Category Archives: Technology: Computer

Computers the new frontier, find out what is new in the Computer World, follow our Press Releases today.

CSIOS Corporation Successfully Completes ISO 9001, ISO/IEC 20000, ISO 22301, and ISO/IEC 27001 Annual Surveillance Audit


https://www.prweb.com/

Mr. Cesar Pie, President and CEO of CSIOS Corporation

The scope of CSIOS ISO certifications is the “Provision of Cyberspace Operations (Defensive, Offensive, and Information Network Operations) and Cybersecurity services to U.S. Federal customers worldwide.” The only one of its kind.

CSIOS Corporation announced today that it has successfully completed annual surveillance audits for ISO 9001 (Quality Management System), ISO/IEC 20000 (Information Technology Service Management), ISO 22301 (Business Continuity Management Systems), and ISO/IEC 27001 (Information Security Management Systems).

The scope of CSIOS ISO certifications is the “Provision of Cyberspace Operations (Defensive, Offensive, and Information Network Operations) and Cybersecurity services to U.S. Federal customers worldwide.” The only one of its kind.

“We have the distinction of being the only provider of Cyberspace Operations and Cybersecurity services certified under quadruple International Organization for Standardization (ISO) certifications.” said Cesar Pie, President and CEO of CSIOS Corporation. Mr. Pie added, “By maintaining our cyber services certified under quadruple ISO standards, we continue to provide clear and tangible evidence that CSIOS operates at the highest level of technical standards. The successful completion of our annual surveillance audits demonstrates our ongoing commitment and pursuit of excellence for meeting our customer expectations, delivering the highest quality services, building customer confidence, exceeding basic requirements, and striving to achieve 100% customer satisfaction.”

Share article on social media or email:



Source link

X-Rite Announces New Display Calibration Solutions for Photographers and Filmmakers


News Image

“Professional and passionate photographers and filmmakers who are concerned about color perfection know that having properly calibrated and profiled displays is an essential and critical component for a successful and efficient creative workflow.”

X-Rite, the world leader in color management, measurement and communication technologies, today announces the immediate availability of the i1Display Studio and i1Display Pro Plus, technologically enhanced hardware and software solutions for color calibration and profiling of displays, laptops, and projectors.

The trusted i1Display Pro has been the professional choice for high-level, on-screen color accuracy for discerning photographers, imaging professionals, and display manufacturers for more than 8 years. X-Rite extends this legacy for photographers and filmmakers alike with the i1Display Studio, an easy-to-use, affordable, yet professional solution and the i1Display Pro Plus, the ultimate solution to color manage super-bright, HD, and HDR display technology.

i1Display Studio is the ideal solution for both passionate and professional photographers looking for professional color results in an easy-to-use format that doesn’t require in-depth knowledge of color science. It features both one-click presets as well as advanced easy-to-navigate wizard-driven options for more control. The i1Display Studio provides users everything they need in an easy-to-use solution that delivers high quality calibration and profile results in no time.

Key features include:

  • Technologically advanced i1Display Studio instrument: an ergonomically designed colorimeter with advanced optical technology and filter set
  • 3-in-1 functionality – designed to easily switch between display or projector profiling and ambient light capture
  • i1Studio software for display and projector profiling
  • Mobile Device Calibration with free ColorTRUE mobile app
  • Intelligent Iterative Profiling to accurately measure the color capabilities of a display
  • Custom control of white point, luminance, contrast ratio, and gamma
  • Color match up to four separate displays for color accuracy
  • Measurement and compensation of ambient lighting conditions
  • FlareCorrect™ for display surface flare measurement and compensation
  • Video Standards Support: NTSC, PAL SECAM, Rec. 709, Rec. 2020 and DCI-P3
  • Profile validation and reminder to view before and after results with included images or load your own

i1Display Pro Plus is ideal for filmmakers and photographers working with super-bright, HD, and HDR displays. This solution includes the ability to measure high luminance (brightness) levels as well as the ability to obtain correct neutral shadow detail levels and higher accuracy in dark colors with new Black Current Subtraction technology.

i1Display Pro Plus contains all the in-depth features found in i1Display Pro to profile monitors, projectors and mobile devices, plus these additional features:

  • Accurately measure luminance/brightness levels up to 2000 nits
  • Obtain correct neutral detail levels and higher accuracy in dark colors with new black current subtraction technology, especially beneficial on OLED displays or any display that can achieve close to zero black point
  • BT.1886 default gamma curve – the standard for HDTV – is especially beneficial for 3D LUT workflows and HDR supported displays to minimize clipping in dark area as well as achieve better behavior in blacks and smooth to ideal detail levels
  • USB-C compatible with included USB-C to USB-A adapter

Learn More

“Professional and passionate photographers and filmmakers who are concerned about color perfection know that having properly calibrated and profiled displays is an essential and critical component for a successful and efficient creative workflow.

