• DDoS Attacks Abuse TFTP for Reflection and Amplification

    Several months ago, security researchers at Edinburgh Napier University published a paper on a distributed denial of service (DDoS) reflection and amplification method leveraging the TFTP (Trivial File Transfer Protocol) protocol, and security researchers at Akamai now warn of real-life attacks leveraging this technique.read more
  • Nvidia may finally bring desktop-grade graphics to laptops

    Nvidia may finally bring desktop-grade graphics to laptops
    According to PC Gamer , Nvidia is planning to release versions of its top-end 1000-series graphics cards that will work in gaming laptops. These aren't some pansy, watered-down "M" version either: they'll be the same chips as the desktop-grade 1080 and 1070 , running at slightly lower power. In other words, desktop-level graphics performance in a portable, battery-powered device. That would be big. DON'T MISS:  Hackers are using remote-control software Teamviewer to hijack PCs and drain Pay
  • Legendary Apple marketing guru believes Apple has ‘lost its way’

    Legendary Apple marketing guru believes Apple has ‘lost its way’
    Writing for The Guardian , longtime Apple marketing guru Ken Segall argues that Apple, in the absence of Steve Jobs, has lost its way . Whereas the company previously harnessed the "power of simplicity" to deliver products and services that were intuitive and easy to use, Segall argues that the "simplicity" that previously defined Apple has waned in recent years. While critiques of Apple are a dime a dozen these days, Segall is certainly a voice worth paying attention to. A close confidant of St
  • U.S. lawmakers probe Fed cyber breaches, cite 'serious concerns'

    U.S. lawmakers probe Fed cyber breaches, cite 'serious concerns'
    By Dustin Volz and Jason Lange WASHINGTON (Reuters) - A U.S. congressional committee has launched an investigation into the Federal Reserve's cyber security practices after a Reuters report revealed more than 50 cyber breaches at the U.S. central bank between 2011 and 2015. The House Committee on Science, Space and Technology on Friday sent a letter to Federal Reserve Chair Janet Yellen to express "serious concerns" over the central bank's ability to protect sensitive financial information. The
  • Advertisement

  • Why Google Home has a lot of catching up to do

    Why Google Home has a lot of catching up to do
    Amazon is quietly shaping the future of computing. The giant retailer created a popular voice-and cloud-based virtual assistant that’s smart enough to perform certain tasks and provide answers to our queries. Amazon doesn’t do voice better than Apple or Google, but Amazon nonetheless created a tool that made it easier for humans to talk to a machine . Google announced Home , a direct competitor for Amazon’s Echo , and Apple is rumored to introduce a similar device in the near f
  • Ransomware hits 10K Australians

    Ransomware hits 10K Australians
    At least 10,000 Australians have been targeted in a ransomware campaign that lures recipients with an email purportedly from local energy company AGL.
  • Malware Uses Clever Technique to Hide DNS Changes

    Several pieces of malware and adware have been observed using a clever technique to hide the changes they make to the DNS settings of infected devices, ESET reported on Thursday.
    read more
  • Guilty pleas for two spammers behind heist of 60M accounts

    Guilty pleas for two spammers behind heist of 60M accounts
    Guilty pleas were entered by two men for a range of computer fraud charge said to have netted $2 million in ill-gotten gains.
  • Advertisement

  • Setting the Record Straight on Cyber Threat Intelligence

    Threat intelligence has achieved buzzword status. The good news behind that is people are talking about it - it is a critical component of a cyber risk management program. The bad news is too many folks have distorted and confused the term, so much so that it’s meaning varies widely depending with whom you’re speaking.
    read more
  • Thousands of UK Enterprise Logins Found on Dark Web

    Fake domains that are only slightly different from the domain of a legitimate company are often leveraged in attacks, and researchers at Anomali recently discovered that cybercriminals abused this technique to target companies in the Financial Times Stock Exchange 100 (FTSE 100).read more
  • When Ransomware Hits Healthcare: To Pay or Not to Pay?

