from Reuters: Technology News https://reut.rs/2LIftCs
Tesla names Oracle's Ellison to board, ending U.S. charges
from Reuters: Technology News https://reut.rs/2LIftCs
Tesla names Larry Ellison, Walgreens executive to board
from Reuters: Technology News https://reut.rs/2CEznv7
Dell debuts at $46 in return to market
from Reuters: Technology News https://reut.rs/2TaDiVK
Better Together with Check Point CloudGuard IaaS and AWS Transit Gateway
As enterprise cloud adoption on AWS accelerates, security remains a top of mind concern for many businesses. Traditional security approaches don’t fit with the dynamic nature of the cloud, leaving business exposed to a host of new threats. Especially now where deployments have a hybrid solution with workloads sitting in AWS as well as in the corporate datacenter, security needs to be rethought from an end to end perspective.
As a result, security teams require a few key capabilities to secure connectivity between workloads across AWS VPCs and from/to on-prem resources: 1. Cloud Perimeter Firewall – customers want to inspect all incoming traffic into the VPCs. 2. Inter-Tenant Inspection – for workloads communicating across VPCs, a security policy needs to be applied and traffic to allow for deep packet inspection 3. Internet Bound Inspection – for workloads communicating to the internet, traffic needs inspection before leaving the IGW. 4. Hybrid Cloud Protection – for workloads that need access on-prem DC, teams need to securely connect their VPC workloads to on-prem resources.
In this blog, we will discuss how the CloudGuard IaaS solution combined with AWS Transit Gateway, builds upon the existing Transit VPC design, and offers end to end protection for enterprise workloads sitting in AWS VPCs or in the corporate datacenter.
Current Security Architecture: Check Point CloudGuard within AWS Transit VPC
The existing Transit VPC design simplifies network management and minimizes the number of connections needed to connect multiple Amazon VPCs and remote networks. Using Check Point CloudGuard together with the Transit VPC, provides comprehensive security for cloud workloads and assets with VPC perimeter security services, seamless security segmentation between VPCs, and automatically established IPsec VPN connectivity between cloud environments. The solution automatically connects spoke VPCs to a central security hub VPC for seamless security inspection, VPN and NAT services.
The post Better Together with Check Point CloudGuard IaaS and AWS Transit Gateway appeared first on Check Point Software Blog.
from Check Point Software Blog http://bit.ly/2ESXW8Z
Tesla names two independent directors as part of SEC deal
from Reuters: Technology News https://reut.rs/2EQSm8d
Tesla names Larry Ellison, Kathleen Wilson-Thompson to board
from Reuters: Technology News https://reut.rs/2EVGmSO
We’re all Just Starting to Realize the Power of Personal Data
from Security Latest http://bit.ly/2ESKqlL
Yankees in talks with Amazon, Sinclair to bid for Yes Network: WSJ
from Reuters: Technology News https://reut.rs/2rZsY7v
Grab ordered to pay compensation to Vietnamese taxi firm
from Reuters: Technology News https://reut.rs/2SjjYWq
China says new financial information rules aimed at providers for institutions
from Reuters: Technology News https://reut.rs/2AlVXqL
Instagram 'back to normal' after bug triggers temporary change to feed
from Reuters: Technology News https://reut.rs/2GGdqja
Why it’s Time to Switch from Facebook Login to a Password Manager
Social media sites are increasingly the focus of our digital lives. Not only do we share, interact and post on platforms like Facebook —we also use these sites to quickly log into our favorite apps and websites. But what happens when these social media gatekeepers are hacked? Awhile back, Facebook suffered a major attack when hackers obtained the digital keys to access at least 30 million accounts (originally thought to be 50 million), exposing highly sensitive personal details.
The attack not only gave the bad guys access to the Facebook accounts but raised the prospect of them also being able to access any linked apps or websites. The message is clear: it may be time to store log-ins for these third-party accounts in a password manager, rather than a frequently targeted social media company.
What happened, exactly?
As a Facebook user, you’re probably well-aware of the ease-of-use benefit of logging-in to your third-party website and application accounts using your Facebook credentials. Known as Facebook Connect, this is what’s called a “Single Sign-On” feature: a fast, simple, and straightforward way to log in to your various accounts, so you don’t have to remember multiple different passwords for different sites and apps.
