Tag Archive for: conference

Upcoming IAEA Conference on Computer Security: Addressing Security for Safety


The growing range and number of cyber threats means that there is no single facility immune to cyber-attacks. In the case of nuclear installations and radiological facilities, computer-controlled systems are extensively used to support their core functions and operations. Information and computer security, therefore, are an essential part of nuclear security measures, along with physical protection, both for nuclear facilities and nuclear or other radioactive material facilities.  

“The heightened awareness of cyber threats urges for further investment of resources towards improving computer security for nuclear security,” said Elena Buglova, Director of the IAEA’s Division of Nuclear Security. The IAEA offers countries assistance in addressing their needs in the area of computer security. In 2022, the IAEA organized 46 computer security-related events, an increase of 28 per cent from 2021, with a focus on national-level support for computer security regulations and inspections, and computer security exercises. 

The IAEA is holding an International Conference on Computer Security in a Nuclear World: Security for Safety, from 19 to 23 June 2023 in Vienna, Austria, bringing together the international community to discuss developments and progress in protecting nuclear and other radioactive material activities against cyber-attacks.  

The conference, the second of its kind with the first held in 2015, will provide the opportunity for countries to discuss and exchange about key elements of computer security, such as state level strategies, regulations, implementation of a computer security programme with protective measures, supply chain and incident response, as well as capacity building courses and exercises offered by the IAEA. 

“Every participant will benefit from the technical sessions planned in the upcoming conference, as well as from a variety of hands-on demonstrations to be showcased,” said Buglova.  

The conference will provide a global forum for competent authorities of IAEA member countries, nuclear operators, integrators and suppliers of security systems and other relevant international and industry organizations and institutions. It will feature…

Source…

Week in review: PaperCut vulnerabilities, VMware fixes critical flaws, RSA Conference 2023


The week in security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

RSA Conference 2023
RSA Conference 2023 took place at the Moscone Center in San Francisco. Check out our microsite for related news, photos, product releases, and more.

Overcoming industry obstacles for decentralized digital identities
In this Help Net Security interview, Eve Maler, CTO at ForgeRock, talks about how digital identities continue to play a critical role in how we access online services securely. Maler also highlights the challenges encountered by various industries in implementing decentralized digital identities.

PaperCut vulnerabilities leveraged by Clop, LockBit ransomware affiliates
Clop and LockBit ransomware affiliates are behind the recent attacks exploiting vulnerabilities in PaperCut application servers, according to Microsoft and Trend Micro researchers.

Common insecure configuration opens Apache Superset servers to compromise
An insecure default configuration issue (CVE-2023-27524) makes most internet-facing Apache Superset servers vulnerable to attackers, Horizon3.ai researchers have discovered.

3CX breach linked to previous supply chain compromise
Pieces of the 3CX supply chain compromise puzzle are starting to fall into place, though we’re still far away from seeing the complete picture.

GitHub introduces private vulnerability reporting for open source repositories
GitHub has announced that its private vulnerability reporting feature for open source repositories is now available to all project owners.

Google Authenticator updated, finally allows syncing of 2FA codes
Google has updated Google Authenticator, its mobile authenticator app for delivering time-based one-time authentication codes, and now allows users to sync (effectively: back up) their codes to their Google account.

VMware fixes critical flaws in virtualization software (CVE-2023-20869, CVE-2023-20870)
VMware has fixed one critical (CVE-2023-20869) and three important flaws (CVE-2023-20870, CVE-2023-20871, CVE-2023-20872) in its VMware Workstation and Fusion virtual user session software.

Google adds new risk assessment tool for Chrome extensions
Google has made available a new tool for…

Source…

USENIX Security ’22 – Dos and Don’ts of Machine Learning in Computer Security