    A new report from theat intelligence firm Flashpoint highlights dark web discussion over targeting hospitals with ransomware - and demonstrates a surprising contrast in opinion. Not all criminals agree with the concept. The problem is it takes only one to disagree.
    read more
  • Ransomware-as-a-Service Lets Anyone be a Cybercriminal

    Flashpoint, a threat intelligence firm that studies the so called 'Deep and Dark Web', has spent five months studying an organized Russian ransomware campaign. It concludes that ransomware is joining other cyber criminal activities by becoming a service - in this case, 'ransomware-as-a-Service'. This particular campaign uses the proven business affiliate model.
    read more
  • Financial Compliance: Problems are Changing, Solutions are Not

    The sixth annual survey from Smarsh on financial services communications compliance issues shows that regulatory scrutiny and compliance difficulties are increasing while resources and solutions are not.
    read more
  • Huawei is making another Nexus phone

    Huawei is making another Nexus phone
    Android fans are eagerly waiting for Android N to come out, as that means new Nexus hardware is due. Multiple reports said this year that HTC will build no less than two devices for Google , with some rumors even claiming that the Taiwanese smartphone maker has scored some sort of Nexus exclusivity deal for the coming years. That doesn’t seem to be the case, as Huawei just seemed to confirm that it’s working on at least one more Nexus-branded device after last year’s Nexus 6P .
  • Data of 40,000 Stamford Podiatry Group patients compromised

    Data of 40,000 Stamford Podiatry Group patients compromised
    Connecticut-based Stamford Podiatry Group is notifying its patients that medical and personal information was compromised in a recent security incident.
  • Ukrainian president condemns leak of journalist data

    Ukrainian president condemns leak of journalist data
    Ukrainian President Petro Poroshenko on Friday condemned the leak of the names and contact information for thousands of journalists who have reported from rebel-controlled eastern Ukraine. The May publication ...
  • QLess’ Bäcker: Company can resolve TSA wait times in 90 days

    Top Priority Sector: access_control_identificationImage Caption: Bäcker PASADENA, CA June 2, 2016Homepage position: 1read more
  • TSA exercises option on RELM's P25 contract

    Top Priority Sector: communicationsImage Caption: StoreyWEST MELBOURNE, FL June 2, 2016RELM Wireless Corporation (NYSE MKT: RWC) today announced that the Transportation Security Administration (TSA) of the U.S. Department of Homeland Security has exercised a portion of the first option year for its contract with RELM, and placed an order for additional equipment and services totaling approximately $1.9 million.Also, the contract term has been extended for one additional year to Septemb
  • Hershman named new CEO of global sports security organization

    Top Priority Sector: security_servicesImage Caption: HershmanDOHA, Qatar, June 2, 2016The International Centre for Sport Security (ICSS) has announced the appointment of Michael Hershman, co-founder of Transparency International, as Group CEO.A globally-respected and highly-decorated leader in the fields of transparency, governance, litigation and security, Mr Hershman joins the ICSS, as it marks its fifth year, to lead, develop and strengthen the organization to best serve sport in th
  • Michigan 9-1-1 systems taking advantage of Rave’s chat system to help those in immediate danger

    Top Priority Sector: communicationsFRAMINGHAM, MA June 1, 2016Rave Mobile Safety, the trusted creator of innovative public safety data and communication software, today announced that 9-1-1 telecommunicators across the state of Michigan are regularly using Smart911Chat to text with callers who are in immediate danger and unable to speak on the phone. This ability is proving critical in helping rescue victims of domestic assault, home invasions, individuals in poor cellular coverage areas, p
  • NOBLE President to speak at Phoenix forum

    Top Priority Sector: law_enforcement_first_respondersImage Caption: ThomasALEXANDRIA, VA June 1, 2016National Organization of Black Law Enforcement Executives' (NOBLE) National President, Gregory A. Thomas, is set to be a featured panelist at the 2nd Annual Bridge Forum in Phoenix, AZ (TheBridgeForum.com) on Thursday, June 2nd at the Crowne Plaza, Phoenix.Homepage position: 1read more
  • Mexican airline receives TSA approval for PreCheck

    Top Priority Sector: airport_aviation_securityMEXICO CITY, June 1, 2016Aeromexico, Mexico's global airline, announced on May 21, that it became the first airline in Latin America authorized by the Transportation Security Administration (TSA) to join the program that provides expedited screening for low-risk passengers, and that will allow Aeromexico customers to enjoy a better travel experience on flights from any airport in the United States to any airport in Mexico.Homepage position: 
  • Almost half of ‘Star Wars: Rogue One’ will need to be reshot

