Have you heard about Operation Spear-Phish? Take the challenge.
Posted: Monday, October 29, 2012 10:38 AM by Jason Woo
Every week I hear cyber security teams say they’re worried about spear-phishing . They’re struggling to defend against them with their current technology. But to exacerbate matters, their users also struggle to understand how to spot a malicious...   Read more >
It’s Phishing Season in Canada: Don’t Take the Bait
Posted: Wednesday, October 24, 2012 3:00 PM by Fiaaz Walji
Last week, the Canadian federal government announced its plans to create a secure, stable and resilient digital infrastructure in Canada. To help improve incident response and stop cyber-threats, the Government of Canada is investing $155M in our cybersecurity...   Read more >
What is Scaring Businesses the Most? Spear-phishing. New Websense Security Labs Research
Posted: Tuesday, October 09, 2012 4:58 AM by Patrik Runald
Spear-phishing is a huge concern for today’s government and enterprises. While high profile attacks like last week’s spear-phishing attack against the White House and last year’s attack against Oak Ridge National Laboratory underscore...   Read more >
Insights from Top CSOs: 100 Percent Concerned About Spear-Phishing
Posted: Tuesday, September 18, 2012 1:14 PM by Jason Clark

I recently hosted a Websense customer round-table discussion with 20 CSOs from top U.S. companies. We swapped war stories, hashed out the security challenges they face every day and they shared how they’ve been successful. These CSOs work in a variety of industries, including federal, finance and healthcare. Recently, there have been a number of highly public targeted attacks, which led to a lengthy discussion on spear-phishing. I found their insights very valuable and I wanted to share some key points...

...   Read more >
EMEA Webcast: Seven Stages of Advanced Threats & Data Theft
Posted: Monday, September 10, 2012 7:59 AM by Spencer Parker
The seven stages hackers follow to steal data have been exposed! Traditional URL and AV defences are no longer effective in blocking targeted attacks. Cloud apps, mobility and remote users have all contributed to a growth in SSL traffic, which is a major...   Read more >
Does your company have a mobile acceptable use policy?
Posted: Thursday, August 16, 2012 9:41 AM by Stacey Garcia

This week, Juniper Research estimated that the number of employee-owned smartphones and tablets used at work is set to reach 350 million by 2014, up from 150 million in 2012. With new smartphones and tablets inundating companies worldwide, IT security teams are struggling to determine acceptable use policies. It goes beyond corporate BlackBerries and laptops to the newest BYOD (like iPads, iPhones, etc).

To help teams manage the mobile influx, we just released a new five-part Websense Mobile Acceptable Use Policy Kit. It provides a guide to help your company embrace mobile devices, communicate with employees, and keep confidential data secure. You can confidently use this guide to help you get started on your company’s acceptable use policy or to supplement your existing mobile device acceptable use policy.

...   Read more >
10 New Defenses That Help Prevent Data Loss and Theft
Posted: Thursday, August 09, 2012 12:11 AM by Tom Clare

 

Last week we announced several new, important core security technologies that we added to our TRITON architecture. Websense ACE now includes 10 new defense innovations; seven are focused on outbound traffic to keep data theft and call-home communications contained, preventing theft or loss. Because so many of them are industry firsts, I wanted to take a moment to explain what many of these do and why we created them.

Truth is, the bad guys are stealing corporate data and avoiding detection using advanced techniques. In just the last year, we've seen key intellectual property and user identities stolen from corporations and government agencies, including some you would least expect-including entertainment (gaming) and security companies!

Below are a few examples of how cyber criminals are going undetected, stealing your IP, and how we can stop it from happening.

More

...   Read more >
Webinar Wednesday: 7 Stages of Advanced Threats & Data Theft
Posted: Monday, August 06, 2012 10:18 PM by Tom Clare

Every day, organizations worldwide are targeted by data-stealing attacks. While these attacks have evolved in frequency and sophistication, many security defenses have failed to adapt. Old techniques don’t address containment against data theft and cybercrime call-home communications. The growing prevalence of cloud apps, along with increases in SSL traffic, mobility and remote users are also adding more blind spots to traditional defenses.

It’s imperative that we continue to stay up-to-date on the latest tactics and tricks. Join me this Wednesday, August 8, 2012 from 10 a.m. - 11 a.m. PT for a webinar on the seven stages of data theft. We’ll be covering each of these steps:

Reconnaissance - Targeted attackers access credentials and research online profiles, email IDs, org. chart information, hobbies and interests from social profiles to gain insight on their victims.

Lures - Designed to prey on human curiosity, web lures often link to videos or breaking news, while email lures are more business-focused on transaction and fake delivery notices.


Redirects - Users are usually directed to a survey, rogue anti virus offer or a fake web page where an exploit kit is waiting. Traditional redirects are injection attacks, while newer ones focus on social networking wall postings, fake plug-ins, fake certificates and heavily obfuscated java script.


Exploit Kits - The exploit kit objective is like that of a sniper: take the shot with a malware dropper file only when an open door for tested vulnerabilities is found.