The new i1Display Studio and i1Display Pro Plus, coupled with our current number one seller, the i1Display Pro, provides every level of user with optimally calibrated displays, projectors and mobile devices, consistently and easily. This ensures a user’s digital files will be viewed and shared accurately to enable faithful reproduction every time.” – Liz Quinlisk, Global Business Unit Manager, X-Rite Incorporated

New Kits

The two new i1Display solutions feature the industry’s most advanced colorimeter bundled with the latest display and projector profiling software to ensure unrivaled color accuracy and consistency now and in the future.

The new kits include:

*Each kit is offered at a reduced price compared to purchasing separately.

Availability

The new i1Display Studio, i1Display Pro Plus, and the new i1 Kits will be shipping in September from X-Rite (North America and Europe) online stores as well as from the company’s worldwide network of resellers.

For more information, please contact Brenda Hipsher:

brendah@macgroupus.com

About X-Rite

Founded in 1958, X-Rite Incorporated is a global leader in the science and technology of color and appearance. With Pantone, X-Rite employs more than 800 people in 11 countries. The company’s corporate headquarters are located in Grand Rapids, Mich., with regional headquarters in Europe and Asia and service centers across Europe, the Middle East, Asia, and the Americas. X-Rite offers a full range of solutions used by manufacturers, retailers, printers, photographers and graphic design houses to achieve precise management and communication of color and appearance throughout their processes. X-Rite products and services are recognized standards in the printing, packaging, photography, graphic design, video, automotive, paints, plastics, textiles and medical industries. For more information, visit xritephoto.com

About MAC Group

33 years ago, MAC Group started as a boutique marketing, sales and distribution group focusing on professional photographers. As the industry has evolved, so has MAC Group with their expansion into filmmaking, video, mobile, content creation and audio. Today, MAC Group is one of the leading companies of their kind with world-renowned brands offering products and education that enhances the lives of passionate content creators at every experience level. For more information, visit macgroupus.com

Share article on social media or email:



Source link

New BullGuard Commissioned Study Reveals Substantial Gaps Between Privacy Concerns And Actual Behaviors Of American, British and German Consumers


https://www.prweb.com/

BullGuard makes it simple to protect everything in your digital life – from your data, your identity, your privacy and your smart home.

“Accessing public Wi-Fi without the use of a VPN (Virtual Private Network), is akin to driving your car without insurance — sooner or later you’re going to end up paying the price for being negligent,” said Paul Lipman, CEO, BullGuard

Amid ongoing identity theft and privacy-related breaches, new research published today by cybersecurity company, BullGuard, revealed substantial gaps between consumers’ privacy concerns and their actual behaviors. The study shows 53% of Americans, 48% of Brits and 62% of Germans are concerned about privacy, but 74% of Americans, 80% of Brits, and 86% of Germans don’t use a VPN (Virtual Private Network) when accessing public Wi-Fi, with convenience trumping privacy and security risks in their rush to get online. A VPN empowers consumers with a highly effective, easy way to safeguard themselves when using public Wi-Fi from their smartphone, tablet or laptop, and adds an extra layer of security and privacy when used on the home network.

Unbeknownst to most consumers, hackers can easily spoof and set up malicious open Wi-Fi networks that appear to be legitimate (e.g. ‘Free Airport Wi-Fi’), but in fact intercept and record all network traffic, including people’s intimate personal data, and allow fraudsters to steal usernames, passwords, credit card details, bank account information and more. Alarmingly, approximately one in five Americans (19%) used a credit card while connected to public Wi-Fi, 17% of Brits performed online banking, and 14% of Germans accessed an insecure website — even though 53% of Americans, 48% of Brits and 62% of Germans believe their data is not secure while on a public Wi-Fi network and two-thirds of all survey respondents stated they are most worried about their banking information being hacked and stolen.

