Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
40% of Organizations Not Doing Enough to Protect Office 365 Data
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
5/14/2019 | 9:23:01 AM
Re: Follow me
I still have floppy disks from ancient backups --- both 3.5 AND 5.25!!!!!   Now finding one of those drives to attach is a challenge.   May have to Ebay an IBM 5150 to read them.  Also runs Visiword.  (Now that disk had an encryption scheme for boot that nobody ever cracked).

i have a box of 8" floppy disks too but don't have an IBM S/36 5360 to run them on. 
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
5/13/2019 | 8:45:30 AM
Re: Follow me
Email too can be a great restoration option - tons of attachments are often resident and can be accessed if needed, of course, by both user and hacker.  Que sera sera. 
StephenGiderson
50%
50%
StephenGiderson,
User Rank: Strategist
5/13/2019 | 3:29:07 AM
Follow me
Previously in school, I used to back up every single one of my assignments on more than 2 devices after saving in my email account. That is how prudent I was when it comes to safeguarding my own data. Organizations should really follow my style!
REISEN1955
0%
100%
REISEN1955,
User Rank: Ninja
3/29/2019 | 8:11:08 AM
Backups to the cloud
As primary?????   I use a cloud app for backups but with CAUTION and have local backups, 3 of them, ready to go if something like ransomware hit my system - and i don't open suspect emails OR open suspect attachments.  Ever.  My backups are set ot mirror the drive structure of primary data data and I have used this for my clients as well.  Small business - bad drive, pull and replace - takes 15 min and a screwdriver but the same apples to data center.  Have two backup protocols, not one - Murphy's Law.  It will fail when needed so have two methods and one offsite secure.  Data schedule generally daily - not weekly or random.  Putting trust in the cloud is a fools game, you are exposing data on a second tier of theft - not one but two.  


COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/1/2020
Stay-at-Home Orders Coincide With Massive DNS Surge
Robert Lemos, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4019
PUBLISHED: 2020-06-01
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.
CVE-2020-4020
PUBLISHED: 2020-06-01
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
CVE-2020-4021
PUBLISHED: 2020-06-01
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
CVE-2020-4023
PUBLISHED: 2020-06-01
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.
CVE-2020-4013
PUBLISHED: 2020-06-01
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.