36 Posts

Michelle Alvarez

Threat Researcher and Editor, IBM Managed Security Services

Michelle Alvarez is a Threat Researcher and Editor for IBM's Managed Security Services; she brings more than 10 years of industry experience to her role. In this role she focuses communications efforts around threat research and mitigation. Michelle joined IBM through the Internet Security Services (ISS) acquisition, where she served as an Analyst on the X-Force Vulnerability Database Team.

Written By Michelle Alvarez

A Magnet for Cybercrime: Financial Services Sector

According to the 2017 IBM X-Force Threat Intelligence Index, cybercriminals targeted the financial services sector more than any other industry in 2016.

2016: The Year of the Mega Breach

The latest edition of the IBM X-Force Threat Intelligence Index detailed how companies were affected by data breaches during the "year of the mega breach."

Disposing of Your Device: Don’t Throw the Data Out With the Old PC

Disposing of your device securely means wiping old data, deauthorizing account access and finding an ecologically sound home for the old device.

Health Care Data at Growing Risk From Ransomware, Insiders and Third-Party Breaches

A new report based on IBM MSS data revealed that ransomware, insider threats and third-party breaches plagued health care organizations in 2016.

Attackers Targeting Retail Are Shopping for Low-Hanging Fruit

A recent IBM study revealed that many high-profile attacks against retail companies originate from vulnerabilities classified as low-hanging fruit.

Rising Attack Rates and Massive Breaches Plague Government Organizations

IBM's "2016 Cyber Security Intelligence Index" reported that the government sector is now the fourth most frequently targeted industry in the U.S.

Hello, You’ve Been Compromised: Upward Attack Trend Targeting VoIP Protocol SIP

According to IBM Managed Security Services data, cybercriminals most commonly target the SIP and SCCP protocols in VOIP spam attacks.

Consequences of IoT and Telnet: Foresight Is Better Than Hindsight

Cybercriminals have learned how to exploit the IoT and Telnet servers to commit record-shattering DDoS attacks against major websites.

Researchers Detect Second Wave of Shellshock Attacks Since Two-Year Anniversary

Researchers detected an increase in Shellshock attacks — the second wave of activity since the malware celebrated its two-year anniversary in September.

Shellshock Anniversary: Major Security Flaw Still Going Strong

As if to celebrate its two-year anniversary, Shellshock, one of the most infamous bugs of 2014, ramped up its activity in September.

Co-Written By Michelle Alvarez

Apache Struts 2: A Zero-Day Quick Draw

It took fraudsters less than 24 hours after the disclosure of a previously unknown Apache Struts 2 vulnerability to develop a Python script to exploit it.

Mirai IoT Botnet: Mining for Bitcoins?

Just in time for IoT Day, the Mirai botnet is launching attacks with a new trick up its sleeve: a built-in bitcoin mining component.