security
Join the Conversation: Where Shopping Experience Meets the New Digital Consumer
The demands of increasingly mobile and digital consumers are creating unprecedented complexity for retailers and brands. How should retailers respond? We’re going to tackle this question together on Twitter next Tuesday, October 27 at 1pm EST/ 10am PST. Together, we’ll discuss questions such as:…
Project Aspis
One of the hardest jobs on the Internet is to work the abuse desk at a hosting provider. These teams have to strike a difficult balance between protecting their customers, ensuring that their services aren’t being abused by malicious actors and delivering the service and convenience their customers…
Vulnerability Spotlight: MiniUPnP Internet Gateway Device Protocol XML Parser Buffer Overflow
Vulnerability discovered by Aleksandar Nikolic of Cisco Talos. Post authored by Earl Carter and William Largent Talos is disclosing the discovery of an exploitable buffer overflow vulnerability in the the MiniUPnP library TALOS-2015-0035 (CVE-2015-6031). The buffer overflow is present in client-sid…
It’s That Time Again—Announcing the Cisco IOS & XE Software Security Advisory Bundled Publication
Today, we released the last Cisco IOS & XE Software Security Advisory Bundled Publication of 2015. As a reminder, Cisco discloses IOS vulnerabilities on a predictable schedule (the fourth Wednesday of March and September each calendar year). Last cycle, we began including Cisco Security Advisor…
Welcome Michelle Dennedy, Cisco’s Chief Privacy Officer
“It’s our thesis that privacy will be an integral part of the next wave in the technology revolution and that innovators who are emphasizing privacy as an integral part of the product life cycle are on the right track.” —The Privacy Engineer’s Manifesto, 2014 Privacy in an al…
IT Security: When Maturity is Overrated
In so many parts of life, the passing of time is a benefit. Wine and whisky mature, intelligence is gained, and friendships grow stronger. For those of us working in IT security, however, the passing of time brings new challenges. Prolonging the use of older technology exponentially increases risk a…
SYNful Knock: Detecting and Mitigating Cisco IOS Software Attacks
Historically, threat actors have targeted network devices to create disruption through a denial of service (DoS) situation. While this remains the most common type of attack on network devices, we continue to see advances that focus on further compromising the victim’s infrastructure. Recently, the…
Anomaly vs Vulnerability Detection Using Cisco IPS
The Cisco IPS network based intrusion prevention system (NIPS) uses signatures to detect network-based attacks. Signatures can be created in a variety of engines based on the type of network traffic being inspected. Cisco signatures have very flexible configurations. In this blog post, I will discus…
Trust Me: Cisco Hearts Video
I was recently talking to an industry colleague about how incredibly focused we are, as a company, on the video marketplace. I meant it, so I was surprised to see the eyebrow-spiked reaction and their response: “How can you say that, when you just unloaded your CPE including set-top boxes, mo…
1