Upcoming Webinar: Why Java Exploits Remain a Top Security Risk
Posted: Tuesday, April 30, 2013 11:05 PM by Bob Hansmann
Java vulnerabilities and zero-days are a serious problem in today's businesses. Frequently discovered vulnerabilities are consistently opening the door for data theft. Recent research by the Websense Security Labs found that 94 percent of computers...   Read more >
EMEA Webcast: Seven Stages of Advanced Threats & Data Theft
Posted: Monday, September 10, 2012 7:59 AM by Spencer Parker
The seven stages hackers follow to steal data have been exposed! Traditional URL and AV defences are no longer effective in blocking targeted attacks. Cloud apps, mobility and remote users have all contributed to a growth in SSL traffic, which is a major...   Read more >
Webinar Wednesday: 7 Stages of Advanced Threats & Data Theft
Posted: Monday, August 06, 2012 10:18 PM by Tom Clare

Every day, organizations worldwide are targeted by data-stealing attacks. While these attacks have evolved in frequency and sophistication, many security defenses have failed to adapt. Old techniques don’t address containment against data theft and cybercrime call-home communications. The growing prevalence of cloud apps, along with increases in SSL traffic, mobility and remote users are also adding more blind spots to traditional defenses.

It’s imperative that we continue to stay up-to-date on the latest tactics and tricks. Join me this Wednesday, August 8, 2012 from 10 a.m. - 11 a.m. PT for a webinar on the seven stages of data theft. We’ll be covering each of these steps:

Reconnaissance - Targeted attackers access credentials and research online profiles, email IDs, org. chart information, hobbies and interests from social profiles to gain insight on their victims.

Lures - Designed to prey on human curiosity, web lures often link to videos or breaking news, while email lures are more business-focused on transaction and fake delivery notices.


Redirects - Users are usually directed to a survey, rogue anti virus offer or a fake web page where an exploit kit is waiting. Traditional redirects are injection attacks, while newer ones focus on social networking wall postings, fake plug-ins, fake certificates and heavily obfuscated java script.


Exploit Kits - The exploit kit objective is like that of a sniper: take the shot with a malware dropper file only when an open door for tested vulnerabilities is found.


Dropper Files - This stage is what most people consider the focus of their forward-facing defenses: analyze every file that comes into the network for malware. The problem is dropper files use dynamic packers, so known signatures and patterns are not available.


Call-Home - This stage involves calling home for malware downloads and tools, and for sending back information, standard procedure for any successful online attack. The problem is that most defenses are only forward-facing and do not analyze the outbound traffic from infected systems.


Data Theft - This is what they are after. The ability to contain an attack and stop data theft raises many questions that we will address. Can your defenses detect password files leaving your network or the use of custom encryption on outbound files?

In addition, we’ll be covering: why current defenses are failing; today’s new security requirements; and the newest, bleeding edge advanced threat and data theft defenses to emerge thus far.

We look forward to having you join the webinar. Bring your questions and be ready to talk threats!

 

...   Read more >
This Wednesday: Why MDM Needs Mobile Security
Posted: Monday, July 09, 2012 10:35 AM by Stacey Garcia

Did you know that 90 percent of all companies experienced some type of data breach within the last year? And that 64 percent happened while employees were outside of the corporate headquarters? We predict it will only get worse as more people use mobile devices and tablets.

Join me this Wednesday, July 11 at 3 p.m. ET/12 Noon PT to discuss...

...   Read more >
You’re Hooked; a Practical Webcast on Avoiding Phishing Attempts
Posted: Tuesday, June 19, 2012 3:01 PM by Jason Woo
Phishing. It’s been around for ages and continues to evolve. From the simple money wire scams and the attempts to steal AOL user passwords, to ultimately the threat that makes IT managers shake in their boots: “spear-phishing.” In recent...   Read more >
Need to safely allow mobile devices? Tomorrow's webinar will teach you how
Posted: Saturday, May 26, 2012 12:35 AM by Matthew Mors
Personal mobile devices are flooding the workplace, and IT is still desperately searching for ways to secure them. This surge of mobility greatly increases the attack surfaces in an organization. But too often the security initiatives attempting to address...   Read more >
Face Your DLP Fears By Managing Risk—New April 5 Webinar
Posted: Monday, April 02, 2012 9:27 PM by Andrew Forgie

Ever been to a webinar that tells you what to do, but fails to say how? Well, this week I’m determined to change that. I’m hosting a webinar that will help eliminate DLP fears and provide a guide on managing risk. As a Websense expert on DLP, I’m going to give real-world practical advice on how anyone can understand, apply, and realize real measurable DLP results. 

Here’s the webinar link. Join me on Thursday, April 5th at 10 a.m. PST/1 p.m. EST. You’ll learn:

- Guiding principles of security and risk management

- Data breach trends from the last six years

- Nine-step DLP methodology and execution strategy

- Success factors in addressing the web DLP challenge 

While CIOs don’t need to be convinced that data loss protection is important—many are afraid of failure. They have heard horror stories about deployment complexities and operational nightmares. Recent high-profile data breach headlines have also made them question the true value and effectiveness of DLP. Could you blame them? Well, this webinar is designed to give you a road map to DLP success.

Register for the webinar here: http://www.websense.com/content/brighttalk-webcast.aspx

If you have any questions on DLP or the webinar, feel free to post a comment. 

 

...   Read more >
Contextual Defenses for the Evolving Web and Employee — Upcoming Webinar
Posted: Wednesday, February 08, 2012 12:58 AM by David Rand
This is the age of constantly changing advanced attacks and it’s spelling an end to static defenses that focus on inbound threats. Threats are ever-evolving. The bad guys are getting smarter. And they are capitalizing on your unprotected data. So...   Read more >
Shutting the Door on Data Theft - Upcoming Webinar
Posted: Tuesday, July 19, 2011 7:06 PM by Patrik Runald

 

A while back it seemed like you just had to worry about foreign governments or competitors going after your IP, and cybercriminals stealing your money. As if that weren’t bad enough, now all of a sudden it’s cool to be a hacker again? Media notoriety elevates the atmosphere around the black, white, and grey hat communities.

So now, hordes of pro and semi-pros are armed with the same arsenal of tools and exploits. I’ve heard that breaches run in the hundreds of dollars per record, but if it is your IP stolen – the fundamental ingredients that make your business what it is, the pain can be even greater.

So, how do they do it? These bad guys are creating code that knows where your weaknesses are and searches out your most valuable data. They use combinations of email and web tactics, gain a foothold in your system and then have almost free reign to exfiltrate any data they think they can monetize.

How easy is it to evade detection? Well , John Strand just posted an excellent article about how to bypass AV on Pauldotcom. I think it’s almost recommended reading for anyone protecting a network.

In addition – tomorrow I’m going to be hosting a Webinar on some of our research on attacks, attack types and how you can stay ahead in the game. It’s a dog eat dog world out there, and there is a lot at stake. Join me and we’ll talk it through. You can register for the webinar here: https://connect.websense.com/e15206815/event/event_info.html

I look forward to sharing with you.

 

...   Read more >
Websense   Follow us>