security

October 20, 2015

RETAIL AND HOSPITALITY

Join the Conversation: Where Shopping Experience Meets the New Digital Consumer

The demands of increasingly mobile and digital consumers are creating unprecedented complexity for retailers and brands.  How should retailers respond?  We’re going to tackle this question together on Twitter next Tuesday, October 27 at 1pm EST/ 10am PST. Together, we’ll discuss questions such as:…

October 13, 2015

THREAT RESEARCH

Project Aspis

One of the hardest jobs on the Internet is to work the abuse desk at a hosting provider.  These teams have to strike a difficult balance between protecting their customers, ensuring that their services aren’t being abused by malicious actors and delivering the service and convenience their customers…

October 2, 2015

THREAT RESEARCH

Vulnerability Spotlight: MiniUPnP Internet Gateway Device Protocol XML Parser Buffer Overflow

Vulnerability discovered by Aleksandar Nikolic of Cisco Talos. Post authored by Earl Carter and William Largent Talos is disclosing the discovery of an exploitable buffer overflow vulnerability in the the MiniUPnP library TALOS-2015-0035 (CVE-2015-6031). The buffer overflow is present in client-sid…

September 23, 2015

SECURITY

It’s That Time Again—Announcing the Cisco IOS & XE Software Security Advisory Bundled Publication

Today, we released the last Cisco IOS & XE Software Security Advisory Bundled Publication of 2015. As a reminder, Cisco discloses IOS vulnerabilities on a predictable schedule (the fourth Wednesday of March and September each calendar year).  Last cycle, we began including Cisco Security Advisor…

September 22, 2015

SECURITY

Welcome Michelle Dennedy, Cisco’s Chief Privacy Officer

“It’s our thesis that privacy will be an integral part of the next wave in the technology revolution and that innovators who are emphasizing privacy as an integral part of the product life cycle are on the right track.” —The Privacy Engineer’s Manifesto, 2014 Privacy in an al…

September 18, 2015

SECURITY

IT Security: When Maturity is Overrated

In so many parts of life, the passing of time is a benefit. Wine and whisky mature, intelligence is gained, and friendships grow stronger. For those of us working in IT security, however, the passing of time brings new challenges. Prolonging the use of older technology exponentially increases risk a…

September 15, 2015

SECURITY

SYNful Knock: Detecting and Mitigating Cisco IOS Software Attacks

Historically, threat actors have targeted network devices to create disruption through a denial of service (DoS) situation. While this remains the most common type of attack on network devices, we continue to see advances that focus on further compromising the victim’s infrastructure. Recently, the…

September 14, 2015

SECURITY

Anomaly vs Vulnerability Detection Using Cisco IPS

The Cisco IPS network based intrusion prevention system (NIPS) uses signatures to detect network-based attacks. Signatures can be created in a variety of engines based on the type of network traffic being inspected. Cisco signatures have very flexible configurations. In this blog post, I will discus…

September 11, 2015

EXECUTIVE PLATFORM

Trust Me: Cisco Hearts Video

  I was recently talking to an industry colleague about how incredibly focused we are, as a company, on the video marketplace. I meant it, so I was surprised to see the eyebrow-spiked reaction and their response: “How can you say that, when you just unloaded your CPE including set-top boxes, mo…