<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Hacktory</title>
    <description>The latest articles on DEV Community by Hacktory (@hacktory).</description>
    <link>https://dev.to/hacktory</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F388684%2F405afc48-ecb7-40cf-98f3-27c0c4dfe898.jpeg</url>
      <title>DEV Community: Hacktory</title>
      <link>https://dev.to/hacktory</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/hacktory"/>
    <language>en</language>
    <item>
      <title>Universities under attack</title>
      <dc:creator>Hacktory</dc:creator>
      <pubDate>Wed, 30 Dec 2020 11:36:25 +0000</pubDate>
      <link>https://dev.to/hacktory/universities-under-attack-3bi4</link>
      <guid>https://dev.to/hacktory/universities-under-attack-3bi4</guid>
      <description>&lt;p&gt;In 2020, we've tremendous changes in our daily lives. Now, we study and work remotely, and that has a massive impact on IT and cybersecurity. While &lt;em&gt;the number of cyberattacks has tripled&lt;/em&gt;, our approach to security remains the same.&lt;/p&gt;

&lt;p&gt;In July and August alone, the &lt;a href="https://edtechnology.co.uk/cybersecurity/20-rise-in-cyber-attacks-on-global-education-sector-in-last-eight-weeks/"&gt;number of weekly attacks&lt;/a&gt; on educational organizations in the US increased by 30% (608 total incidents). The average number of weekly attacks on the European academic institutions in the same period rose by 24% (to 793 incidents). Most of these attacks were aimed at information disclosure. This is a threatening trend, and the new wave of the pandemic and another shift to distance learning can only make it worse. &lt;/p&gt;

&lt;h2&gt;
  
  
  Why are schools so attractive to hackers?
&lt;/h2&gt;

&lt;p&gt;Colleges and universities are a mother lode for cybercriminals because they store tons of personal data. Higher education institutions collect social security numbers, passport details, scholarship data, and a host of other personal information, all of which is precisely what hackers need. With stolen personal data, they can organize successful phishing campaigns.&lt;/p&gt;

&lt;p&gt;Besides, universities own intellectual property, including research data and exclusive access to thousands of publications university libraries have. Some of this information could be sold to an interested third party and damage the victim institution.&lt;/p&gt;

&lt;p&gt;The attacks can also be aimed at hijacking university email accounts. The point is that virtually every email system today employs some form of anti-spam filters. They analyze incoming mail and decide whether a letter should be delivered to the recipient. Many rules help identify potential spam, and some parameters are pretty straightforward. For example, it turns out that letters coming from .edu addresses are usually deemed trustworthy and are less likely to end up in the spam folder. So, valid .edu email accounts are very suitable for phishing attacks and can be used to deliver malicious attachments or links with a high success rate. &lt;/p&gt;

&lt;h2&gt;
  
  
  How do attackers break into a school's system?
&lt;/h2&gt;

&lt;p&gt;Educational institutions are relatively easy targets because they often do not maintain cybersecurity properly. Most students use their own laptops, tablets, and phones, which is a considerable threat. Incorrectly configured systems, simple passwords, and absent precautions could lead to inadvertent disclosure of confidential information.&lt;/p&gt;

&lt;p&gt;Phishing attacks are still widespread. In August 2018, over 300 fake university websites were &lt;a href="https://www.ncsc.gov.uk/report/the-cyber-threat-to-universities"&gt;discovered&lt;/a&gt; in 14 countries. Malicious emails redirect victims redirected to fake websites with login pages designed to steal user credentials. Once they are entered, the victim is redirected to the legitimate university website.&lt;/p&gt;

&lt;p&gt;Ransomware is another major threat for universities and colleges. It encrypts data and threatens to disclose or destroy it unless a ransom is paid. For example, in August 2020, the &lt;a href="https://www.zdnet.com/article/university-of-utah-pays-457000-to-ransomware-gang/"&gt;University of Utah&lt;/a&gt; was attacked by the NetWalker ransomware. The attackers encrypted the data and threatened to publish student details online, prompting the university to pay a ransom of $ 457,000. The &lt;a href="https://www.zdnet.com/article/university-of-california-sf-pays-ransomware-hackers-1-14-million-to-salvage-research/"&gt;University of California&lt;/a&gt;, San Francisco, has also fallen victim to NetWalker. The university decided to pay $1.14 million to recover decrypted files.&lt;/p&gt;

&lt;h2&gt;
  
  
  Could students be a threat?
&lt;/h2&gt;

