Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

// // //
10/3/2017
12:00 PM
Simon Marshall
Simon Marshall
Simon Marshall

A Month for Cybersecurity

It's National Cybersecurity Awareness Month, a time to think about, plan and deploy better cybersecurity for your organization.

It's National Cybersecurity Awareness Month (NCSAM), and the National Cyber Security Alliance (NCSA) and the US Department of Homeland Security want everyone to know that securing the Internet is everyone's job. It's a noble sentiment and one consumers need to hear: not literally going out there and securing it themselves, but at least behaving wisely while online.

Will we soon see families rushing out to purchase their own industrial endpoint protection? Well, maybe. Especially if the Department of Homeland Security continues to ban Kaspersky Labs from its approved federal vendor list. Will neighbors instead form blue teams and try to defeat hackers at their own game? Pretty unlikely (although an interesting idea).

There's a veritable hackerfest out there to deal with, so consumers are better barricading themselves indoors than saddling up for King and Country and galloping out there to lance them.

But sometimes, the wisdom isn't there and so NCSAM -- themed "Our Shared Responsibility" -- is all about setting the educational record straight. There's hope for us yet: in a survey today from Raytheon and Forcepoint in partnership with the NCSA, about 85% of adults worldwide aged between 18 and 26 think that keeping the Internet safe and secure should be a shared venture.

Today's "devil take the hindmost" consumer culture could soon be replaced with a new vibe -- some would say the original Internet vibe of a shared resource for all -- to take more responsibility online, for the greater good.

"NCSAM is the time we all re-dedicate our efforts to make sure that everyone has the information they need to stay safe online, and build a safer, more secure and more trusted Internet," said Michael Kaiser, NCSA's executive director. "We must secure all corners."

Although consumers are in the swing of erecting their firewalls, and rolling out anti-malware and anti-virus efforts, identity theft is still a major worry. A report today from the Identity Theft Resource Center (ITRC) kicked up a couple of interesting stats that show how stressful the identity theft experience has become.

"The results [of the] survey indicate 75 percent of respondents were severely distressed by the misuse, or attempted misuse, of their personal information, highlighting the serious repercussions for victims," said Eva Velasquez, ITRC's CEO and president. "Nearly a quarter of the participants sought professional help to manage the emotional and physical symptoms they suffered as a result of this crime."

Sadly, it's still the senior community that bears the brunt of scamming. Just more than one-third of US seniors say someone has tried to scam them online, according to a survey conducted by Home Instead, franchisor of the Home Instead Senior Care network.


You're invited to attend Light Reading's Virtualizing the Cable Architecture event – a free breakfast panel at SCTE/ISBE's Cable-Tec Expo on October 18 featuring Comcast's Rob Howald and Charter's John Dickinson.

Apparently, it could be a combination of Teddy Roosevelt's motto, "everybody deserves a square deal" and their generally trusting nature that can lead to seniors coming unstuck. The top five scams remain: bogus PC tech support alerts, tax scams, ransomware, false debt collection emails and sweepstake scams.

To try and keep consumers heading off the security cliff without a hang-glider, NCSA is reiterating a catchy campaign to remind users to think carefully while online. "STOP. THINK. CONNECT," launched in October 2010, is simple, actionable advice all digital citizens can follow -- STOP: make sure security measures are in place. THINK: about the consequences of your online actions. CONNECT: and enjoy the Internet.

To complement this, NCSA is also literally taking its message on the road: it's parking cars strategically to flag the issues to people on the street.

Related posts:

— Simon Marshall, Technology Journalist, special to Security Now

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Black Hat USA 2022 Attendee Report
Black Hat attendees are not sleeping well. Between concerns about attacks against cloud services, ransomware, and the growing risks to the global supply chain, these security pros have a lot to be worried about. Read our 2022 report to hear what they're concerned about now.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-36312
PUBLISHED: 2022-08-16
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
CVE-2022-38216
PUBLISHED: 2022-08-16
An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes,...
CVE-2022-36306
PUBLISHED: 2022-08-16
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity 1500 running software version 9.3.0.01249, were still presen...
CVE-2022-36307
PUBLISHED: 2022-08-16
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
CVE-2022-36308
PUBLISHED: 2022-08-16
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP. This issue may affec...