Security news that informs and inspires

All Articles

2376 articles:

Ways Web Services Monitor User Accounts for Fraud

Here are some recommendations for what we’d like to see online services do while monitoring their platform for account fraud. While some of them apply specifically to account recovery, but recommendations focus on improving overall account security.

Labs Research, Account Security

Decipher: Security Without Fear

Decipher is designed to bring security news and information out of the dark and into the light.

Decipher

Two-Step Verification or Two Factor: 90% Don’t Use it to Protect Gmail

Less than 10 percent of active Google accounts use two-step verification (2SV) to secure access to their services, like Gmail. While experts commonly favor using two-factor authentication or password managers, these tools are virtually absent from the security posture of regular users.

2fa, Google

Phishing Campaign Targets U.S. Senators & Political Organizations

Pawn Storm (aka Fancy Bear) has been attempting to phish webmail accounts for many years now, targeting U.S. senators and political organizations across the world, according to a recent Trend Micro report.

Phishing, 2fa, Biometrics, Mfa

Understanding Bluetooth Security

When it comes to Internet of Things (IoT) security research, you may run into roadblocks examining Bluetooth pairing and encryption between older devices and new ones - this blog post explains what you need to know to overcome them.

Labs Research, Bluetooth Security, Iot Security

Examining Personal Protection Devices: Hardware and Firmware Research Methodology in Action

In a technical paper released today, Duo Labs details research into two personal protection devices based on ARM Cortex M microcontrollers. These devices allow wearers to notify people of their well-being.

Iot Security, Personal Protection Devices

What You Need to Know About Complying With GDPR

Have questions about the E.U.'s General Data Protection Regulation (GDPR)? Get non-scary advice on the basics of complying, and what you need to do to protect your organization.

GDPR, General Data Protection Regulation, UK Security

Malicious Chrome Extensions Steal Passwords & CPU Power

A number of recent malicious Google Chrome extensions that steal user data and CPU have slipped into the Chrome Web Store, disguised as ad blockers, security tools and URL shorteners. Users beware of shady extensions in the Chrome Web Store...

Chrome Security, Stolen Passwords

Protecting Against Bad Rabbit Ransomware Infection

A new severe variation of the Not-Petya ransomware has infected mainly Russian users - here’s how it spreads and how to protect against it.

Ransomware, SMB Security, Drive by Malware

SSH Key Exposure: Lapses in Server Access Security

The exposure of SSH keys to public websites or code repositories can result in unauthorized admin access to your servers and systems.

SSH Security, SSH Keys, Server Security, AWS Security

Bluetooth Hacking Tools Comparison

The Duo Labs security research team compares the features and capabilities of several Bluetooth scanners and software to best assist you in your security and IoT research.

Labs Research, Bluetooth Security, Bluetooth Hacking

Explaining KRACK: A Critical Attack Affecting A Wi-Fi Security Protocol

Learn about KRACK (key reinstallation attacks), the serious WPA2 vulnerabilities and how it impacts authentication and certain platforms, plus caveats on how the attack can work in the real world.

Wpa2 Security, Wi Fi Security, KRACK

Evasive Brute-Force Attacks Target Office 365 Accounts

There’s a new sneaky brute-force attack targeting unprotected enterprise Office 365 accounts, including those in the manufacturing, financial services, healthcare industries.

Mfa, Sso, Cloud

New York Cybersecurity Regulations in Effect for Financial Services

New York-based banks, insurance companies and other financial services must comply with finalized cybersecurity regulations - here’s a summary of the mandatory provisions and components of a cybersecurity program.

Cybersecurity, Financial Data Security

An Analysis of BlueBorne: Bluetooth Security Risks

Cut through the FUD (Fear, Uncertainty & Doubt) with a Duo Labs analysis of the recent series of Bluetooth vulnerabilities known as BlueBorne - and get our mitigation recommendations on how to keep your devices safe.

Bluetooth Security, Blueborne, Bluetooth Vulnerabilities