“Consumers are playing Russian Roulette with their personal data and privacy, opting for convenience over safety when using public Wi-Fi,” said Paul Lipman, CEO of BullGuard. “The research findings clearly indicate that Americans, Brits, and Germans do not feel safe online, yet they are ignoring their fears and risking financial theft, identity theft, account fraud and more in their quest to use public Wi-Fi. Accessing public Wi-Fi without the use of a VPN is akin to driving your car without insurance – sooner or later you’re going to end up paying the price for being negligent.”

The research also revealed 48% of Americans, 62% of Brits and 69% of Germans are only using antivirus (AV) software to protect their online information on their home Wi-Fi. AV software prevents, detects and removes malware and helps protect users from other threats such as ransomware, malicious URLs, phishing scams, botnet DDoS attacks and more, but it does not hide a consumer’s origin IP address or prevent others – including ISPs (Internet Service Providers) and government organizations – from monitoring a consumer’s online browsing activity, including what websites they visit, what they download or what services and applications they use.

“A disconnect currently exists in the minds of consumers between the benefits and differences of AV software and VPN. The research findings indicate a need to educate consumers that VPN is not simply a useful tool for streaming geo-locked content, but an integral component to safeguard their overall online security and privacy,” stated Lipman. “While antivirus software is essential for detecting and removing malware from your PC, smartphone and tablet devices, it offers no protection from having your personal data intercepted by a malicious hotspot or blocking your ISP from monitoring your online browsing activity.”

Additionally, a significant number of individuals (19% of Americans, 12% of Brits and 7% of Germans, respectively) use no additional methods and rely solely on their ISP and browser to keep their online information private and secure. This despite results that show consumers believe the following entities are tracking their online activities:

1.    Search engines such as Google (56% Americans, 63% Brits and 71% Germans)

2.    Internet Browser (51% Americans, 57% Brits and 57% Germans)

3.    Internet Service Provider (53% Americans, 58% Brits and 44% Germans)

4.    Online retailers like Amazon (46% Americans, 54% Brits and 61% Germans)

5.    Social media platforms such as Facebook (55% Americans and 62% Brits)*

6.    Messenger apps such as Facebook Messenger and WhatsApp (42% Americans and 51% Brits)*

7.    Social media platforms and messengers, e.g. Facebook and WhatsApp (65% Germans)**

8.    US government (52% Americans and 36% Brits)*

9.    UK government (15% Americans and 55% Brits)*

10.    German government (34% Germans)**


  • US and UK only; **Germany only

The BullGuard commissioned survey was conducted in August 2019 and queried a total of 5,000 adult consumers across the US, the UK, and Germany (2000 each in the US and UK, and 1000 in Germany). A press kit including graphs, charts, logos and other assets related to the research study can be accessed here. Journalists who are interested in the raw data, please contact bullguard@wearemgp.com.

About BullGuard

BullGuard is a multi-award winning, consumer cybersecurity company. We make it simple to protect everything in your digital life – from your data, your identity and your Smart Home. The BullGuard product portfolio extends to PCs, tablets and smartphone protection, and includes internet security, comprehensive mobile security, 24/7 identity protection and VPN, which provides the highest levels of privacy and protection. BullGuard released the world’s first IoT vulnerability scanner and leads the consumer cybersecurity industry in providing continuous innovation. Dojo by BullGuard is an award-winning intelligent defense system and service that provides the highest level of protection to consumers across all of their connected devices and smart homes. Dojo by BullGuard is the cornerstone of a Smart Home, ensuring a connected world where every consumer in every home, is smart, safe and protected. Follow us on Twitter @BullGuard, like us on Facebook at BullGuard, or learn more at https://www.bullguard.com.

All trademarks contained herein are the property of their respective owners.

###

Share article on social media or email:



Source link

Vendavo is Now ISO/IEC 27001:2013 Certified


News Image

Securing our data, particularly sensitive customer and partner data that resides within our SaaS production environments, is a critically important pillar for our business.

Vendavo, the market leader in commercial excellence solutions, today announced its ISO/IEC 27001:2013 certification.

Published by the International Standardization Organization (ISO), the ISO/IEC 27001:2013 standard is a renowned international security management system standard that specifies information security best practices and security controls.

“I’d like to congratulate our team that worked on this certification for a job well done,” said David Edwards, CTO, Vendavo. “Securing our data, particularly sensitive customer and partner data that resides within our SaaS production environments, is a critically important pillar for our business and this certification demonstrates we are following internationally-recognized security best practices.”

