Posts

Expect Behavioral Analytics to Trigger a Consumer Backlash

Image
In the coming years, organizations’ insatiable desire to understand consumers through behavioral analytics will result in an invasive deployment of cameras, sensors and applications in public and private places. A consumer and regulatory backlash against this intrusive practice will follow as individuals begin to understand the consequences. Highly connected ecosystems of digital devices will enable organizations to harvest, repurpose and sell sensitive behavioral data about consumers without their consent, with attackers targeting and compromising poorly secured systems and databases at will. Impacts will be felt across industries such as retail, gaming, marketing and insurance that are already dependent on behavioral analytics to sell products and services. There are also a growing number of sectors that will see an increased dependency on behavioral analytics, including finance, healthcare and education. Organized criminal groups, hackers and competitors will begin stealing and...

Expect Behavioral Analytics to Trigger a Consumer Backlash

Image
In the coming years, organizations' insatiable desire to understand consumers through behavioral analytics will result in an invasive deployment of cameras, sensors and applications in public and private places. A consumer and regulatory backlash against this intrusive practice will follow as individuals begin to understand the consequences. Highly connected ecosystems of digital devices will enable organizations to harvest, repurpose and sell sensitive behavioral data about consumers without their consent, with attackers targeting and compromising poorly secured systems and databases at will. Impacts will be felt across industries such as retail, gaming, marketing and insurance that are already dependent on behavioral analytics to sell products and services. There are also a growing number of sectors that ...

Holding public cloud security to account

Image
At one of the last cyber-security events I attended before the Covid-19 enforced lockdowns, I was talking with an IT director about how his organization secures its public cloud deployments. He told me: “We have over 500 separate AWS accounts in use, it helps all our development and cloud teams to manage the workloads they are responsible for without crossover or account bloat, and it also makes it easier to control cloud usage costs: all the accounts are billed centrally, but each account is a separate cost center with a clear owner.” I asked about security, and he replied that each AWS account had different logins, meaning fewer staff had access to each account, which helped to protect each account. While it’s true that having hundreds of separate public cloud accounts will help to keep a closer eye on cloud costs, it also creates huge complexity when trying to manage the connectivity and security of applications and workloads.  Especially when making changes to applications ...

No Silver Bullet for Addressing Cybersecurity Challenges During Pandemic

Image
Infosec professionals have always had their work cut out for them, as the threat landscape continuously challenges existing security measures to adapt, improve and cope with the unexpected. As the coronavirus pandemic forced organizations to migrate their entire workforce to a work-from-home context, practically overnight, security professionals faced a new challenge for which half of them had not planned. A recent Bitdefender survey reveal that 83 percent of US security and IT professionals believe the COVID-19 pandemic will change the way their business operates, mostly because their infrastructure had to adapt to accommodate remote work. Another concern for companies is that employees tend to be more relaxed about security (34 percent) and that working remotely means they will not be as vigilant in identifying and flagging suspicious activity and sticking to security protocols (34 percent). Lessons learned Having managed the initial work-from-home technology transition challen...

Could the Twitter Social Engineering Hack Happen to You?

Image
Learning from the experiences of others should be a key job requirement for all cybersecurity, AppSec, DevSecOps, CISO, CRMO and SecSDLC professionals. The recent attack against Twitter where high-profile accounts were compromised to promote a Bitcoin scam is one such opportunity. As new information comes to light (and I sincerely hope that Twitter continues to provide meaningful details), everyone within the cybersecurity realm should look to both their internal IT and application development practices as well as those of your suppliers for evidence that this particular attack pattern couldn’t be executed against your organization. What we know as of now is that on July 15th, an attack was launched against Twitter that targeted 130 accounts . Of those 130, 45 had their passwords reset and eight had their Twitter data downloaded. While the initial public focus was on Twitter Verified accounts, those eight accounts were not verified. The attack itself was based on the concept of so...

Holding public cloud security to account

Image
At one of the last cyber-security events I attended before the Covid-19 enforced lockdowns, I was talking with an IT director about how his organization secures its public cloud deployments. He told me: "We have over 500 separate AWS accounts in use, it helps all our development and cloud teams to manage the workloads they are responsible for without crossover or account bloat, and it also makes it easier to control cloud usage costs: all the accounts are billed centrally, but each account is a separate cost center with a clear owner." I asked about security, and he replied that each AWS account had different logins, meaning fewer staff had access to each account, which helped to protect each account. While it's true that having hundreds of separate public cloud accounts will help to keep a closer...

Could the Twitter Social Engineering Hack Happen to You?

Image
Learning from the experiences of others should be a key job requirement for all cybersecurity, AppSec, DevSecOps, CISO, CRMO and SecSDLC professionals. The recent attack against Twitter where high-profile accounts were compromised to promote a Bitcoin scam is one such opportunity. As new information comes to light (and I sincerely hope that Twitter continues to provide meaningful details), everyone within the cybersecurity realm should look to both their internal IT and application development practices as well as those of your suppliers for evidence that this particular attack pattern couldn't be executed against your organization. What we know as of now is that on July 15th, an attack was launched against Twitter that targeted 130 accounts . Of those 130, 45 had their passwords reset and eight had their T...