&lt;p&gt;Sometimes students become attackers. They move freely across campus, which makes it hard to track down the source of an attack. As was shown by a &lt;a href="https://www.lgfl.net/cybercloud/securityaudit"&gt;security audit&lt;/a&gt; of 400 British schools, the students were responsible for 20% of the incidents.&lt;/p&gt;

&lt;p&gt;What usually motivates students to attack the school's systems is their desire to change their grades or exam results. &lt;a href="https://www.edweek.org/leadership/tech-savvy-students-hack-into-school-computers/2010/06"&gt;Such cases&lt;/a&gt; are quite common. For example, it happened in the Winston Churchill High School in Maryland. A student of Tesoro High School, California, was put on trial for fixing grades. Two students of Haddonfield Memorial High School in New Jersey were charged for breaking into the school's system's secured areas. They used a keylogger to get the necessary passwords. Finally, an &lt;a href="https://www.standard.co.uk/news/london/university-of-greenwich-website-hacked-by-disgruntled-former-student-a3274671.html"&gt;expelled student of the University of Greenwich&lt;/a&gt; went as far as hacking the university website to ask the management to take him back.&lt;/p&gt;

&lt;h2&gt;
  
  
  How can universities protect themselves?
&lt;/h2&gt;

&lt;p&gt;Higher education institutions continue to be an attractive target for cybercriminals, especially with the spread of distance learning. Colleges and universities must adopt stronger strategies to ward off attacks and protect their data.&lt;/p&gt;

&lt;p&gt;Education and training are useful to minimize the risk of cyber incidents. It is critical to have robust security measures in place and maintain the cybersecurity awareness of the staff. There are so many courses to fit any demand. Yet, boring lectures, outdated textbooks, and complex tasks do not give the expected results. On the opposite, &lt;a href="https://hacktory.ai/"&gt;gamified cybersecurity courses can effectively help schools change their security practices and ensure their systems and data are safe&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>learning</category>
    </item>
    <item>
      <title>Unaware web application developers as a threat to cybersecurity</title>
      <dc:creator>Hacktory</dc:creator>
      <pubDate>Mon, 31 Aug 2020 12:29:42 +0000</pubDate>
      <link>https://dev.to/hacktory/unaware-web-application-developers-as-a-threat-to-cybersecurity-1c08</link>
      <guid>https://dev.to/hacktory/unaware-web-application-developers-as-a-threat-to-cybersecurity-1c08</guid>
      <description>&lt;p&gt;With the development of information systems, threats are becoming more serious every year, and the damage is estimated at millions and billions of dollars. As for the first half of 2019 alone, more than 1276 cases of confidential information leakage were published and registered in the world (based on research by the InfoWatch analytical center), which is 22% more than the number of incidents recorded for the same period of 2018.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources of threats
&lt;/h2&gt;

&lt;p&gt;It is noteworthy that according to &lt;em&gt;InfoWatch&lt;/em&gt;, data leakage is the result of the internal violation influence in 55.6% of the considered cases. In 44.8% of cases, unprivileged company employees were found guilty of information leakage, and in less than 2% of cases top managers of organizations and top personnel caused security issues. &lt;br&gt;
One of the high-profile cases is the &lt;em&gt;theft of data 8,000 Coca Cola employees&lt;/em&gt;. Approximately 13% of personal information was compromised in the course of the incident caused by a former employee fault.&lt;/p&gt;

&lt;h2&gt;
  
  
  Making employees aware
&lt;/h2&gt;

&lt;p&gt;Today, it is extremely important for large companies to pay attention to the employees' training and the increase of their professional skills in the area of cybersecurity in order to reduce the number of information leakages. Indeed, often the staff does not know about all types of phishing, Trojans, and other threats that were created with the purpose of tricking into forcing unaware users to unwanted “cooperation”. In this way, employees often serve as the main target for attacks without actually realizing that they are becoming a threat to the security of their own company. However, ignorance is no excuse. For the company, confidential information leaks or personal data of users threatens with a loss of reputation and multi-million fines, and for an employee it may turn a dismissal as a minimum.&lt;/p&gt;

&lt;h2&gt;
  
  
  What about IT specialists?
&lt;/h2&gt;

&lt;p&gt;For IT professionals, the ability to write clear and secure code is extremely important. Depending on your programming language and subject area, you may need to beware of buffer overflows, XXS, SQL injections, and other security problems. You can study them and try to avoid. &lt;br&gt;
The notion that security is not a developer's job is not quite true. A good web developer should take cyber threats into account when working with applications to protect employers and end users. It is also worth mentioning that the cheaper and more reliable way is to ensure safety during the development phase, rather than extinguish the fire after the product is released. Hackers don’t need many vulnerabilities to cause havoc, they only need one.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to reduce risks?
&lt;/h2&gt;

&lt;p&gt;As mentioned above, in order to reduce the risks of corporate network "infection" and data leakage, it is necessary not only to update the software, but also raise employee awareness regularly. It is software flaws and human errors that make malware notorious. &lt;br&gt;
Building a cybersecurity culture begins with the fact that every employee (from accountant to developer) regularly undergoes mandatory orientation training. Interest in cybersecurity issues should be encouraged so that developers are aware of security issues. &lt;br&gt;
It is necessary to discuss security issues during the development process. Make it a hot topic to share and read about. Cybersecurity should be part of the discussions surrounding every development project.&lt;br&gt;
To minimize risks, many organizations are constantly looking for new ways to deal with possible leaks. One way is corporate training. The traditional idea of what corporate training is, how it should be carried out, and who should be aimed at, is no longer relevant. The most effective training is when it is supported by a specific practical context, the acquisition of new experience. Today there are many different teaching methods, the most popular are: lectures, video tutorials, seminars, trainings, online courses.&lt;br&gt;
Unaware staff can cause multimillion-dollar damage to the company's budget, as well as undermine its credibility. However, there is an option not to lose money, but to save or even increase. It is better to convert money into knowledge and protect the future of the company by giving an opportunity for staff to learn new skills and remain the best in their area, isn’t it?&lt;/p&gt;

</description>
      <category>security</category>
      <category>webdev</category>
    </item>
    <item>
      <title>5 compelling reasons to take an online cybersecurity course</title>
      <dc:creator>Hacktory</dc:creator>
      <pubDate>Mon, 18 May 2020 14:06:07 +0000</pubDate>
      <link>https://dev.to/hacktory/5-compelling-reasons-to-take-an-online-cybersecurity-course-3gjm</link>
      <guid>https://dev.to/hacktory/5-compelling-reasons-to-take-an-online-cybersecurity-course-3gjm</guid>
      <description>&lt;p&gt;In recent years, the number of cyber attacks and leaks of confidential information has increased by several times. As new cybercrime cases get mentioned in the press more and more often, it becomes clear that there's an acute need for cyber security-oriented professionals among organizations.&lt;/p&gt;

&lt;p&gt;It's no surprise that information security analysts have been taking leading positions for several years now, according to statistics of Best Jobs U.S. News Ranking. This specialty is believed to occupy the fifth place in the ranking of the best technological vacancies of 2020 and will be included in the top 20 STEM-professions, according to &lt;a href="https://money.usnews.com/careers/best-jobs/information-security-analyst"&gt;forecasts&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Meanwhile, experts are discussing the duration of the cybersecurity crisis caused by a &lt;a href="https://www.csoonline.com/article/3120998/zero-percent-cybersecurity-unemployment-1-million-jobs-unfilled.html"&gt;shortage&lt;/a&gt; of hands and heads, and &lt;a href="https://cybersecurityventures.com/career-news/"&gt;predict&lt;/a&gt; "the top 5 jobs in the cybersecurity area that will bring thousands of dollars."&lt;/p&gt;

&lt;p&gt;The world is changing, and so are higher education perceptions. Today, it's unnecessary to spend 4-5 years at a university in case you think to become a specialist in any professional sphere. It's enough to have self-discipline, to be aware of your goals, and have access to the Internet.&lt;/p&gt;

&lt;p&gt;Often during their university years, a person gets applied skills and doesn't particularly understand how to put acquired knowledge into practice. In this case, online courses can help systemize large amounts of information. Depending on a course, a student will be able to apply the gained knowledge in practice (for example, a simulated threatscape like &lt;a href="https://hacktory.ai/"&gt;Hacktory&lt;/a&gt;) and understand the direction to move. Some courses offer an internship program after a successful completing of a final test.&lt;/p&gt;

&lt;p&gt;Apart from that, there are 5 other reasons to take a cybersecurity course.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Convenience
&lt;/h2&gt;

&lt;p&gt;One of the advantages of distance learning is that it does not bound students to any exact place and is suitable for people who cannot attend full-time classes for some reason. For example, offline learning requires extra time separate from the main job or other classes: not only will the student have to adjust his schedule to a study curriculum, but he also will waste time on getting to the particular place.&lt;/p&gt;