Vendavo equips and empowers companies around the globe to unleash their true commercial potential, claim their competitive edge, and become B2B performance leaders with intelligent pricing and sales enablement solutions.

##

About Vendavo

Vendavo powers the shift to digital business for the world’s most demanding B2B companies, unlocking value, growing margin and accelerating revenue. With the Vendavo Commercial Excellence platform, companies develop dynamic customer insights and optimal pricing strategies that maximize margin, boost sales effectiveness and improve customer experience. With an annual margin improvement totaling more than $2.5 billion across companies in chemicals, distribution, high-tech and manufacturing, Vendavo delivers cutting-edge analytics and deep industry expertise that help companies stay one step ahead. Vendavo is headquartered in Denver, CO and has offices around the globe. Learn more at Vendavo.com.

Share article on social media or email:



Source link

Teracube Launches on Kickstarter Bringing a Sustainable, Affordable Smartphone to Market


News Image

I’ve always envisioned changing the disposable nature of the consumer electronics industry by designing high-quality products that last longer,” said Sharad Mittal, Co-Founder of Teracube. “We want to talk about our footprint and show people how small changes can make a huge impact.

Teracube launches today on Kickstarter bringing an affordable smartphone with a fast octa-core processor, dual rear cameras, dual back cameras, high-speed processing and extensive storage space to tech lovers everywhere. Teracube is also the world’s first and only cutting-edge smartphone that comes with a 4-year warranty.

“I’ve always envisioned changing the disposable nature of the consumer electronics industry by designing high-quality products that last longer,” said Sharad Mittal, Co-Founder of Teracube. “This is why we are offering a four-year warranty on Teracube. We want to talk about our footprint and show people how small changes can make a huge impact.”

Teracube’s 4-year warranty promises high performance for years to come. It not only eliminates the typical investment of a new phone every few years, but it also ensures users can keep one piece of personal technology for a longer period of time. In turn, this can significantly decrease the amount of electronic waste over time.

With Teracube, users don’t have to worry about sacrificing typical smartphone features. In fact, Teracube’s dual rear cameras take vivid and sharp pictures. One camera captures the depth of the objects while the second captures vibrant colors and other details. The front camera utilizes artificial intelligence technology to take beautiful self portraits that users can share with the world.

Teracube also has an octa-core processor which enables it to carry out more advanced tasks, such as handling high resolution videos and graphic-heavy games without draining the battery. The octa-core processor also gives Teracube a much faster load time. With 128GB of storage and 6GB RAM, users won’t have to worry about running out of space and can experience great performance for years to come. Plus, with its 3400 mAh battery, Teracube will stay charged throughout the day. Last but not least, Teracube’s 6.2” Full HD+ IPS display, Teracube offers an immersive viewing experience.

In terms of durability, Teracube’s display is constructed with sturdy Gorilla Glass to handle the demands of everyday life. The metal alloy frame provides ultimate strength making Teracube long lasting. Teracube is backed by hassle-free warranty, covering all parts, performance, labor, and two-way shipping at no cost. It even includes free battery change and express replacement. Teracube will be available for pre-order on Kickstarter for $175 (MSRP $349). The screen size is 6.2” and the phone is 157mm x 75.5mm x 7.7mm. The phone supports AT&T, MetroPCS, T-Mobile, Cricket, Lyca and more. For more information about the campaign, or to place a pre-order, please visit pr.go2.fund/teracube.

About Teracube Inc.

Teracube is an innovative technology development company out of Redmond, Washington. The founders Sharad Mittal and Anthony Tsim are both excited to bring Teracube to market. Mittal is a passionate environmentalist and has more than 10 years of experience in consumer electronics design and retail, and more than 10 years in software development. They want to have a different conversation with their customers than most other brands. Teracube wants to create awareness on the environmental impact due to the vast amount of e-waste produced from the growing number of discarded phones. They believe small changes can make a huge difference for our planet. For more information, visit http://www.myteracube.com.

Share article on social media or email:



Source link

Q Software and Syntax Join Forces to Deliver Automated Security and License Audits of JD Edwards and Oracle E-Business Suite to Managed Services customers


Q Software

“We’re excited to work with Q Software, recognised experts in ERP security, audit and compliance, to offer our customers innovative services which will transform their audit experience.” – Sarah Mills, Senior Director, JDE Managed Services at Syntax.

