IOActive

Site Map  |  Privacy Policy  |  Advisories

About Us

Services

News

IOActive Labs

Contact
IOActive Labs IOBOT! Click to learn more.

 
greybar

Press Releases
greybar

IOActive's Anthony Zboralski to Present at ISSA-UK and OWASP Web Application Security Training Day

May 9, 2012
Managing Security Consultant to Present App (In)security


IOActive's Ian Amit to Present at You Sh0t the Sheriff

May 4, 2012
Director of Services to Present So, the red team was here and tore us a new one. WHAT NOW?


IOActive's David Baker to Appear on KING 5 News Seattle

April 19, 2012
Vice President of Services Discusses Social Engineering


IOActive's Robert Zigweid to Present at InfoSec World 2012

March 23, 2012
Principal Compliance Consultant to Present Stormy Skies: Compliance in the Cloud


IOActive's Matias Brutti to Present at Hackito Ergo Sum 2012

March 23, 2012
Senior Security Consultant to host a workshop on social engineering


IOActive's Ruben Santamarta to Present at AppSec DC 2012

March 19, 2012
Security Researcher to present Real World Backdoors on Industrial Devices


IOActive's Cesar Cerrudo to Present at Hackito Ergo Sum 2012

March 9, 2012
Chief Technology Officer of IOActive Labs to present Easy Local Windows Kernel Exploitation


IOActive's Joshua Pennell to Present at IDC and Oracle's Security for the Smart Grid Event

March 9, 2012
Founder and President to present Smart Grid Security


IOActive's Vincent Berg to speak exclusively at WTIA IT's Security Community Event: The Future of Secure Internet Commerce

March 9, 2012
Senior Security Consultant to be publicly interviewed


IOActive's Ryan O'Horo to Present at RSA USA 2012

February 17, 2012
Senior Security Consultant to present PenTesting People: Scoial Engineering Integration


IOActive's David Baker to Present at RSA USA 2012

February 17, 2012
Vice President of Services to present Engineering the Smart Grid


IOActive's David Baker to Present Webcast on Mobile Device Threats

January 25, 2012
Vice President of Services to present Mobile Devices: Is your organization protected from this newest threat?


IOActive's Robert Zigweid to Present at OWASP Los Angeles

January 25, 2012
Principal Compliance Consultant to present Security in the Cloud


IOActive's Cesar Cerrudo to Present at Infiltrate

January 11, 2012
Chief Technology Officer of IOActive Labs to present Easy Local Windows Kernel Exploitation


IOActive's Ryan O'Horo to Present a Webcast on Social Engineering

November 21, 2011
IOActive Security Consultant to present Inside the Mind of a Social Engineer


IOActive's Joshua Pennell to Present at SOURCE Barcelona 2011

November 9, 2011
IOActive Founder and President to present There's an App for That: Evolving Mobile Security into a Business Advantage


IOActive's Vincent Berg to Present at Ruxcon 2011

November 4, 2011
IOActive Security Consultant to present SSL Traffic Analysis Attacks


IOActive's Mike Ridpath and Matias Brutti to Present at BayThreat

November 2, 2011
IOActive Security Consultants to present Social Engineering PenTest: Using the Dreaded Telephone


IOActive's Matias Brutti to Present at Microsoft's BlueHat Redmond Security Briefings

October 31, 2011
IOActive Security Consultant to present The Security Trifecta: Platforms, Apps, and Stores


IOActive's Mike Ridpath and Matias Brutti to Present a Webcast on Social Engineering

September 27, 2011
IOActive Security Consultants to present Automating Social Engineering


IOActive's Ryan O'Horo to Present at BSidesDFW

September 27, 2011
IOActive Security Consultant to present PenTesting People: Social Engineering Integration


IOActive's Mike Ridpath and Matias Brutti to Present at WSCPA Seattle Chapter

September 22, 2011
IOActive Security Consultants to be featured speakers for WSCPA Seattle Chapter


IOActive's Mike Ridpath and Matias Brutti to Present at BSides Portland

September 22, 2011
IOActive Security Consultants to present Covert Calling: Secrets of Social Engineering Revealed!


