Tag: patching

Dev Ops Secrets are a major source of breaches, including the recent hack of Uber. We speak with Elizabeth Lawler of CyberArk about it.

Podcast: Uber Breach Puts Focus on Securing DevOps Secrets

The hack of Uber and the loss of information on 57 million customers is just the latest security incident stemming from what our guest Elizabeth Lawler calls “DevOps secrets” – valuable credentials, APIs and other sensitive information that often end up exposed to the public as a result of lax continuous development operations. In this Spotlight Edition* of The Security Ledger Podcast, sponsored by CyberArk, we talk with Elizabeth about how to contain DevOps secrets and secure the secret super user lurking in modern organizations: highly privileged application code.  Podcast: Play in new window | DownloadSubscribe: Android | RSS

Germany wants to destroy kids' smart watches. Why?

Podcast: Why Germany wants Smart Watches destroyed and One Nation Under Trolls

In this week’s Security Ledger podcast, sponsored by our friends at CyberArk, we talk about the German government’s recent decision to declare kids smart watches “surveillance devices” and to order their destruction. Also: Adrian Shabaz of Freedom House comes in to talk to us about the latest Internet Freedom report, which finds that governments are increasingly manipulating online content to shape online discussions and even the outcome of elections at home and abroad. And finally: leaked credentials in a GitHub repository may have been behind Uber’s loss of information on some 50 million customers. In a preview of a Security Ledger spotlight podcast, we hear from Elizabeth Lawler of CyberArk about the proliferation of so-called “Dev Ops secrets” and how companies need to do a better managing the permissions assigned to applications.  Podcast: Play in new window | DownloadSubscribe: Android | RSS

There are warnings from the DHS and FBI about a North Korean cyber operation dubbed Hidden Cobra.

US Government Warns of Hidden Cobra North Korea Cyber Threat

A Department of Homeland Security (DHS) Alert released on Tuesday warns the public about a campaign of hacking by the government of North Korea it has code-named “Hidden Cobra.”

A Security Ledger and LogMeIn survey of device makers finds concerns about security - but a tendency to leave low hanging fruit unpicked.

Survey finds Device Makers Security Priorities Often Misplaced

Low-hanging Internet of Things security fruit may be left unpicked, as connected device makers fret about the predation of sophisticated hackers, but balk at simple security fixes, a Security Ledger and LogMeIn survey finds. You can download the full report here.