No Silver Bullet for Addressing Cybersecurity Challenges During Pandemic

Image
Infosec professionals have always had their work cut out for them, as the threat landscape continuously challenges existing security measures to adapt, improve and cope with the unexpected. As the coronavirus pandemic forced organizations to migrate their entire workforce to a work-from-home context, practically overnight, security professionals faced a new challenge for which half of them had not planned. A recent Bitdefender survey reveal that 83 percent of US security and IT professionals believe the COVID-19 pandemic will change the way their business operates, mostly because their infrastructure had to adapt to accommodate remote work. Another concern for companies is that employees tend to be more relaxed about security (34 percent) and that working remotely means they will not be as vigilant in identifying an...

Dota 2 - Aghanim's Labyrinth Update - July 30, 2020

Image
General - The next of Aghanim's Trials will be set to Grand Magus ascension level - Fixed a bug where passives would sometimes not update their values from upgrades immediately Ursa - Earthshock bonus damage upgrade increased from 75 to 100 - Fixed Relentless stacks getting wiped by re-casting Overpower - Relentless: stacks gained increased from 1 to 2 - Ursa Minor: Cubs' Fury Swipes damage increased from 20% to 25% - Fixed Ursa being able to get permanent Concealed Weaver - Fixed Weaver being able to reduce Swarm's attack interval to near zero Several Encounters have had their difficulty adjusted down - The Malorkian Hammers - An Unwinnable Standoff - The Soothing Sounds of Sirens Several Encounters have had their difficulty adjusted up - The Beastly Babies - Rizzrick the Razorsaw - A Bad Trading Post via Steam RSS News Feed "https://ift.tt/3jPO0PI"

Dota 2 - Aghanim's Labyrinth Update - July 24, 2020

Image
General - The next of Aghanim's Trials will take place on Sorcerer. - The damage and health of enemies in Sorcerer and Grand Magus Act 1 / 2 now ramp up more slowly, better matching the curve in Apprentice and Magician (Act 3 unchanged). - Many common and elite shards with low selection or efficacy rates have had their values increased or been removed (i.e. Witch Doctor 5% evasion, many mana cost shards) - Fixed a bug where Viper and Magnus could get multiple ultimate ability upgrade options in the starting room - Trap room treasure chests and the items they drop are removed if they are not picked up when the encounter completes - Improved behavior when units like grumpy ogre seals bounce out of the level - Boots of Travel: increased bonus move speed 32 -> 90 - Fixed several cases where enemies would not aggro on damage. - Gary's armor now increases per ascension level. - Time before creatures detect invisible players increased from 2.5 to 5 minutes - Time before...

Dota 2 Update - July 20, 2020

Image
Bug Fixes: - Fixed being able to use abilities and items in the Rolling In Riches Bonus Room. - Flight is now disabled upon entering Trap rooms. - Fixed Voodoo Restoration's Mana Cost upgrade increasing the mana cost. - Fixed a case where players could die to Astral Step after The Shadow of Inai was defeated. - Fixed players being able to die in the Aghanim victory sequence by dodging the invulnerability period with Eul's Scepter. - The Tusk Walrus Wallop upgrade can no longer move Rizzrick. - Fixed Witch Doctor's Death Ward being killable in some cases. - Fixed Witch Doctor's Max Health Voodoo Restoration talent affecting Aghanim with Hocus Pocus. - Fixed a case where Aghanim could be instantly killed by Winter's Curse. - Fixed a server crash with Raisin Firesnaps. Map Changes: - Nav fixes for A Mind-Tingling Offer, Arrows Of The Moon, The Pugilist Pixies of Plague Wood, Manipulators of Time and Space, Mister Cleaver, The Soothing Sound of Sirens, The...

Now Available on Steam - Soviet Jump Game

Image
Soviet Jump Game is Now Available on Steam! Snag powerups, collect coins, and battle against 49 other comrades in this 2D sidescrolling free-for-all. Together, we are one--but will you be the one who is held above all others? via Steam RSS News Feed "https://ift.tt/394CHyo"

Dota 2 Update - July 16th 2020

Image
- Fixed a bug with Bloodrage that caused it to do more damage to yourself than intended via Steam RSS News Feed "https://ift.tt/2WpLx4F"

Portal 2 Authoring Tools - Update

Image
An update has been released for Portal 2 Authoring Tools. - Fixed the Publishing Tool failing to display any workshop item with an ID too large to fit into 32 bits. via Steam RSS News Feed "https://ift.tt/397T39v"

Left 4 Dead 2 Authoring Tools - Update

Image
An update has been released for the Left 4 Dead 2 Authoring Tools. - Fixed the Workshop Manager failing to display any workshop item with an ID too large to fit into 32 bits. via Steam RSS News Feed "https://ift.tt/305tyBx"

Portal 2 - Update

Image
An update has been released for Portal 2. - Fixed issue with recent workshop maps that prevented voting on them or advancing past them in the quick queue. - Fixed workshop map thumbnails not loading in the community map voting dialog. - Removed workshop map download limits for subscribed maps introduced in the last update, and increased the limit for the history queue to 500 by default. The history queue size is also now a convar, cm_max_history_chambers, so it can be increased if desired. via Steam RSS News Feed "https://ift.tt/2BLvjM7"