IOActive's Joshua Pennell to Present at RSA Europe 2011

September 14, 2011
IOActive's Founder and President to present There's an App for That: Evolving Mobile Security into a Business Advantage


IOActive's Robert Zigweid to Present at HouSecCon 2011

September 14, 2011
IOActive's Principal Compliance Consultant to present Stormy Skies: Compliance in the Cloud


IOActive's Ryan O'Horo to Present at HouSecCon 2011

September 14, 2011
IOActive's Security Consultant to present PenTesting People: Social Engineering Integration


IOActive's Cesar Cerrudo to Present at EkoParty

September 12, 2011
IOActive's CTO of IOActive Labs to present Squeezing the Web: Combining Drops of Information to Own Any Argentinian


IOActive's Joshua Pennell to Present at 44Con 2011

August 29, 2011
IOActive's Founder and President to present There's an App for That: Evolving Mobile Security into a Business Advantage


IOActive's Ilja van Sprundel to Present at 44Con 2011

August 29, 2011
IOActive's Principal Security Consultant to present AndBug, a scriptable open source debugger


IOActive's Robert Zigweid to Present at Black Hat USA

July 28, 2011
IOActive's Principal Compliance Consultant to partipate on the panel "Digital Forensics: What is the Meaning of This"


IOActive's Mike ridpath to Present at Black Hat USA

July 28, 2011
IOActive's Security Consultant to present his GMaps-Trafficker tool


IOActive's Ryan O'Horo to Present at Hacker Halted

July 5, 2011
IOActive's Security Consultant to present PenTesting People: Social Engineering Integration


IOActive's Cesar Cerrudo to Present at Black Hat USA

July 1, 2011
IOActive's CTO of IOActive Labs to host a workshop concerning vulnerability hunting in Windows


IOActive's Mike Ridpath and Matias Brutti to Present at ToorCon Seattle

June 7, 2011
IOActive's Security Consultants to present Social Engineering and the Cold Call


IOActive's Vincent Berg to Present at 44Con 2011

June 7, 2011
IOActive's Security Consultant to present Attacking Modern Web Applications


IOActive's Ryan O'Horo to Present at BSidesCT

June 6, 2011
IOActive's Security Consultant to present PenTesting People: Social Engineering Integration


IOActive's James Lester to Speak at the ISSA Rainier Chapter

May 31, 2011
IOActive's Security Consultant to present Securing Web Applications in 2011


IOActive's Scott Dunlop to Present at ToorCon Seattle 2011

May 31, 2011
IOActive's Senior Security Consultant to present Reverse Engineering Using the Android Emulator


IOActive Acquires Argeniss Security and Names Cesar Cerrudo as Chief Technology Officer of IOActive Labs

May 23, 2011
IOActive expands team and funding of the IOActive Labs division


IOActive’s Ilja van Sprundel to Present at LOGIN

May 17, 2011
IOActive’s Principle Security Consultant to present Writing Secure iOS Applications


IOActive’s Scott Dunlop to Present at Recon

May 17, 2011
IOActive’s Senior Security Consultant to unveil AndBug, a scriptable open source debugger


IOActive’s Robert Zigweid to Present at SOURCE Seattle

May 12, 2011
IOActive’s Principle Security Consultant to discuss best practices for threat modeling


IOActive’s Ryan O’Horo to host a web application seminar

October 15, 2010
IOActive’s Security Consultant will conduct an interactive seminar that is designed to give participants basic knowledge of web application security


IOActive’s Joshua Pennell and Barnaby Jack to present at SOURCE Barcelona

September 15, 2010
Pennell’s presentation will focus on the state of Smart Grid security and Jack will discuss software vulnerabilities discovered in Automated Teller Machines


IOActive’s Barnaby Jack to Present at Ekoparty

September 14, 2010
IOActive’s Director of Security Testing to discuss software vulnerabilities discovered in Automated Teller Machines


IOActive’s Robert Zigweid to present at OWASP AppSec USA

September 1, 2010
IOActive’s Senior Security Consultant to discuss best practices for threat modeling