Oracle Partners Q Software Global and Syntax have today announced a partnership agreement enabling Syntax to add Q Software’s powerful QCloud automated security and license auditing solutions to their Managed Service offerings to JD Edwards and Oracle E-Business Suite users.

With these Cloud-based services, Syntax will proactively monitor for issues that could jeopardize the integrity of their clients’ ERP systems, leave them vulnerable to fraud, and incur unforeseen damages and costs.

“Our Managed Service customers rely on us to keep their ERP systems running smoothly, and we’re always looking for new ways to nurture and safeguard the engines that drive their businesses,” said Sarah Mills, Senior Director, JDE Managed Services at Syntax. “We’re excited to work with Q Software, recognised experts in ERP security, audit and compliance, to offer our customers innovative services which will transform their audit experience.”

“Syntax has been a valued Q Software Partner for several years, introducing our on-premise solutions to their customer base,” said Mike Hoskin, Vice President of Sales at Q Software. “We’re delighted that they’ve decided to add QCloud to their Managed Services portfolio.”

QCloud Security Audit highlights key risks, such as Segregation of Duties conflicts and users with access to Critical Objects. It also identifies weaknesses that are often overlooked, such as inactive users or redundant roles, which could be exploited by a fraudster.

QCloud License Audit gives detailed statistics on actual ERP module usage, helping customers to stay compliant with their Oracle License agreement and providing evidence for license negotiations.

Q Software (booth 534) and Syntax (booth 517) will showcase QCloud at Oracle OpenWorld in San Francisco from 16-19 September.

About Syntax:

Since 1972, Syntax has been providing comprehensive technology solutions to businesses of all sizes with thousands of customers trusting Syntax with their IT services and ERP needs. Today, Syntax is a leading Managed Cloud Provider for Mission Critical Enterprise Applications. Syntax has undisputed strength to implement and manage ERP deployments (Oracle, SAP) in a secure, resilient, private, public or hybrid cloud. With strong technical and functional consulting services, and world class monitoring and automation, Syntax serves corporations across a diverse range of industries and markets. Syntax has offices worldwide, and partners with Oracle, SAP, AWS, Microsoft, IBM, HPE, and other global technology leaders. Learn more about Syntax at http://www.syntax.com.

About Q Software:

Oracle Gold Partner Q Software provides on-premise and Cloud-based Audit, Security Control, and Efficiency solutions to JD Edwards, Oracle E-Business Suite and Oracle ERP Cloud customers. These solutions help customers protect their businesses from fraud, while significantly reducing the cost, effort and complexity of managing risk and achieving regulatory compliance. Founded in the UK in 1996, the company has over 300 customers in 58 countries, serviced by offices in the United States, the United Kingdom, Australia and a global network of sales and service partners. http://www.qsoftware.com

Trademarks

Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners.

Share article on social media or email:



Source link

California Regional MLS (CRMLS) Signs Agreement with Absolute Strategic Agent to Offer IDX MLS Links for CRMLS Users


Image of Absolute Strategic Agent IDX Links for CRMLS Members

Absolute Strategic Agent IDX Links for CRMLS Members

“When we saw how Absolute Strategic Agent could help us generate better IDX links, we jumped at the opportunity.” -Art Carter, CEO of CRMLS.

Teams at CRMLS and Absolute Strategic Agent worked together to offer new basic IDX links for all of their users.

“We believe quality IDX solutions matter to professionals and consumers,” said CRMLS CEO Art Carter. “When we saw how Absolute Strategic Agent could help us generate better IDX links, we jumped at the opportunity.”

“We are honored to be working so closely with the great people and users of CRMLS,” said Richard Uzelac, CEO of Absolute Strategic Agent. “Throughout the months of planning for this change, we have collaborated with the CRMLS team to provide high-quality basic IDX links for their users that we see as a nice upgrade for the basic links previously offered,” Richard Uzelac added.

IDX links generated directly through Matrix, through approved IDX vendors, and via RESO-certified data feeds will not be affected. Only links generated through the IDX Link Generator on CRMLS.org from 2012 onward will be changing.

Here’s what the new-and-improved IDX Plus version looks like to the right.

