Remove vulnerabilities-threats vulnerability-management-isn-t-just-a-numbers-game
article thumbnail

Supply Chain Security 101: An Expert’s View

Krebs on Security

— had allegedly inserted hardware backdoors in technology sold to a number of American companies. — had allegedly inserted hardware backdoors in technology sold to a number of American companies. It seems like a pretty big threat, but also one that is really hard to counter. National Security Agency. TS: Exactly.

Security 203
article thumbnail

The Hacker Mind: Shattering InfoSec's Glass Ceiling

ForAllSecure

She’s an amazing person who has done an amazing number of things in a short amount of time -- CMU professor, Forrester analyst, CSO at a successful startup -- and she’s not done changing the industry. I said sure, then realized I didn’t know the first thing about computer viruses. That is, until Chenxi Wang spoke up.

Cloud 40
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

The Hacker Mind Podcast: Hacking Diversity

ForAllSecure

For many, though, that isnt true. This is a generality of course there are exceptions, but even today there are just not enough exceptions. At a time when organizations are dealing with the SolarWinds breach and a persistent threat of ransomware throughout the world. Vamosi: When I was last looking for a new job.

article thumbnail

The Hacker Mind Podcast: Hacking Diversity

ForAllSecure

For many, though, that isnt true. This is a generality of course there are exceptions, but even today there are just not enough exceptions. At a time when organizations are dealing with the SolarWinds breach and a persistent threat of ransomware throughout the world. Vamosi: When I was last looking for a new job.

article thumbnail

The Hacker Mind Podcast: Hacking Ethereum Smart Contracts

ForAllSecure

Yannis Smaragdakis , a researcher with Dedaub , found a major vulnerability in Ethereum smart contracts, arguably within the billion-dollar range, that would have made it one of the largest hacks ever—given that it was a theoretically unbounded threat -- had it not been mostly mitigated by the time it went public.

article thumbnail

The Hacker Mind Podcast: Incident Response in the Cloud

ForAllSecure

There are servers that you don’t. MUSIC] VAMOSI: If you haven’t been paying attention, cloud security is critical right now. It simply doesn’t work to say that you can take your existing security and port it into the cloud. There are the servers you control. So I decided to ask an expert.

Cloud 40
article thumbnail

LAPSUS$ Cyber Crime Spree Nabs Microsoft, Okta, NVIDIA, Samsung

eSecurity Planet

The LAPSUS$ threat group has had an attention-grabbing month, snaring high-profile victims like Microsoft, Okta , NVIDIA, Samsung and others. ” In a short amount of time, LAPSUS$ has collected a substantial number of victims — and shows no signs of stopping. Mid-March, popular game developer Ubisoft reported a data breach.