IOActive Names Barnaby Jack as Director of Security Testing

June 17, 2010
IOActive continues expansion by adding esteemed researcher to management team


IOACTIVE TO PRESENT AT EUSECWEST IN AMSTERDAM

June 11, 2010
IOActive Security Consultants, Ilja van Sprundel and Vincent Berg join top researchers from around the world at EUSecWest


Erin Jacobs to Present at BSides Denver

June 10, 2010
IOActive's Engagement Director to discuss future trends in compliance


Joshua Pennell to Present at the ISMS Forum in Spain

May 18, 2010
IOActive’s Founder and President to discuss regulatory compliance in the cloud


Dan Kaminsky to Present at SIGINT 2010

May 14, 2010
IOActive’s Director of Penetration Testing to discuss techniques for better securing the web


Dan Kaminsky to Present at SOURCE Boston

April 19, 2010
IOActive's Director of Penetration Testing to discuss strategies for securing the Web


Jim Reavis to Present at SOURCE Boston

April 19, 2010
President of IOActive's Strategic Advisory Board to discuss security issues with cloud computing and a roadmp for overcoming these problems.


David Baker to Present at the Regional Government Security Briefing

April 16, 2010
IOActive's Director of Services to discuss progress the utilities industry has made to improve security in smart meter devices.


IOActive to Present at Seattle OWASP Meeting

April 15, 2010
IOActive's Security Consultants, Walter Pearce and Wade Winright, to discuss best practices for securing web applications.


IOActive to Present at the IDC IT Security Conference

April 13, 2010
IOActive's President and Founder, Joshua Pennell, will discuss security challenges related to cloud computing.


Erin Jacobs to Present at Bsides Boston

April 12, 2010
IOActive's Engagement Director to discuss lessons she learned while working as a CSO at a mid-size company.


Scott Dunlop to Present at Notacon 7

April 7, 2010
IOActive's Senior Security Consultant to demonstrate how NoSpex can consolidate information from log files and simplify analysis.


Joshua Pennell puts Smart Grid Security on Agenda at Infosecurity Europe

March 30, 2010
Research and case studies underscore need for utilities to craft new security strategies as foundation of UK plc's security.


Michael Milvich to Participate in a Panel Discussion at the SANS Process Control and SCADA Security Summit

March 25, 2010
IOActive's Principal Security Consultant to discuss vulnerabilities found in SCADA and critical infrastructure systems.


Josh Pennell to Present at the World Meter Design Congress

March 5, 2010
IOActive's Founder and President will discuss strategies for designing more secure smart meter devices.


Ward Spangenberg to Present at RSA Conference

March 1, 2010
Director of PCI and Compliance Services to participate in a panel discussing PCI and security implications for cloud computing.


Dan Kaminsky to Participate in Panel Discussions at RSA Conference

March 1, 2010
Director of Penetration Testing to discuss high-profile security vulnerability disclosures and how the industry has evolved over the years.


Wes Brown to Present at BSides San Francisco

March 1, 2010
Principal Security Consultant to discuss building and using an automated malware pipeline.


Glenn Kaleta to Present at SDForum

January 25, 2010
Director of Services, Glenn Kaleta, will discuss emerging issues related to incident response preparation.


Mike Davis to Participate in the Intelligent Utility Reality Webcast

December 31, 2009
Senior Security Consultant, Mike Davis, to participate in a panel discussion focusing on strategies for securing the Smart Grid.


Robert Zigweid to Present at the Minneapolis OWASP Meeting

December 7, 2009
Senior Security Consultant to discuss strategies and considerations for employing threat modeling.


Ilja van Sprundel to Preset at hack.lu

October 27, 2009
IOActive's Principal Security Consultant to discuss exploiting applications written in the Delphi language.


