Mobile

A CISO's View of Mobile Security Strategy, With Stacey Halota

100%
0%

CISO of Graham Holdings Stacey Halota visits Dark Reading News Desk at Black Hat to discuss her talk at the CISO Summit, why securing mobile devices is a top priority despite their absence in recent mega-breach story lines, and how her company is using mobile devices to improve security, instead of threaten it.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
kaymera
50%
50%
kaymera,
User Rank: Apprentice
2/7/2018 | 4:14:26 AM
Not that difficult to hack a mobile device
We all have mobile devices and we are all connected. Everyone has email accounts, social media and access to their organization's email and their resources. If a hacker wanted to target someone or the organization, the best tool is the Mobile phone.

Most mobile phone users are really not aware of the cyber risks from downloading apps (without reviewing what access they are giving up), connecting to open WIFI networks at the cafe, airport, mall, etc... You might not even need a sophisticated attacking system to infect a mobile device, you just need to manipulate the user.

Everyone I know has a firewall or an antivirus software on their personal computer, however, most people do not have a Mobile Threat Defense app on their mobile phone. So it's important that a mobile phone user install a Mobile Threat Defense app such as the Kaymera CipherWatch app that will detect, prevent and protect the user /organization from mobile threats.
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12242
PUBLISHED: 2018-09-19
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.
CVE-2018-12243
PUBLISHED: 2018-09-19
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths i...
CVE-2018-14792
PUBLISHED: 2018-09-19
WECON PLC Editor version 1.3.3U may allow an attacker to execute code under the current process when processing project files.
CVE-2018-16607
PUBLISHED: 2018-09-19
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
CVE-2018-16785
PUBLISHED: 2018-09-19
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell