Press Releases

Josh Pennell to Present at the World Meter Design Congress.

March 5, 2010
IOActive's founder and President will discuss strategies for designing more secure smart meter devices.


Ward Spangenberg to Present at RSA Conference.

March 1, 2010
Director of PCI and Compliance Services to participate in a panel discussing PCI and security implications for cloud computing.


Dan Kaminsky to Participate in Panel Discussions at RSA Conference

March 1, 2010
Director of Penetration Testing to discuss high-profile security vulnerability disclosures and how the industry has evolved over the years.


Wes Brown to Present at BSides San Francisco.

March 1, 2010
Principal Security Consultant to discuss building and using an automated malware pipeline.


Glenn Kaleta to Present at SDForum.

January 25, 2010
Director of Services, Glenn Kaleta, will discuss emerging issues related to incident response preparation.


Mike Davis to Participate in the Intelligent Utility Reality Webcast.

December 31, 2009
Senior Security Consultant, Mike Davis, to participate in a panel discussion focusing on strategies for securing the Smart Grid.


Ilja van Sprundel to Preset at hack.lu

October 27, 2009
IOActive's Principal Security Consultant to discuss exploiting applications written in the Delphi language.


IOActive to Present at SANS Process Control and SCADA Security Summit

October 26, 2009
Founder and President, Josh Pennell, will participate in a panel discussing best practices for overcoming security vulnerabilities discovered in the Smart Grid


IOActive to Present at SecureWorld Seattle

October 20, 2009
Director of Compliance Services, Ward Spangenberg, will discuss strategies for leveraging the benefits of cloud computing without jeopardizing compliance


Dan Kaminsky to Present at ToorCon

October 20, 2009
Dan Kaminsky, Director of Penetration Testing at IOActive, will discuss authentication problems uncovered in X.509


Robert Zigweid to Present Threat Modeling at ToorCon

October 19, 2009
Robert Zigweid, a Senior Security Consultant at IOActive, will discuss how organizations can utilize threat modeling to optimize security budgets.


IOActive to Present at RSA Europe

October 19, 2009
IOActive will discuss how organizations can migrate to the cloud without sacrificing compliance or security.


IOActive Discovers Critical Flaw in Adobe Reader 9.1.2

October 13, 2009
Richard van Eeden discovers serious security flaw that enables arbitrary file creation.


Wes Brown to Present at Hack in the Box Malaysia

September 29, 2009
Senior Security Consultant, Wes Brown, will demonstrate how to build and use an automated malware analysis pipeline.


David Baker to Present at the EnergySec 2009 Annual Summit

September 22, 2009
IOActive's Director of Services will discuss how the industry can work together and ensure a secure Smart Grid.


Ward Spangenberg to Present at Information Security Compliance and Risk Management Institute

September 17, 2009
IOActive's Director of PCI and Compliance to discuss how cloud computing affects an organization's ability to achieve and maintain compliance.


Joshua Pennell to Present at IDC's IT Security Conference

September 14, 2009
IOActive's Founder and President to discuss securely leveraging the benefits of cloud computing.


Joshua Pennell to Present at the OWASP Scotland Meeting

September 14, 2009
IOActive's Founder and President to discuss the 2010 application security threatscape.


IOActive to Present at Prestigious Agora Meeting

September 3, 2009
Team presents on Smart Meter security research and their efforts assembling a super computer capable of cracking WPA2 keys.


Dan Kaminsky Selected to Present at Hacking at Random

August 13, 2009
IOActive's Director of Penetration Testing will discuss flaws in digital certificate technology.


Ward Spangenberg to Discuss Cloud Computing at CSA Federal Cloud Security Symposium

August 5, 2009
IOActive's Director of PCI and Compliance was selected to educate attendees on cloud computing.


Mike Davis to unveil Smart Grid research at Black Hat USA

July 29, 2009
IOActive Senior Security Consultant discusses security vulnerabilities and simulates a worm attack in smart meter platforms.


Ilja Van Sprundel to Present at London OWASP Meeting

July 8, 2009
An IOActive Principal Senior Consultant, Ilja van Sprundel was selected to discuss auditing C# code at the July London OWASP meeting.


Ward Spangenberg to Participate in a Panel Discussion at the Puget Sound ISSA June Meeting.

June 17, 2009
IOActive's Director of PCI Services to discuss strategies and best practices to help organizations migrate securely into cloud technologies.


Dan Kaminsky to Present Webcast with Fellow DNS Experts

June 9, 2009
IOActive's Director of Penetration Testing will present alongside leading experts to discuss current DNS security issues and how to address them using DNSSEC


Tiller Beauchamp Selected to Present at Shakacon Conference

May 20, 2009
IOActive's Principal Consultant will discuss the use of dynamic tracing for exploitation development and fuzzing.


Dan Kaminsky Testifies to Congress on Cyber Security

May 13, 2009
IOActive's Director of Penetration Testing briefed White House officials on the current state of cyber security and his vision for moving forward.


Ilja Van Sprundel to Present at EUSecWest

May 11, 2009
IOActive's Principal Security Consultant was selected to present at EUSecWest and discuss the exploitation of applications written in Delphi/Pascal.


Tiller Beauchamp to Present at Upcoming ISSA-LA Meeting

May 5, 2009
IOActive's Principal Security Consultant selected to discuss popular malware that attackers are utilizing for online crime.


Dan Kaminsky Nominated into the InfoSecurity Europe Hall of Fame

April 27, 2009
IOActive's Director of Penetration Testing internationally recognized for years of thought leadership and significant contributions to the security industry.


Dan Kaminsky Collaborates With Honeynet Project to Mitigate
Threat from Conficker Worm

March 31, 2009
Honeynet Project brings in IOActive's Director of Penetration Testing to help research the threat and develop a scanning tool to detect the Conficker Worm easily.


IOActive Verifies Critical Flaws in Next-generation Energy Infrastructure

March 23, 2009
Company cautions against wider adoption of Smart Grid technology until security risks are mitigated and industry adopts a Security Development Lifecycle.


Ward Spangenberg to Discuss the Economic Benefits of PCI at Source Boston

March 12, 2009
Spangenberg will present Employing PCI Compliance Programs as a Springboard for Enterprise Security and Business Enablement, addressing the reality of PCI compliance and the consequences that organizations face when they fail to comply.


Jason Larsen and Mike Davis to Discuss the State of AMI Security at Sans SCADA Summit

February 6, 2009
Larsen and Davis will present What's Going on Out There in Cyber Attacks and What is Coming Next?, addressing current security issues faced by the Advanced Metering Infrastructure (AMI).


Ted Ipsen to Discuss the Secure Development Lifecycle at Upcoming ISSA Meeting

February 4, 2009
Ted Ipsen, VP of Services, will demonstrate how the old software model of Develop, Deploy, Exploit, Patch, Repeat is inefficient and costly in today's hostile networked environments.


Jason Larsen to Present on SCADA Security at THE WTIA

December 1, 2008
Jason Larsen will present Cyber Attack of the Critical Infrastructure as part of a discussion of security issues pertaining to Supervisory Control and Data Acquisition (SCADA) installations.


IOActive to Keynote PCI Roadshow with Fortinet

November 7, 2008
IOActive today announced that Ward Spangenberg, their director of PCI services, will participate in a Fortinet®-sponsored PCI Roadshow, which kicks off on NOvember 11, 2008 in Los Angeles, CA.


Dan Kaminsky and Ward Spangenberg to Speak at Secure World Seattle

October 28, 2008
Dan Kaminsky to present the keynote speech Internet Infrastructure: Designed for Instability? and Ward Spangenberg to present The Challenges of Meeting and Maintaining PCI Compliance in an Enterprise Environment at SecureWorld Seattle in Bellevue on October 29.


Application Security Talk at HTCIA

October 21, 2008
Ted Ipsen, IOActive's Vice President will deliver a 90-minute presentation at HTCIA about threats relevant to payment card data and the Payment Card Industry Data Security Standard. The High Technology Crime Investigation Association (HTCIA) is holding its annual conference in Atlantic City, NJ.


Microsoft Selects IOActive as SDL Partner

October 7, 2008
IOActive announces that it is one of nine companies internationally selected to be a member of Microsoft's Security Development Lifecycle (SDL) Pro Network, which will kick off its year-long pilot phase in November 2008.


Entire Web at Risk: Earthlink and Verizon Advertising Security Revealed

April 19, 2008
Dan Kaminsky, Director of Penetration Testing at IOActive, discussed a new Web vulnerability at the Toorcon Security Conference on April 19, 2008. Ad injection systems at major ISPs, including Earthlink and Verizon, were vulnerable to cross-site scripting attacks. These systems mimic the entire Web as part of daily operations; therefore, their vulnerabilities affect everyone's domains. Users at these ISPs were at risk and their sensitive data was jeopardized—credit card numbers, email information, and passwords—which could have caused considerable damage if left untreated.