IOActive to Present at SANS Process Control and SCADA Security Summit

October 26, 2009
Founder and President, Josh Pennell, will participate in a panel discussing best practices for overcoming security vulnerabilities discovered in the Smart Grid


IOActive to Present at SecureWorld Seattle

October 20, 2009
Director of Compliance Services, Ward Spangenberg, will discuss strategies for leveraging the benefits of cloud computing without jeopardizing compliance


Dan Kaminsky to Present at ToorCon

October 20, 2009
Dan Kaminsky, Director of Penetration Testing at IOActive, will discuss authentication problems uncovered in X.509


Robert Zigweid to Present Threat Modeling at ToorCon

October 19, 2009
Robert Zigweid, a Senior Security Consultant at IOActive, will discuss how organizations can utilize threat modeling to optimize security budgets.


IOActive to Present at RSA Europe

October 19, 2009
IOActive will discuss how organizations can migrate to the cloud without sacrificing compliance or security.


IOActive Discovers Critical Flaw in Adobe Reader 9.1.2

October 13, 2009
Richard van Eeden discovers serious security flaw that enables arbitrary file creation.


Wes Brown to Present at Hack in the Box Malaysia

September 29, 2009
Senior Security Consultant, Wes Brown, will demonstrate how to build and use an automated malware analysis pipeline.


David Baker to Present at the EnergySec 2009 Annual Summit

September 22, 2009
IOActive's Director of Services will discuss how the industry can work together and ensure a secure Smart Grid.


Ward Spangenberg to Present at Information Security Compliance and Risk Management Institute

September 17, 2009
IOActive's Director of PCI and Compliance to discuss how cloud computing affects an organization's ability to achieve and maintain compliance.


Joshua Pennell to Present at IDC's IT Security Conference

September 14, 2009
IOActive's Founder and President to discuss securely leveraging the benefits of cloud computing.


Joshua Pennell to Present at the OWASP Scotland Meeting

September 14, 2009
IOActive's Founder and President to discuss the 2010 application security threatscape.


IOActive to Present at Prestigious Agora Meeting

September 3, 2009
Team presents on Smart Meter security research and their efforts assembling a super computer capable of cracking WPA2 keys.


Dan Kaminsky Selected to Present at Hacking at Random

August 13, 2009
IOActive's Director of Penetration Testing will discuss flaws in digital certificate technology.


Ward Spangenberg to Discuss Cloud Computing at CSA Federal Cloud Security Symposium

August 5, 2009
IOActive's Director of PCI and Compliance was selected to educate attendees on cloud computing.


Mike Davis to unveil Smart Grid research at Black Hat USA

July 29, 2009
IOActive Senior Security Consultant discusses security vulnerabilities and simulates a worm attack in smart meter platforms.


Ilja Van Sprundel to Present at London OWASP Meeting

July 8, 2009
An IOActive Principal Senior Consultant, Ilja van Sprundel was selected to discuss auditing C# code at the July London OWASP meeting.


Ward Spangenberg to Participate in a Panel Discussion at the Puget Sound ISSA June Meeting

June 17, 2009
IOActive's Director of PCI Services to discuss strategies and best practices to help organizations migrate securely into cloud technologies.


Dan Kaminsky to Present Webcast with Fellow DNS Experts

June 9, 2009
IOActive's Director of Penetration Testing will present alongside leading experts to discuss current DNS security issues and how to address them using DNSSEC


Tiller Beauchamp Selected to Present at Shakacon Conference

May 20, 2009
IOActive's Principal Consultant will discuss the use of dynamic tracing for exploitation development and fuzzing.


Dan Kaminsky Testifies to Congress on Cyber Security

May 13, 2009
IOActive's Director of Penetration Testing briefed White House officials on the current state of cyber security and his vision for moving forward.


Ilja Van Sprundel to Present at EUSecWest

May 11, 2009
IOActive's Principal Security Consultant was selected to present at EUSecWest and discuss the exploitation of applications written in Delphi/Pascal.


Tiller Beauchamp to Present at Upcoming ISSA-LA Meeting

May 5, 2009
IOActive's Principal Security Consultant selected to discuss popular malware that attackers are utilizing for online crime.


Dan Kaminsky Nominated into the InfoSecurity Europe Hall of Fame

April 27, 2009
IOActive's Director of Penetration Testing internationally recognized for years of thought leadership and significant contributions to the security industry.