&lt;p&gt;With online learning, a student can choose their study schedule on their own, taking into account working time and workload. Do not forget that each person has their own rhythm and speed of information perception. Online courses allow you to return to the topic at any time or to re-watch the lesson video, where the speaker, for instance, conducts a comprehensive analysis of information security incidents. Such an opportunity is a significant advantage for the IT sector, and it increases the chances of successful training completion. As for offline learning, the pace of learning in a group is set by a teacher or tutor, and students don't have an opportunity to re-listen to the material. The teacher needs to fit the course program in a certain period of time while the students have to adapt to this pace, which can negatively affect the training quality.&lt;/p&gt;

&lt;h2&gt;
  
  
  2.Great variety of courses
&lt;/h2&gt;

&lt;p&gt;A boring monotonous lecture (this format of presentation is typical for university education) is unlikely to help improve practical skills as well. At the same time, when taking an online course, you can combine different types of material feed, for example, videos, texts, or tests.&lt;/p&gt;

&lt;p&gt;In addition to that, new trends in education, such as gamification or immersive learning, are gaining popularity and are increasingly used in online courses. Such formats make the studying process exciting and allow you to pay more attention to complex topics. Gamification is also a powerful motivation tool: scores, rating tables, and a story scenario engage people of all ages into the learning process.&lt;/p&gt;

&lt;h2&gt;
  
  
  3.Demand for Cyber Security Professionals
&lt;/h2&gt;

&lt;p&gt;The never-ending process of adapting programs in such a dynamic environment is very difficult, and there's a need for young IT specialists. Many of them are faced with the illusion that a university degree is the end of their studies. In reality, this is only the beginning, since in order to become a true professional in the information security sphere, you need to constantly improve your skills.&lt;/p&gt;

&lt;p&gt;There is a huge variety of books, lectures, and educational platforms with courses for every taste - both for beginners and more experienced learners. It is of great importance that after passing an online course a student is issued a certificate confirming the successful program completion. And as for an employer, the certificate is a "candidate's desire to develop" confirmation.&lt;/p&gt;

&lt;h2&gt;
  
  
  4.Field of constant change
&lt;/h2&gt;

&lt;p&gt;Every information technology aspect goes hand in hand with cybersecurity, and focusing on security as a core profiling opens up a world of opportunities. From cybercrime investigations to risk assessment and application security, this sphere provides the broadest choice for IT professionals.&lt;/p&gt;

&lt;p&gt;Cybersecurity of organizations is the next decade main trend. But still, today there is a huge shortage of specialists in the industry and a huge number of vacancies. That said, it is expected that by 2022 in quantitative terms this figure will reach an impressive 1.8 million people worldwide.&lt;/p&gt;

&lt;p&gt;If you are already an IT specialist, be it a developer, programmer, architect, or system administrator, and the security area seems attractive to you, you may be interested in Pentester training. At the moment, there is a huge number of courses, and you will probably be able to find the ones that are right for you, regardless of your previous experience, employment, and location.&lt;/p&gt;

&lt;h2&gt;
  
  
  5.Cost
&lt;/h2&gt;

&lt;p&gt;The main advantage of online courses is their low cost (comparing with the cost of one semester at the university). However, the most important resource is not money, but time. As mentioned above, IT is a rapidly changing field, and you need to be quite flexible in order to remain in demand. During the period of 4-5 years, when a person takes the university course, global changes are taking place. This results in a situation when some of the knowledge provided by the university becomes irrelevant. Thus, graduates do not have skills applicable to the current situation in the sphere of IT and often regret the years they spent. An average online course lasts 1.5 to 2 months, while the course program can introduce new technologies into the learning process.&lt;/p&gt;

&lt;p&gt;To sum up, online education is an excellent option for people who are already working and want to change their activity field. This is a promising option for students without experience in the specialty. And this is an excellent opportunity to get valuable knowledge in a short time and even absolutely free, as well as to expand your CV.&lt;/p&gt;

&lt;p&gt;Online courses are especially relevant now when the whole world is in quarantine. The virus will go away, but the knowledge will remain. Therefore, it is worth thinking about training in such a fast-growing field as cybersecurity. IT specialists are in demand even in a crisis, and you do not have to leave the house and break self-isolation.&lt;/p&gt;

</description>
      <category>security</category>
    </item>
  </channel>
</rss>
