via IFTTT After its 2015 breach, the Information Commissions Office (ICO) has released a very thorough report which highlights a number of deficiencies in Carphone Warehouse's security. I've summed up some of the key points in dramatic fashion The report well worth a read: http://ift.tt/2AM6B7B
Author: j4vv4d
Uncybered
It dawned on me, that I've never written a browser extension before. And there are words IT Security articles continually overuse that I wish they wouldn't. So, I combined both these together and wrote a chrome extension that would change commonly misused words to something a little more interesting. Examples: - IoT becomes 'cheap connected … Continue reading Uncybered
M&A Mania
2018 has kicked off with a flurry of M&A activity in the infosec space. There have been four that I've been aware of, Barracuda acquired Phishline Cyxtera acquired Immunity Inc Verizon acquired Niddel Threatcare acquired Savage Security I wonder how many more deals will be announced between now and RSA. Either way, it looks like … Continue reading M&A Mania
10 infosec conversation starters
I recently had my 17 anniversary... which is almost as long as I've been working in information security. Information security is great for communication, and communication is great for all relationships and friendships.
Exploiting browser password logins
The cool researchers over at freedom to tinker found two scripts that exploit browsers built in login managers to retrieve and exfiltrate ID’s. Below is the email I sent, and the reply from OnAudience The script that OnAudience uses can be found here if you have time, check out this tweet thread between … Continue reading Exploiting browser password logins
Threatcare secures $1.4m seed funding
Threatcare has announced a $1.4m seed round led by Moonshots Capital and includes Flyover Capital and Firebrand Ventures. The Austin-based company was founded in 2014 by CEO Marcus Carey. Its flagship product, Violet, is a SaaS-based offering that enables continuous security validation through attack simulations. For many security departments, the question they are often faced … Continue reading Threatcare secures $1.4m seed funding
Meltdown
If everyone and their dog is talking about Meltdown and Spectre, then it would be negligent of me to not keep up with all the cool kids. Website for the vulnerabilities: Meltdown Attack Google Project Zero blog NCSC's advice Linus Torvalds statement
Security Terminology
Work for long enough in one industry for any period of time and you end up speaking an entirely language altogether. This isn’t necessarily a bad thing, in many cases it’s convenient and allows rapid communication amongst peers. However, in Information security we need to be mindful when communicating with non security, or even non … Continue reading Security Terminology
Welcome to 2018
I thought I'd kick off the new year by poking around the news stories, surely not much could have happened. But quite a lot did unfortunately. In the video are the top 3 stories or headlines that caught my attention, but more importantly, I think we should make a pact to stop using these buzzwords … Continue reading Welcome to 2018
Analyst Vendor Briefings
Fuelled by a twitter conversation both Adrian Sanabria and Anton Chuvakin posted articles here and here, sharing some good tips on what makes a good briefing and common pitfalls to avoid. As a former (recovering?) analyst, I thought it only right that I jump on the bandwagon and share my thoughts on the topic. What … Continue reading Analyst Vendor Briefings