    Almost half of ‘Star Wars: Rogue One’ will need to be reshot
    That's the latest news regarding the status of Rogue One: A Star Wars Story , which has been making headlines all week after a report from Page Six claimed that Disney executives weren't satisfied with the first cut of the spinoff film. SEE ALSO:  Matt and Kim just released one of the best music videos of 2016 In the original report , sources told Page Six that Rogue One would need significant revisions after failing to connect with audiences in test screenings. Deadline and The H
  • Constructive Disclosure

    Constructive Disclosure
    This is going to be a bit different from my usual blog postings but I think the time is good for this discussion for several reasons. First, the notion of constructive and responsible disclosure of bugs is a clear issue for threat hunters.
  • Baby seals are being killed by ‘sealfies’ because humanity is awful

    Baby seals are being killed by ‘sealfies’ because humanity is awful
    People are bad, Snapchat is awful, and selfies are the worst. Exhibit A: the federal government has had to issue warnings against taking selfies with baby seals, because it's causing seal pups to be abandoned and die. The National Oceanic and Atmospheric Administration (NOAA) has been forced to issue a specific warning against taking selfies with seal pups, an activity painfully known as a "sealfie." According to the 1,000-word blog post some poor federal employee had to write, there's
  • Card Data, Keystrokes Quickly Exfiltrated by FastPOS Malware

    Trend Micro researchers have come across a new point-of-sale (PoS) malware family that has been described as quick and efficient when it comes to exfiltrating harvested data.
    read more
  • Here are the funniest moments in Marvel movie history

    Here are the funniest moments in Marvel movie history
    It feels like Marvel has pumped out more movies than I can remember over the past few years. There's been a few serious misses, some great action, and a healthy dose of comedy along the way. This video from Screen Rant breaks down the funniest gags and scenes from the Marvel movie universe. DON'T MISS:  Hackers are using remote-control software Teamviewer to hijack PCs and drain PayPal accounts It's a great list that surfaces some gems I'd forgotten about.  Deadpool  was such a fu
  • Modern Mirror CEO reflects on security and privacy

    Modern Mirror CEO reflects on security and privacy
    Usually, it's up to a company's IT leaders to convince the CEO to invest in security and privacy. But at SC Congress Toronto, one CEO of an SMB said it was she who informed her corporate team that they needed to do more.
  • GE Patches Critical Flaw in Industrial Switches

    General Electric has released firmware updates for several of its MultiLink series switches to address a critical vulnerability that hackers could exploit to gain administrative access to devices.
    read more
  • Reeling in workers: Social engineering

    Reeling in workers: Social engineering
    When it comes to finding a scapegoat after a company falls victim to a spearphishing scam, pointing toward the human being in the room typically isn't unjustified or unfair.
  • Pakistan APT Group Targets Indian Government

    An advanced persistent threat (APT) group believed to be based in Pakistan has been observed targeting government and military personnel in India using spear phishing emails and watering hole attacks.
    read more
  • World Banks Reel From Digital Robberies

    Bankers are under attack around the world. The assault is not being led by masked men with pistols but rather by anonymous cyber-thieves armed with malicious code. Their vulnerability stems from a historic ...
  • AMD challenges Intel with amazing next-gen laptop processors

    Computex 2016 is the place to be if you want to see a kick-ass battle between computing giants. Intel wasn’t the only company to announce some incredibly fast new silicon at the show, and Intel's 10-core desktop CPU isn’t the only marvelous thing coming out of Computex. AMD has unveiled a variety of mobile chips that are supposed to be even faster than what Intel has to offer. DON’T MISS: Hackers are using remote-control software Teamviewer to hijack PCs and drain PayPal accoun
  • Hackers can read your WhatsApp and Telegram chats if they wanted to

    Hackers can read your WhatsApp and Telegram chats if they wanted to
    WhatsApp has recently announced that all its chats are protected by end-to-end encryption , meaning that only the sender and receiver will be able to read the messages in a conversation. Telegram offers end-to-end encryption too in secret chats. But hackers can read WhatsApp and Telegram conversations with relative ease if they wanted to, and that’s all without breaking encryption. DON’T MISS: Google Nexus phones won't run pure Android anymore The following videos, published on

Follow @newloc_security on Twitter!