Dan Kaminsky Collaborates With Honeynet Project to Mitigate
Threat from Conficker Worm

March 31, 2009
Honeynet Project brings in IOActive's Director of Penetration Testing to help research the threat and develop a scanning tool to detect the Conficker Worm easily.


IOActive Verifies Critical Flaws in Next-generation Energy Infrastructure

March 23, 2009
Company cautions against wider adoption of Smart Grid technology until security risks are mitigated and industry adopts a Security Development Lifecycle.


Ward Spangenberg to Discuss the Economic Benefits of PCI at Source Boston

March 12, 2009
Spangenberg will present Employing PCI Compliance Programs as a Springboard for Enterprise Security and Business Enablement, addressing the reality of PCI compliance and the consequences that organizations face when they fail to comply.


Jason Larsen and Mike Davis to Discuss the State of AMI Security at Sans SCADA Summit

February 6, 2009
Larsen and Davis will present What's Going on Out There in Cyber Attacks and What is Coming Next?, addressing current security issues faced by the Advanced Metering Infrastructure (AMI).


Ted Ipsen to Discuss the Secure Development Lifecycle at Upcoming ISSA Meeting

February 4, 2009
Ted Ipsen, VP of Services, will demonstrate how the old software model of Develop, Deploy, Exploit, Patch, Repeat is inefficient and costly in today's hostile networked environments.


Jason Larsen to Present on SCADA Security at THE WTIA

December 1, 2008
Jason Larsen will present Cyber Attack of the Critical Infrastructure as part of a discussion of security issues pertaining to Supervisory Control and Data Acquisition (SCADA) installations.


IOActive to Keynote PCI Roadshow with Fortinet

November 7, 2008
IOActive today announced that Ward Spangenberg, their director of PCI services, will participate in a Fortinet®-sponsored PCI Roadshow, which kicks off on NOvember 11, 2008 in Los Angeles, CA.


Dan Kaminsky and Ward Spangenberg to Speak at Secure World Seattle

October 28, 2008
Dan Kaminsky to present the keynote speech Internet Infrastructure: Designed for Instability? and Ward Spangenberg to present The Challenges of Meeting and Maintaining PCI Compliance in an Enterprise Environment at SecureWorld Seattle in Bellevue on October 29.


Application Security Talk at HTCIA

October 21, 2008
Ted Ipsen, IOActive's Vice President will deliver a 90-minute presentation at HTCIA about threats relevant to payment card data and the Payment Card Industry Data Security Standard. The High Technology Crime Investigation Association (HTCIA) is holding its annual conference in Atlantic City, NJ.


Microsoft Selects IOActive as SDL Partner

October 7, 2008
IOActive announces that it is one of nine companies internationally selected to be a member of Microsoft's Security Development Lifecycle (SDL) Pro Network, which will kick off its year-long pilot phase in November 2008.


Entire Web at Risk: Earthlink and Verizon Advertising Security Revealed

April 19, 2008
Dan Kaminsky, Director of Penetration Testing at IOActive, discussed a new Web vulnerability at the Toorcon Security Conference on April 19, 2008. Ad injection systems at major ISPs, including Earthlink and Verizon, were vulnerable to cross-site scripting attacks. These systems mimic the entire Web as part of daily operations; therefore, their vulnerabilities affect everyone's domains. Users at these ISPs were at risk and their sensitive data was jeopardized—credit card numbers, email information, and passwords—which could have caused considerable damage if left untreated.


 
greybar

More Information


Need more information?
Contact IOActive today.



IOActive Profile:
Established: 1998
Headquarters: Seattle, WA and London, UK
Privately held and self-funded
 
IOActive Services:
Application Security, SCADA and Smart Grid, PCI and Compliance, Security Development Lifecycle, Infrastructure Audit, Incident Response and Training.
 
Customers:
Global 500 companies including power and utility, game, hardware, retail, financial, media, travel, aerospace, healthcare, high-tech, social networking, and software development organizations.
 



Visit our Facebook page Visit our Twitter page Visit us on Flickr