In addition to the IDX links at no additional cost, Absolute Strategic Agent’s Premium IDX with Full Website is also available with major discounts on CRMLS.org. The embedded video shows the upgraded products are over 50% off for CRMLS members!

“We at Absolute Strategic Agent are also proud to be featured in the CRMLS Marketplace to offer our Premium IDX with Full Website as an option for CRMLS users that want more for their online presence and marketing,” said Richard Uzelac.

CRMLS user agents will be able to upgrade to the Premium IDX with Full Website for over 50% off retail prices. Marketing and Advertising programs as also available from Absolute Strategic Agent.

About California Regional MLS

California Regional MLS is the nation’s largest and most recognized subscriber-based MLS, dedicated to servicing 96,000 real estate professionals from 34 Associations, 3 Boards of REALTORS® and 1 MLS. CRMLS is the industry powerhouse and thrives on providing the most relevant products and services to its subscribers. For more information on CRMLS visit http://www.crmls.org.

About Absolute Strategic Agent Inc.

Based out of Thousand Oaks, CA, Absolute Strategic Agent Inc. offers professional websites for real estate agents and brokerages as well as IDX home search software that shows listings and available properties in real-time to potential buyers online. Since 2010, Absolute Strategic Agent Inc. has remained committed to offering savvy software solutions and digital marketing strategies that give real estate professionals an online platform optimized for generating more leads and revenue. Absolute Strategic Agent Inc. keeps new and established real estate professionals on the cutting-edge for their digital marketing and advertising strategies. For more information about their full-suite of services, contact their team for a free consultation at (805) 413-7895 or visit http://www.AbsoluteStrategicAgent.com

About Richard Uzelac, CEO of Absolute Strategic Agent Inc.

Founder of GoMarketing and Absolute Strategic Agent, Richard Uzelac is a former award-winning Realtor and a real estate company owner in both New Jersey and California. Richard Uzelac is also the former Senior Director of Production for Realtor.com Richard Uzelac has helped many local businesses and real estate professionals increase their leads and sales via digital marketing these last 15 years, Richard Uzelac is also available as a Real Estate Technology Speaker, Seminar Provider and Consultant. For more information, contact Richard Uzelac at 805.413.7895.

Share article on social media or email:



Source link

Tala Security’s 2019 State of the Web Report Finds 98 Percent of U.S. Alexa 1000 Websites Are Inadequately Secured Against Magecart and Other Advanced Attacks


News Image

“The number one enemy of enterprise website security is lack of awareness about what’s ‘under the hood’ from an integration and architecture standpoint. This is basically a websites’s ‘supply chain’,” said Aanand Krishnan, Founder & CEO of Tala Security.

Tala Security, the provider of security solutions protecting enterprise websites and web applications against advanced client-side attacks like Magecart, today announced the Tala 2019 State of the Web Report. The report, which tested U.S. websites within the Alexa 1000 ranking, educates enterprises about the critical and under-recognized security threats related to their web assets and the third party vendors that support them.

Today, the primary connection point between companies and their customers is the corporate website, which, in addition to acting as an educational resource, is also a key driver of corporate revenue for most businesses. Most websites are loaded with client-heavy JavaScript applications that execute web code to enrich the customer experience, provide compelling content and images and assist in engagement. The Tala 2019 State of the Web Report highlights that this architecture, in an effort to make sites more attractive and useful, introduces significant vulnerabilities that enable client-side website attacks – such as Magecart – to impact customer browsing sessions and can lead to theft of sensitive user personally identifiable information (PII) and financial data.

In August, the PCI Security Standards Council (PCI SSC) and the Retail and Hospitality ISAC issued a joint bulletin to address the growing threat of online skimming to payment security. The vulnerabilities specifically leveraged to launch these accelerating attacks are the main focus of this data analysis. Raising awareness of the critical website security flaws identified in the report are its main goal. “These attack techniques are of increasing significance to the retail and hospitality industry…It is important that businesses grow in their awareness of the nature of these attacks and of the security controls necessary to detect and defeat them,” stated Carlos Kizzee, Vice President, Intelligence, Retail and Hospitality ISAC. “We must endeavor to ensure that focused attention, commitment and peer collaboration in e-commerce cybersecurity efforts within the retail and hospitality industry outpaces the growth and evolution of threats such as these.”

