Chrome Zero Day Vulnerability Noticed on Halloween

https://www.zdnet.com/article/halloween-scare-google-discloses-chrome-zero-day-exploited-in-the-wild/ ZDNet points out that Google Chrome has a Zero-day vulnerability – which means you cannot patch or fix your Chrome Browser. The above image is from a Mac Chrome browser, thus I want to make sure you know any Chrome browser (including on Android or IPhone as well). I have discussed Zero-Day vulnerabilities before … Read more

New PCI – Payment Card Industry Standards in 2019

A new Secure Software Requirements and Assessment Procedures was released v1.0 on Jan 2019. So if you are developing software for the Payment card industry either for an application on a website or for a retail location you have a new framework and software requirements standard. Developing software to capture credit card information (and use … Read more

IoT, IT and OT Merging and Needs Integrated Defense

First of all what is the alphabet soup: IoT, IT and OT? Internet of Things, Information Technology, Operational Technology are explained best in the sans.org white paper: https://ics.sans.org/media/IT-OT-Convergence-NexDefense-Whitepaper.pdf Operational Technology (OT) consists of hardware and software systems that monitor and control physical equipment and processes, often found in industries that manage critical infrastructure, such as … Read more

Stopping Social Engineering Attacks No, Slow Down Yes!

Elements of an Attack: From the article at TechNewsWorld. Social Engineering is equivalent to scammers trying all types of methods to gain information or money. What does it mean to have an image above that shows many possible Social engineering attacks? Let’s list them: Techniques Phishing Pretexting Baiting Quid Pro Quo Compliance principles Friendship or … Read more