Quick pick

NIS2

NIS2

11 posts
ISO 27001

ISO 27001

19 posts
AI & ML

AI & ML

7 posts
SSDLC

SSDLC

13 posts
Spam & Phishing

LinkedIn phishing ? Think again…

When you see such an email, you don’t think that it is a phishing… After all, why would anyone steal your LinkedIn credentials, right? Nobody would request a ransom to give your credentials back, nobody would steal your email & password and try to reuse them on other websites. You have, after all, read my […]

Security

Classical Antivirus is dead.Long live EDR?

We recall last year’s article in WSJ  quoted executives from antivirus pioneer Symantec declaring antivirus software “dead” and stating that the company is focusing on developing technologies that attack online threats from a different angle. I also wrote about it here: http://www.sorinmustaca.com/2014/05/08/is-antivirus-really-dead-it-depends-what-you-call-antivirus/   Now the new concept has a name: Endpoint Detection and Response (EDR). Kelly Jackson Higgins, […]

Antivirus Automotive Security

As expected: the USB Stick-like infection from PCs goes to automotive as well!

Just seen this article on Wired Magazine: Car Hack Technique Uses Dealerships to Spread Malware At the Derbycon hacker conference in Louisville, Kentucky last week, security consultant Craig Smith presented a tool designed to find security vulnerabilities in equipment that’s used by mechanics and dealerships to update car software and run vehicle diagnostics, and sold by […]

News

WinRAR: The wrong way of answering to a critical vulnerability

With over 500 million users worldwide, WinRAR is by far the most popular compression program. An independent security lab found a remote code execution vulnerability in the official WInRAR SFX v5.21 software. The vulnerability allows remote attackers to unauthorized execute system specific code to compromise a target system. The issue is located in the Text […]