Key findings from the Tala 2019 State of the Web Report highlight that the majority of global brands fail to deploy adequate security to guard against client-side attacks, including:

  •     The average website relies on 31 third-parties. Nearly two-thirds (~63 percent) of the externally loaded JavaScript code executed in the browser is either written by and/or managed by third-parties.
  •     98 percent of websites use forms to collect PII and financial data from the user. This form data is defined by the website owner’s code architecture to be purposefully sent to an average of 1.6 domains. However, in reality, due to the reliance on third-party integrations, form data is exposed to an average of 15.7 third-party domains. In other words, user form data is exposed to an order of magnitude more domains than intended by the website owner.
  •     87 percent of websites were found to include innerHTML, which allows JavaScript code to manipulate a website being displayed. InnerHTML is a common injection point attackers leverage to launch Cross-Site Scripting (XSS) attacks.
  •     Dynamic JavaScript code was found to exist in more than 60 percent of websites. This code is not loaded statically, but is instead loaded via a static JavaScript command. This kind of “piggybacking” creates a more expansive attack surface for hackers to exploit.
  •     Only 27 percent of websites were found to deploy standard-based security such as content security policies (CSP) capable of guarding against vulnerabilities introduced by the significant reliance on JavaScript or to limit unauthorized access and distribution of form data.
  •     94 percent of website operators that deploy CSP have implemented a set of policies that are not capable of guarding against client-side attacks. CSP and other standards-based security implementations exist but deploying these at scale requires substantial administration and has been proven challenging.

“The number one enemy of enterprise website security is lack of awareness about what’s ‘under the hood’ from an integration and architecture standpoint. This is basically a website’s ‘supply chain’,” said Aanand Krishnan, Founder & CEO of Tala Security. “The fundamental issue with the way today’s websites are secured is that user data is greatly exposed to third-party applications and services that have not been properly vetted. While Magecart is the most well-known, there are many other attacks that leverage client-side vulnerability. It’s imperative that organizations keep security top-of-mind and expand their perspective on what has become a pervasive attack vector – the organization’s website.”

Methodology

For each of the Alexa 1000 websites, Tala used its analysis engine, which evaluates 50 unique indicators of a web page’s architecture and integrations to document code, content and data change on the website. The findings represented in the Tala 2019 State of the Web Report are the result of aggregate study of the Alexa 1000 to define statistically relevant insights that indicate mass vulnerability to client-side website attacks such as cross-site scripting (XSS), Magecart, user data leakage, content integrity attacks, ad injections and session redirects. These vulnerabilities are capable of significantly impacting the secure operation of nearly every website included in the study.

Download the Tala 2019 State of the Web Report here: https://go.talasecurity.io/state-of-the-web-report-2019

About Tala Security

Tala Security protects modern websites and web applications from critical and growing threats, such as cross-site scripting (XSS), Magecart, website supply-chain attacks, clickjacking and others. Tala defends against such attacks by automating the deployment and dynamic adjustment of browser-native, standards-based security controls such as Content Security Policy (CSP), Subresource Integrity (SRI), HTTP Strict Transport Security (HSTS) and other web security standards. The activation of browser-native security controls provides comprehensive security without requiring any changes to the application code and with almost no impact to website performance. Tala’s product is powered by an AI-assisted analytics engine that evaluates over 50 unique indicators of a web page’s behavior. The analytics engine provides comprehensive risk analysis and enables Tala to automate the generation, implementation and updating of browser-native security policies. Tala’s product also provides customers with alert analytics and incident management. Tala serves large website operators in verticals such as financial services, online retail, payment processing, hi-tech, fintech and education. Learn more at http://www.talasecurity.io

Share article on social media or email:



Source link

Trucking Industry Battle: Proposed Drive-Time Regulations


Advanced Training Systems is a technology and engineering firm that has revolutionized the design and manufacture of high-tech simulator systems to improve training for operators of all types of motor-powered vehicles

John Kearney, CEO of Advanced Training Systems, underscores the need for simulator training in light of the proposed drive-time regulations.

“Fatigue is a real factor in driving, and while there is no magic way to eliminate it, it is something that simulation training can help drivers recognize and deal with.”

In mid-August, the Transportation Department’s Federal Motor Carrier Safety Administration (FMCSA) proposed a set of changes to the hours-of-service rules that govern the hours truckers can spend behind the wheel and the total number of breaks they are required to take[1]. “This proposal addresses some real issues and frustrations confronting truckers and the industry,” says John Kearney, CEO of Advanced Training Systems. Kearney, whose company is a leading designer and manufacturer of virtual simulators for driver training. “However, we must always make safety, both for drivers and other motorists, our number-one concern.”

