Towerwall's InfoSec Blog

Content Type

See all

Shellshock , The Latest Mac OSX and Linux Vulnerabilty—

network security , Shellshock. Bash bug , passwords , security software , Data Security , Linux , iOS update , Security Threat , Information Security , web server , Bash , Mac , Mac OSX , Hackers , cybercriminals , Security Alert , Data Privacy , security research , iOS , GNU Bash Remote Code Execution Vulnerability , Unix , cannabis , cybersecurity , Enterprise , Data Breach

Michelle Drolet

By: Solange_Desc1 Security researchers have discovered a new software bug known as the “Bash Bug” or “Shellshock,” or to those more technically “in-the-know” as GNU Bash Remote Code Execution Vulnerability (CVE-2014-6271)(link is external). This bug, more correctly termed, ‘vulnerability’, potentially allows attackers to gain control over targeted computers. The bug is present in a piece of computer software called, Bash, that is typically found on computers running an operating system calledfalse

1.2 billion logins scooped up by CyberVor hacking crew - what you need to do

passwords , Cache , Heartbleed , infected phone , Botnet , bot-infected , two-factor authentification , SQL injection , Information Security , web server , infected computer , Hackers , Cloud Security , Web Application Firewall , cybercriminals , Cryptolocker , Web Browser , web users , cybersecurity

Michelle Drolet

Towerwall Application Security Alert Vol 13.73 Hackers have amassed a vast collection of stolen data, including 1.2 billion unique username/password pairs, by compromising over 420,000 websites using SQL injection techniques. Researchers monitored the gang for over seven months, thought to be "fewer than a dozen men in their 20s who know one another personally" based in a small city in central Russia. They found that the group, working together since at least 2011, had rented time on false

Towerwall Application Security Alert Vol 13.73

network security , passwords , Web Storage , Data Security , Security Regulations , Botnet , credit card security , Security Threat , bot-infected , two-factor authentification , Information Security , web server , Application Security , Security , Hackers , Cloud Security , Web Application Firewall , security policy , cybercriminals , penetration testing , Cryptolocker , Security Alert , Data Privacy , Web Browser , web users , cybersecurity , Enterprise , Data Breach

Michelle Drolet

1.2 billion logins scooped up by CyberVor hacking crew - what you need to do Hackers have amassed a vast collection of stolen data, including 1.2 billion unique username/password pairs, by compromising over 420,000 websites using SQL injection techniques. Researchers monitored the gang for over seven months, thought to be "fewer than a dozen men in their 20s who know one another personally" based in a small city in central Russia. They found that the group, working together since at least 2011,false

Why wasn't healthcare.gov security properly tested?

security software , Security Regulations , credit card security , Security Threat , Security Program , Information Security , web server , Application Security , Security , software updates , Hackers , Web Application Firewall , HIPAA , security policy , cybercriminals , penetration testing , information security tips , web users , cybersecurity

Michelle Drolet

When the healthcare.gov website was launched on Oct. 1 it didn't take long for technical issues to hit the headlines. Americans trying to register for health care found the website unusable. There were glitches, extremely long loading times, and serious errors, but most worrying of all for anyone entrusting sensitive data to the system was the lack of security testing. Three white hat hackers, charged with exposing flaws in the security of online systems told a Congress hearing that thefalse

Introducing our Quarterly Newsletter: the Data Security Review

Security Partners , network security , Security Services , security software , Web Storage , Data Security , Government Compliance Regulations , Security Regulations , Heartbleed , credit card security , Mobile Devices , Security Threat , Security Program , Information Security , web server , Application Security , Security , malware , Mobile Apps , Hackers , endpoint security system , Cloud Security , T-Mobile , Web Application Firewall , Apple , Shockwave. Internet Explorer , security policy , cybercriminals , penetration testing , financial security , Security Alert , information security tips , Big Data , Mobile Protection , Data Privacy , Web Browser , security research , vulnerability management , Mobile Security , Third-party Vendor , web users , cybersecurity , Data Breach

Michelle Drolet

I am excited to announce the launch of our quarterly newsletter, the Data Security Review.

10 Things I Know About... Mobile Security

Security Services , passwords , Web Storage , Data Security , Security Regulations , Mobile Devices , Security Threat , Information Security , web server , Application Security , Security , iPhone , Mobile Apps , Cloud Security , T-Mobile , Web Application Firewall , cyber-attack , Apple , cybercriminals , Security Alert , information security tips , Mobile Protection , Data Privacy , Web Browser , security research , Mobile Security , web users , cybersecurity , Data Breach

Michelle Drolet

10. Malware Is On The Rise The threat of malware on mobile platforms is growing steadily as more cybercriminals target mobile devices in increasingly sophisticated ways.

New LinkedIn E-Mail Scam

Linkedin , security software , Security Regulations , Social Engineering , credit card security , Security Threat , Information Security , web server , Security , Hackers , Cloud Security , cyber-attack , security policy , cybercriminals , Security Alert , information security tips , Web Browser , security research , Mobile Security , web users , email scam , cybersecurity , Enterprise

Michelle Drolet

Hi all, there is an e-mail scam doing the rounds. The message is an invite from some random person you won’t know with a link (how original). If you get such a message don’t use the link, check your LinkedIn account as if it’s a legit request it will be there waiting for approval. Even if it is legit, make sure you vet all invite requests carefully. I have had several dodgy requests from what I believe to be bogus profiles who are likely up to no good. LinkedIn is about the quality of yourfalse

New Internet Explorer zero day being exploited in the wild

Security Services , security software , Web Storage , Data Security , Security Regulations , Security Threat , Information Security , web server , Security , Internet Explorer , Hackers , Web Application Firewall , cyber-attack , security policy , cybercriminals , penetration testing , information security tips , Web Browser , security research , Mobile Security , web users , cannabis , cybersecurity , Enterprise

Michelle Drolet

After the last zero day exploit on Java we reported some weeks ago it appears that a new 0day has been found in Internet Explorer by the same authors that created the Java one. Yesterday, Eric Romang reported the findings of a new exploit code on the same server that the Java 0day was found some weeks ago. The new vulnerability appears to affect Internet Explorer 7 and 8 and seems to be exploitable at least on Windows XP. The exploit code found in the server works as follow: - The filefalse

Beware the wild west of Web applications

Security Partners , network security , Security Services , security software , Web Storage , Data Security , Security Regulations , Security Threat , Security Program , Information Security , web server , Application Security , Security , Cloud Security , Web Application Firewall , security policy , penetration testing , information security tips , Compliance , Web Browser , web users , cannabis , cybersecurity , Enterprise

Michelle Drolet

Web applications – particularly those facilitating collaboration and communication – are a boon to sales, marketing and productivity. Teams work together more effectively, salespeople enjoy better leads and marketing tools and customer service reps can more closely connect with those they serve. All of these gains, though, come at a cost: risk. By their very nature, Web applications circumvent many enterprise security controls. They are designed to enable communication, not security. A paper byfalse