SYS-CON MEDIA Authors: Zakia Bouachraoui, Carmen Gonzalez, Yeshim Deniz, Pat Romanski, Gary Arora

News Feed Item

Global Cyber Alliance Launches Free Tools To Secure Websites And Evaluate Risk From Partner Email

GCA McScrapy and the GCA DMARC Risk Scanner Empower Organizations to Launch Proactive Cyber Defenses

SAN FRANCISCO, April 17, 2018 /PRNewswire-USNewswire/ -- The Global Cyber Alliance today released two new free, open-source tools to enable organizations to reduce cybersecurity risks associated with website and email born cyberattacks.

GCA McScrapy enables organizations to lock down their website to remove potential security issues from third-party services and other unnecessary functionality. In addition, a new email security tool – the GCA DMARC Risk Scanner – allows organizations to determine if the organizations on which they depend, such as their trading partners and supply chain, are protecting their email domains from being spoofed or phished.

"Reducing risk is the best cyber defense," said Philip Reitinger, president and CEO of the Global Cyber Alliance. "Among the most popular open doors that cyber criminals exploit are phishing attacks and compromise of an organization's website. The tools we released today are designed to help stop these attacks and prevent loss to businesses."

GCA McScrapy: Locking Down Websites

While GCA McScrapy can be used on websites developed with any content management system, nearly 60 percent of websites are designed using the WordPress platform. While WordPress is a popular platform, by its nature, its functions raise the risk of potential compromise. WordPress dynamically composes web pages using PHP and JavaScript and thus carries with it a risk for bugs and security vulnerabilities that serve as an attack vector. According to a WP WhiteSecurity October 2017 report on WordPress vulnerabilities, there are 2407 known vulnerabilities, more than half those vulnerabilities (54%) are from WordPress plugins and 31.5% are core WordPress vulnerabilities. The two most prevalent vulnerabilities are cross-site scripting and SQL injection.

GCA McScrapy converts a website into a set of static files, removing unnecessary functionality. Using a static website nullifies many concerns of cross-site scripting and SQL injection since there is no communication with the website's content management system for dynamic content. The tool evaluates every part of a website and renders it into simple form, keeping as much functionality as possible, while removing potential security issues such as third-party services.  Not all functionality can be maintained, however, and updating websites takes extra steps, making GCA McScrapy best for websites for which security is very important.  GCA McScrapy is also highly configurable and can be adjusted to reduce scan times and scrape mobile sites. GCA McScrapy is free for anyone to use. Learn more about GCA McScrapy at github.com/GlobalCyberAlliance/.

GCA DMARC Risk Scanner: Holding Partners Accountable

The Domain-based Message Authentication, Reporting & Conformance (DMARC) security protocol enables organizations to protect their email domains from being used by spammers and phishers to trick employees, customers and trading partners.

The GCA DMARC Risk Scanner can be used to scan hundreds of domains at one time to determine the level of DMARC and Sender Policy Framework (SPF) protections used by an organization's partners, including the third parties with whom it works, its supply chain, and its trading partners.  This enables an organization to better understand, and act upon, the risk imposed on it by its partners who have not employed DMARC.

Without DMARC implemented, scammers and criminals can easily "spoof" an email domain to steal money, trade secrets or even jeopardize national security. DMARC weeds out fake emails (known as direct domain spoofing) deployed by spammers and phishers targeting the inboxes of workers in all sectors of society.  According to the 2017 Symantec ISTR report, 1 in 131 emails contained malware, the highest rate in 5 years.

Like all GCA tools, the GCA DMARC Risk Scanner is freely available. Learn more about DMARC at dmarc.globalcyberalliance.org.

About the Global Cyber Alliance
The Global Cyber Alliance (GCA) is an international, cross-sector effort dedicated to eradicating cyber risk and improving our connected world. We achieve our mission by uniting global communities, implementing concrete solutions, and measuring the effect. GCA, a 501(c)3, was founded in September 2015 by the Manhattan District Attorney's Office, the City of London Police and the Center for Internet Security. Learn more at www.globalcyberalliance.org.