Current hours-of-service rules include the following provisions:

1.    Truckers can drive for a cumulative daily maximum of 11 hours following 10 consecutive hours off duty.

2.    Drivers are required to take an off-duty period of at least 30 minutes after a maximum of eight consecutive hours of driving.

3.    They cannot drive beyond the 14th consecutive hour after coming on duty[2].

The proposed new rules include these suggested revisions:

1.    Drivers would be able to take a break while on duty but not driving–i.e. while the truck is stationary and waiting to be loaded or unloaded.

a.    Under current rules, stationary on-duty hours count against the driver’s allowable daily driving time.

2.    Drivers would be permitted to “pause” the 14-hour driving window for an off-duty break of up to three hours.

a.    This would create a possible 17-hour workday, with the provision that the driver still takes 10 consecutive hours off duty at the end of the shift[3].

Many drivers are paid by the mile, which means that excessive wait time at loading docks—known in the trade as “detention time”—costs drivers money. According to a recent FMCSA report, detention time costs the average driver $1,281 to $1,534 per year, or 3-3.6 percent of the driver’s total annual income. The report also estimates that excess detention time raises the likelihood a driver will be involved in a crash by 6.2 percent, due to a consequent urge to make up for lost time[4].

“We can argue about what specific hours-of-service limits should be,” Kearney said. “No one questions that reasonable limits should exist and should be enforced. Fatigue is a real factor in driving, and while there is no magic way to eliminate it, it is something that simulation training can help drivers recognize and deal with. Given that, and given the seriousness of this whole issue, I would suggest that one urgently needed change in FMCSA regulations is to make simulator experience a mandatory part of commercial driver training.”

Whether or not the proposal goes through, simulator training can help prepare drivers for long hours on the road–before they even hit the road.

About Advanced Training Systems LLC:

Advanced Training Systems (ATS) is a technology and engineering firm that has revolutionized the design and manufacture of high-tech simulator systems to improve training for operators of all types of motor-powered vehicles. ATS, the holder of multiple patents in its field, is dedicated to providing cutting-edge adaptive training at an affordable cost to all involved in the transportation industry, resulting in more qualified drivers/operators and safer streets. For more information, visit http://www.atstrainingsystems.com.

1.    Lardner, Richard, “Administration moves to ease drive-time rules for truckers,” Associated Press, July 1, 2019.

2.    “Summary of Hours of Service Regulations,” Federal Motor Carrier Safety Administration.

3.    Lardner, Richard, “Government moves toward easing drive-time rules for truckers,” Associated Press, August 14, 2019.

4.    Rafter, Michelle, “Loading Dock Wait Times Cost Truckers Over $1 Billion Annually,” TRUCKS, February 4, 2018.

# # #

Share article on social media or email:



Source link

Financial Poise™ Announces “Cybersecurity & Data Privacy 2019,” a New Webinar Series Premiering September 24th at 1:00 PM CST Through West LegalEdcenter™


News Image

This series explores the various laws and regulations which govern businesses, and how to have an information security policy that will protect the company from a data breach.

About the Series: This series explores the various laws and regulations which govern businesses both in the US and abroad, as well as how to implement and enforce an information security policy to protect your company and limit any damage from a data breach.

About the Episode: There is no federal law governing privacy and data security applicable to all US citizens. Rather, individual states and regulatory agencies have created a patchwork of protections that may overlap in certain industries. This webinar provides an overview of the many privacy and data security laws and regulations which may impact your business, from the state law protecting personal information to regulations covering the financial services industry to state breach notification laws.

To learn more, click here.

The webinar will be available on-demand after its premiere. As with every Financial Poise Webinar, it will be an engaging and plain English conversation designed to entertain as it teaches.

About Financial Poise

Financial Poise has one mission: to provide reliable plain English business, financial and legal education to investors, private business owners and executives, and their respective trusted advisors. Financial Poise content is created by seasoned, respected experts who are invited to join our Faculty only after being recommended by current Faculty Members. Our editorial staff then works to make sure all content is easily digestible. Financial Poise is a meritocracy; nobody can “buy” their way into the Financial Poise Faculty. Start learning today at https://www.financialpoise.com/.

Share article on social media or email:



Source link