Dropper Files - This stage is what most people consider the focus of their forward-facing defenses: analyze every file that comes into the network for malware. The problem is dropper files use dynamic packers, so known signatures and patterns are not available.


Call-Home - This stage involves calling home for malware downloads and tools, and for sending back information, standard procedure for any successful online attack. The problem is that most defenses are only forward-facing and do not analyze the outbound traffic from infected systems.


Data Theft - This is what they are after. The ability to contain an attack and stop data theft raises many questions that we will address. Can your defenses detect password files leaving your network or the use of custom encryption on outbound files?

In addition, we’ll be covering: why current defenses are failing; today’s new security requirements; and the newest, bleeding edge advanced threat and data theft defenses to emerge thus far.

We look forward to having you join the webinar. Bring your questions and be ready to talk threats!

 

...   Read more >
Black Hat Briefings & Exhibits: Day One...
Posted: Thursday, July 26, 2012 7:46 PM by Bob Hansmann

Time for Black Hat again! Day one is almost complete and I’ve seen some big themes.

There’s some of the usual. Vulnerability scanning and pen testing are definitely present and the topics of identifying and learning from data breaches are still big—especially around the area of SIEM. There are also some new developments. For example, more exhibitors are simply about education, including your typical certification schools, but general higher learning institutions, like the University of Maryland, are also here.

As usual, Black Hat USA is full of security vendors and their products, but there seem to be more ‘service’ offerings showcased this year. This may not be surprising to those who have heard analysts increasingly discuss the weaknesses assumed by an organization that is overly dependent on purely in-house resources.

Education, services and research tools are obviously taking center stage in the battleagainst cybercrime. All this focus on education is precisely why we’ve developed a few new tools and resources to help resource-strapped customers tap into the expertise of the Websense® Security Labs™ researchers.

Sometimes you need more than what you have on-hand—especially when you are dealing with highly advanced malware and complex data stealing attacks. That’s when you need an expert security researcher to help. Our Websense Security Labs have morethan one hundred team members worldwide, hip–deep in the latest threats. The new Websense CyberSecurity Intelligence™ (CSI) servicesannounced today, help extend their expertise and educational benefits right into your organization.

Websense CSI services offer both online and 1:1 time with our researchers, through tools, training, in-person guidance and malware forensics.

All Websense CSI customers will have access to ThreatScope™, an online sandbox environment, to safely test potential malware. It uses our Websense Advanced Classification Engine (ACE) analytics to compile an extensive report of observed behavior on an uploaded file. Insights include the infection process; post-infection activities (such as calling home); system-level events and processes; registry changes and filemodifications.

Think about it, Black Hat USA only comes around once a year, but every day needs to be about education in the security field. Websense CSI services can be an extension of your learning process— giving you access to our researchers and the necessary tools to help you become more educated on the threats of today.

If you could study one aspect of today’s threats, what would you dive into?

...   Read more >
Watch Olympians “Go for the Gold” at Work - Safely
Posted: Saturday, July 14, 2012 4:41 PM by Joshua Rosenthal
On July 27, for the first time ever, all of the summer Olympic game events will be streamed online by a network. In addition, we’ll see thousands of other sites re-streaming or hosting the content. The internet will be awash with Olympics. And while...   Read more >
You’re Hooked; a Practical Webcast on Avoiding Phishing Attempts
Posted: Tuesday, June 19, 2012 3:01 PM by Jason Woo
Phishing. It’s been around for ages and continues to evolve. From the simple money wire scams and the attempts to steal AOL user passwords, to ultimately the threat that makes IT managers shake in their boots: “spear-phishing.” In recent...   Read more >
Heading to the Gartner Security & Risk Management Summit?
Posted: Friday, June 08, 2012 5:52 PM by Tom Clare
Websense has a packed agenda at the conference, and we are inviting you to join us for some sessions we’ve put together just for this event. During the first session, I’m chatting with Derek Houts, Sr. Director, Information Security, Broadcom...   Read more >
LinkedIn Breach, Part II: What You Need to Prepare for Next
Posted: Thursday, June 07, 2012 8:29 PM by Jason Clark
Yesterday’s LinkedIn breach made headlines, but I want to go deeper and provide practical advice for organizations on how they can anticipate any DLP consequences and tighten their network security. As the world’s largest professional social...   Read more >
How & Why to Alert Your Employees to the LinkedIn Breach
Posted: Thursday, June 07, 2012 3:49 PM by Jason Clark
Yesterday's news that more than 6.4 million LinkedIn passwords have been breached has many IT professionals on high alert. CSOs are asking me how/if they should communicate this news to company employees and the need to immediately change passwords...   Read more >
Websense Threat Report – Advanced Malware Invading, Stealing Data
Posted: Tuesday, May 22, 2012 5:58 AM by Tom Clare

We recently released findings on the current state of security in Canada. If you’ve read that piece, you may now be wondering how that compares with the rest of the world. The Websense Security Labs recently released our 2012 Threat Report exploring the biggest threats, trends, and themes collected by the Websense ThreatSeeker Network and investigated by our security lab research teams.

