations surveyed during July and August by Druva, a cloud data management and security company. But the forecast for the security and management of company data in that setting is, well, ... Read More
How to help your medical devices meet the UL (and FDA) standard

How to help your medical devices meet the UL (and FDA) standard

Any effort to overhaul the cyber security of connected medical devices is likely to take considerable time and energy. Given that many of them are made to last decades, securing them while they’re in use can make turning an ocean liner look positively nimble. Still, the announcement last month by ... Read More
Black Hat USA 2018 Keynote: Parisa Tabriz

Project Zero director exhorts Black Hat audience to do security better

Google’s famous “Don’t be evil” motto got a corollary this week at Black Hat from Parisa Tabriz, director of engineering for the company’s Project Zero: “Do things better.” “We have a responsibility to do things better. Computer security is becoming the security of the world,” she said during her Wednesday ... Read More