Skip to main content

Posts

Showing posts from April, 2021

Concepts of Cybersecurity

Q:  What is cybersecurity.? A:   Cyber security, also referred to as information technology security, focuses on protecting Information technology assets and its information Cybersecurity is the collection policies, procedures, guidelines and risk management approaches. The NIST framework includes Identify, Protect, Detect, Respond and Recover. Q: What is NIST framework IDENTIFY A: NIST Framework identify includes    Identifying physical and software assets   Identifying cybersecurity policies   Identifying asset vulnerabilities   Identifying a Risk Management Strategy   Identifying authorization   Identifying authentication roles Q: What is NIST Cybersecurity Framework  - PROTECT A: NIST framework protect includes  Protections for Identity Management Protection for physical assets Protection for data Protect technology Proper change management Disaster recovery  Q:  What is NIST Cybersecurity Fram...

Computer Engineering

   I'm planning to do my master’s in cyber security do I need programming knowledge to complete my Masters ? A)       No, it does not require programming knowledge. Firewall is which type of cyber security domain  A)     Preventive control

Microsoft Office SharePoint Targeted With High-Risk Phish, Ransomware Attacks

Microsoft Office SharePoint Targeted With High-Risk Phish, Ransomware Attacks   A phishing campaign, discovered by researchers at  Cofense , is draping itself in a Microsoft Office SharePoint theme and successfully bypassing security email gateways (SEGs). In a post on Tuesday, the firm said that this is an example of why it’s not always prudent to share documents via Microsoft’s hugely popular, widely used SharePoint collaboration platform.  The phish is targeting Office 365 users with a legitimate-looking SharePoint document that claims to urgently need an email signature. The campaign cropped up in a spot that’s supposed to be protected by Microsoft’s own SEG. This isn’t the first time that we’ve seen the SEG sanctuary get polluted:: In December,  spearphishers spoofed Microsoft.com  itself to target 200 million Office 365 users, successfully slipping past SEG controls due to Microsoft’s reported failure to enforce domain-based message authentication, reporti...