Convenient, eh? But here’s the problem. At the end of September (in 2018), Facebook discovered a major security issue: attackers managed to steal the crucial access tokens which act as “digital keys” to keep you logged into the site without having to re-enter your password each time you use Facebook. These keys also provide access to all those third-party applications and websites you log-in to via Facebook: everything from Airbnb and Amazon to Tinder and your favorite news apps. Since there’s a chance that the bad guys were also able to illegally access these, they may have been able to gather more of your sensitive info across these accounts to commit identity theft—and thereby gain access to your credit cards as well.
How did the hackers grab these all-important access tokens? By exploiting several bugs in Facebook’s “View As” and video posting features. (View As is a feature that allows users to see what their own profile looks like to someone else). They ultimately stole access tokens for 30 million users; accessed just name and contact details for 15 million; virtually all profile info including name, contact details, username, gender, language, relationship status, religion, etc. for 14 million; and no info at all for 1 million.
Facebook has been quick to point out that there are currently no signs the attackers did access any of third-party apps using Facebook SSO. However, that may change. It also doesn’t alter the fact that a similar incident like this, or worse, could happen in the future. Social media and web providers like Facebook are a major target for attackers, while human error will inevitably lead to some security mistakes in the future. A bug in Google’s code recently exposed the data of 500,000 users of its Google+ social platform, which has prompted their decision to shut down the consumer side of the site within the next 10 months (as of October 2018).
How can I stay safe?
Post-hack
Facebook has fixed the bugs in question and reset the access tokens of those affected by this breach, which should help to stop future attacks. However, if your account was illegally accessed in the attack, there are a few steps you should take:
|
|
Take preventative steps
After the above, consider the following options to keep all your accounts secure going forward:
|
|
Will it affect my use of Facebook?
If you disable Facebook SSO there may be some loss of sharing functionality. For example, you might find that you can’t post/share articles from within news apps direct to Facebook, and instead have to cut and paste the link manually. It will depend, however, on the apps you’re using. At the end of the day, you need to decide what’s more important to you: tighter integration between apps/websites and Facebook, or keeping your passwords in a separate, secure place away from the social media company.
How can Trend Micro help?
Trend Micro Password Manager can help you to protect the privacy and security of your app and website account passwords across PCs and Macs, and Android and iOS mobile devices. Use it as a highly user-friendly but more-secure alternative to Facebook SSO. Trend Micro Password Manager
|
|
For more information, or to purchase the product, go to our Trend Micro Password Manager website. Note that Trend Micro Password Manager is automatically installed with Trend Micro Maximum Security.
The post Why it’s Time to Switch from Facebook Login to a Password Manager appeared first on .
from Trend Micro Simply Security http://bit.ly/2Aifjx7
The Most-Read Security Stories of 2018
from Security Latest http://bit.ly/2rVI1iC
Tech firm Sigfox develops tiny tracker to help fight rhino poaching
from Reuters: Technology News https://reut.rs/2EQrkg5
Innogy to put electric vehicle business into separate company
from Reuters: Technology News https://reut.rs/2QS7uZd
Pan Am Flight 103: Robert Mueller’s 30-Year Search for Justice
from Security Latest http://bit.ly/2EMEbQB
Privacy Law Showdown Between Congress and Tech Looms in 2019
from Security Latest http://bit.ly/2ERLqYa
Exclusive: Foxconn to begin assembling top-end Apple iPhones in India in 2019 - source
from Reuters: Technology News https://reut.rs/2GKu7dp
Huawei expects 2018 revenue to rise 21 percent despite international scrutiny
from Reuters: Technology News https://reut.rs/2Skrz76
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...
-
Original release date: November 08, 2018 Summary JBoss Verify and EXploitation tool (JexBoss) is an open-source tool used by cybersecurity...
-
Original release date: May 21, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded b...
-
Original release date: January 29, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...
-
It's no secret that learning how to code is one of the most important things you can do when it comes to the beginning or furthering pra...
-
Original release date: February 12, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Original release date: February 26, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Os estragos causados pelo ataque com ransomware ao Superior Tribunal de Justiça (STJ) ainda não são totalmente conhecidos. A Polícia Federa...
-
Original release date: March 9, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In som...
-
Original release date: October 26, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In...
-
Original release date: January 08, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...