admin

Timelines for migration to post-quantum cryptography

The transition to Post-Quantum Cryptography (PQC) mirrors many significant technology migration projects. The main objective is to seamlessly integrate PQC into existing systems while minimizing new cyber security threats. Hence, comprehensive planning at the outset is crucial. Organizations may adopt various models for successful technology migration, with each having its unique framework. Regardless of the…

Read More

Passkeys: the promise of a simpler and safer alternative to passwords

In today’s digital landscape, accessing various online services including messaging, shopping, travel, social media, media streaming, and government resources typically requires managing yet another account and password. Concurrently, there is a rising trend of cyber criminals attempting to hijack online accounts for their illegal gain, often at the expense of users. Safeguarding these account passwords…

Read More

Cyber Security and Resilience Policy Statement to strengthen regulation of critical sectors

As the Director of National Resilience at NCSC, the announcement of a Cyber Security and Resilience Bill in July 2024 by the government was a pivotal step towards addressing the increasing cyber threats to essential services, including water, power, and healthcare. Today, we appreciate the publication of the Department of Science, Innovation and Technology’s (DSIT)…

Read More

Protective DNS for the private sector

This guidance targets private sector organizations that do not qualify to utilize the NCSC’s Protective DNS (PDNS). If your organization does qualify for the NCSC’s PDNS, note that a commercially procured protective DNS service is not a suitable alternative. Reasons to Implement Protective DNS Protective DNS (PDNS) systems block access to malicious domains attempted by…

Read More

New guidance on securing HTTP-based APIs

APIs (application programming interfaces) play a crucial role across various industries, spanning social media, finance, healthcare, and telecommunications. They enable effective data exchange between different systems and services. However, the growing reliance on APIs opens the door for attackers who look to exploit potential vulnerabilities in their design and implementation. Recent high-profile security breaches involving…

Read More

Italy’s Data Protection Watchdog Issues €15m Fine to OpenAI Over ChatG

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has imposed sanctions on OpenAI due to violations of data protection laws related to the ChatGPT chatbot. OpenAI is required to pay a fine of €15 million (approximately $15.6 million) and undertake a six-month public awareness initiative throughout Italian media. This campaign aims…

Read More

Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits

Vulnerability / Network Security Fortinet has issued an advisory regarding a recently patched critical security vulnerability affecting its Wireless LAN Manager (FortiWLM), which poses a risk of exposing sensitive information. This vulnerability, identified as CVE-2023-34990, has been rated with a CVSS score of 9.6 out of 10, indicating a severe threat level. “A relative path…

Read More

Critical Apache Struts flaw under active exploit

A significant security vulnerability in Apache Struts 2 was addressed last week, but it is currently being exploited with publicly available proof-of-concept (PoC) code. Struts is a widely used Java-based web application framework, favored by large corporations and government institutions. Issues in this open-source framework can have severe consequences, reminiscent of the Equifax breach in…

Read More

Microsoft revamps how it will disclose vulnerabilities

Dive Brief Microsoft is enhancing its vulnerability disclosure process by adopting the Common Security Advisory Framework (CSAF), enabling organizations to more efficiently prioritize and remediate CVEs (Common Vulnerabilities and Exposures). This machine-readable format allows for faster and higher volume processing of CVEs, while customers can still access updates through the Microsoft security update guide or…

Read More
Back To Top