2011 redefined the way many think of and view internet and corporate security. 2012 is continuing this trend. From high profile targeted attacks, hacktivism, data theft and the leverage of exploit kits to selectively deliver malware dropper files when vulnerabilities are detected on user systems, the year forced everyone to think, “Am I next?”

The Websense Security Labs Threat Report provides metrics and practical advice for IT Security professionals. Take a read and let us know if you have any questions about the findings.

 

...   Read more >
9 Tips for CSOs to Get a Fresh Start this Spring
Posted: Friday, April 13, 2012 5:18 PM by Jason Clark

With the hectic travel schedule of first quarter wrapping up I had some spare time to think about advocating a fresh approach to security for the spring. I know it’s not the beginning of the year, but if your schedule is anything like mine, this may be the first time you’ve had a minute to spare since the calendar moved to 2012. With everything in the threat landscape changing so frequently, it’s important to reassess your current status and plan for the coming year, whenever we can come up for air. So, I came up with the following nine tips to help you get a fresh start this spring:

<CONTINUE>

...   Read more >
Face Your DLP Fears By Managing Risk—New April 5 Webinar
Posted: Monday, April 02, 2012 9:27 PM by Andrew Forgie

Ever been to a webinar that tells you what to do, but fails to say how? Well, this week I’m determined to change that. I’m hosting a webinar that will help eliminate DLP fears and provide a guide on managing risk. As a Websense expert on DLP, I’m going to give real-world practical advice on how anyone can understand, apply, and realize real measurable DLP results. 

Here’s the webinar link. Join me on Thursday, April 5th at 10 a.m. PST/1 p.m. EST. You’ll learn:

- Guiding principles of security and risk management

- Data breach trends from the last six years

- Nine-step DLP methodology and execution strategy

- Success factors in addressing the web DLP challenge 

While CIOs don’t need to be convinced that data loss protection is important—many are afraid of failure. They have heard horror stories about deployment complexities and operational nightmares. Recent high-profile data breach headlines have also made them question the true value and effectiveness of DLP. Could you blame them? Well, this webinar is designed to give you a road map to DLP success.

Register for the webinar here: http://www.websense.com/content/brighttalk-webcast.aspx

If you have any questions on DLP or the webinar, feel free to post a comment. 

 

...   Read more >
Contextual Defenses for the Evolving Web and Employee — Upcoming Webinar
Posted: Wednesday, February 08, 2012 12:58 AM by David Rand
This is the age of constantly changing advanced attacks and it’s spelling an end to static defenses that focus on inbound threats. Threats are ever-evolving. The bad guys are getting smarter. And they are capitalizing on your unprotected data. So...   Read more >
QR Codes and the Damage (to be) Done?
Posted: Sunday, January 15, 2012 10:00 PM by Patrik Runald

When we were looking at putting out our Websense Security Labs predictions for 2012, we knew that mobile threats were going to be big this year. While we included one prediction on it, there was one piece that I had thought of, but didn’t include. It’s still a ways away, but Paul Henry has an excellent write up on “QR Codes – Leading Lambs To the Slaughter.”

He correctly points out that these “ultimate url-obfuscators” can be a serious threat down the line.

It’s a good reminder that any applications on workforce mobile devices need to be properly sandboxed from the operating system. We’ve already noted in Websense Security Labs research that there are challenges with certain platforms and there are a number of mobile malware variants, including Trojans on handhelds.

It’s interesting to think QR codes as threats continue to evolve in the mobile landscape. What’s funny is as I was writing this, our Security Labs researches discovered QR codes being used a new way – through a spam campaign

What do you think about QR codes?

 

 

...   Read more >
Websense Security Survey: IT Stresses as Data Breaches Put Jobs on the Line
Posted: Thursday, October 20, 2011 3:59 AM by Matthew Mors

 

IT managers feel that getting a divorce or losing their job is less stressful than looking after company confidential data

SAN DIEGO—October 20, 2011 How are IT managers coping with today’s fast-changing threat landscape? Are they properly protected against the latest data-stealing malware? And would employees report if they compromised corporate data? To find out these answers and more, Websense, Inc. (NASDAQ: WBSN), a global leader in content security and data theft protection, commissioned independent research firm Dynamic Markets to survey 1,000 IT managers and 1,000 non-IT employees in the U.S., UK, Canada, and Australia about the latest threats to corporate and personal security, including modern malware and advanced persistent threats (APTs).

The research reveals that serious data breaches have occurred compromising CEO and other executives’ data, confidential customer data, and data necessary for regulatory compliance. IT managers are feeling the pressure and saying that data loss incidents put their jobs on the line and that the stress of managing their company confidential data is greater than divorce, managing personal debt, or a minor car accident. But help is on the horizon as headline-grabbing security incidents have promoted data security talks amongst top management and have driven focus on security, including the need for additional budget. Click here to download the full report entitled Security Pros & ‘Cons’: IT professionals on confidence, confidential data, and today’s cyber-cons.

 

...   Read more >
More Posts Next page »
Websense   Follow us>