CONTACT: Josh Zecher, [email protected], 202-463-0045

Cision View original content:http://www.prnewswire.com/news-releases/global-cyber-alliance-launches-free-tools-to-secure-websites-and-evaluate-risk-from-partner-email-300631409.html

SOURCE Global Cyber Alliance

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Latest Stories
Public clouds dominate IT conversations but the next phase of cloud evolutions are "multi" hybrid cloud environments. The winners in the cloud services industry will be those organizations that understand how to leverage these technologies as complete service solutions for specific customer verticals. In turn, both business and IT actors throughout the enterprise will need to increase their engagement with multi-cloud deployments today while planning a technology strategy that will constitute a ...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Every organization is facing their own Digital Transformation as they attempt to stay ahead of the competition, or worse, just keep up. Each new opportunity, whether embracing machine learning, IoT, or a cloud migration, seems to bring new development, deployment, and management models. The results are more diverse and federated computing models than any time in our history.
Andrew Keys is co-founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereum.
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Concerns about security, downtime and latency, budgets, and general unfamiliarity with cloud technologies continue to create hesitation for many organizations that truly need to be developing a cloud strategy. Hybrid cloud solutions are helping to elevate those concerns by enabling the combination or orchestration of two or more platforms, including on-premise infrastructure, private clouds and/or third-party, public cloud services. This gives organizations more comfort to begin their digital tr...
Isomorphic Software is the global leader in high-end, web-based business applications. We develop, market, and support the SmartClient & Smart GWT HTML5/Ajax platform, combining the productivity and performance of traditional desktop software with the simplicity and reach of the open web. With staff in 10 timezones, Isomorphic provides a global network of services related to our technology, with offerings ranging from turnkey application development to SLA-backed enterprise support. Leadin...
On-premise or off, you have powerful tools available to maximize the value of your infrastructure and you demand more visibility and operational control. Fortunately, data center management tools keep a vigil on memory contestation, power, thermal consumption, server health, and utilization, allowing better control no matter your cloud's shape. In this session, learn how Intel software tools enable real-time monitoring and precise management to lower operational costs and optimize infrastructure...
Data center, on-premise, public-cloud, private-cloud, multi-cloud, hybrid-cloud, IoT, AI, edge, SaaS, PaaS... it's an availability, security, performance and integration nightmare even for the best of the best IT experts. Organizations realize the tremendous benefits of everything the digital transformation has to offer. Cloud adoption rates are increasing significantly, and IT budgets are morphing to follow suit. But distributing applications and infrastructure around increases risk, introdu...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science" is responsible for guiding the technology strategy within Hitachi Vantara for IoT and Analytics. Bill brings a balanced business-technology approach that focuses on business outcomes to drive data, analytics and technology decisions that underpin an organization's digital transformation strategy. Bill has a very impressive background which includes ...
Darktrace is the world's leading AI company for cyber security. Created by mathematicians from the University of Cambridge, Darktrace's Enterprise Immune System is the first non-consumer application of machine learning to work at scale, across all network types, from physical, virtualized, and cloud, through to IoT and industrial control systems. Installed as a self-configuring cyber defense platform, Darktrace continuously learns what is ‘normal' for all devices and users, updating its understa...
DevOps has long focused on reinventing the SDLC (e.g. with CI/CD, ARA, pipeline automation etc.), while reinvention of IT Ops has lagged. However, new approaches like Site Reliability Engineering, Observability, Containerization, Operations Analytics, and ML/AI are driving a resurgence of IT Ops. In this session our expert panel will focus on how these new ideas are [putting the Ops back in DevOps orbringing modern IT Ops to DevOps].
On-premise or off, you have powerful tools available to maximize the value of your infrastructure and you demand more visibility and operational control. Fortunately, data center management tools keep a vigil on memory contestation, power, thermal consumption, server health, and utilization, allowing better control no matter your cloud's shape. In this session, learn how Intel software tools enable real-time monitoring and precise management to lower operational costs and optimize infrastructure...
While a hybrid cloud can ease that transition, designing and deploy that hybrid cloud still offers challenges for organizations concerned about lack of available cloud skillsets within their organization. Managed service providers offer a unique opportunity to fill those gaps and get organizations of all sizes on a hybrid cloud that meets their comfort level, while delivering enhanced benefits for cost, efficiency, agility, mobility, and elasticity.
Most organizations are awash today in data and IT systems, yet they're still struggling mightily to use these invaluable assets to meet the rising demand for new digital solutions and customer experiences that drive innovation and growth. What's lacking are potent and effective ways to rapidly combine together on-premises IT and the numerous commercial clouds that the average organization has in place today into effective new business solutions. New research shows that delivering on multicloud e...