Tag: SecurityWeek RSS Feed

Virgin Media Exposed Personal Information of 900,000 People

UK-based phone, TV and broadband services provider Virgin Media on Thursday admitted that it exposed the personal information of roughly 900,000 people. read more   Advertise on IT Security News. Read the complete article: Virgin Media Exposed Personal Information of…

US Lawmakers Propose Internet Controls to Fight Child Porn

US lawmakers proposed legislation Thursday that could see internet companies held legally responsible for content on their platforms if they don’t do enough to police child pornography. read more   Advertise on IT Security News. Read the complete article: US…

Cruise Operator Carnival Discloses 2019 Data Breach

Leisure travel company Carnival Corporation has started informing customers of a data breach that occurred last year and which resulted in their personal information being accessed by a third-party. read more   Advertise on IT Security News. Read the complete…

T-Mobile Notifying Customers of Data Breach

Wireless carrier T-Mobile is sending notifications to its customers to inform them of a data breach that resulted in some of their personal information being compromised read more   Advertise on IT Security News. Read the complete article: T-Mobile Notifying…

Over 600 Microsoft Subdomains Can Be Hijacked: Researchers

There are more than 600 legitimate Microsoft subdomains that can be hijacked and abused for phishing, malware delivery and scams, researchers warned this week. read more   Advertise on IT Security News. Read the complete article: Over 600 Microsoft Subdomains…

Cisco Patches Remote Code Execution Flaws in Webex Player

Cisco has released patches to address more than a dozen vulnerabilities across various products, including two code execution bugs in Webex Player that could be exploited remotely.  read more   Advertise on IT Security News. Read the complete article: Cisco…

Hamas-Linked Hackers Add Insurance and Retail to Target List

MoleRATs, a politically-motivated threat actor apparently linked to the Palestinian terrorist organization Hamas, has expanded its target list to include insurance and retail industries, Palo Alto Networks’ security researchers report. read more   Advertise on IT Security News. Read the…

D.C. Council Passes Data Security Legislation

The Council of the District of Columbia on Tuesday unanimously passed a bill whose goal is to expand data breach notification requirements and improve the way organizations protect personal information. read more   Advertise on IT Security News. Read the…

A Zero-Day Homograph Domain Name Attack

What started as almost casual research in November 2019 and disclosed to various vendors as a vulnerability in November and December 2019 and January 2020 was abruptly reclassified and treated as a zero-day vulnerability on February 13, 2020. read more…

Bug Forces Let’s Encrypt to Revoke 3 Million Certificates

Free and open certificate authority (CA) Let’s Encrypt is revoking over 3 million currently-valid certificates after discovering a bug in its Certification Authority Authorization (CAA) code. read more   Advertise on IT Security News. Read the complete article: Bug Forces…

Mobile Payment Fraud on the Rise

Mobile payment fraud is growing, and is growing faster in the mobile ecosystem than anywhere else. While Windows remains the most popular operating system used by fraudsters at 38%, the combined figures for iOS and Android are now 51% of…

Google Patches Critical Remotely Exploitable Android Bug

Google’s March 2020 security updates for Android include fixes for over 70 vulnerabilities, including a critical flaw in media framework.  read more   Advertise on IT Security News. Read the complete article: Google Patches Critical Remotely Exploitable Android Bug

Google Launches Free Fuzzer Benchmarking Service

Google this week announced the launch of FuzzBench, a free and open source service for evaluating fuzzers. The fully automated service was designed to allow for an easy but rigorous evaluation of fuzzing research, in an attempt to boost the…

Legal Services Firm Epiq Hit by Ransomware

Legal services company Epiq has taken its systems offline globally after being hit by a piece of ransomware. Epiq said on Monday that it detected the malware on its systems on February 29. The company said it had found no…

The OT Security Opportunity for CISOs

In my previous column, I talked about the rapidly changing geopolitical landscape and the escalation of cyberattacks on critical infrastructure. Some of you may be wondering: “Why should I care? Russia and other nation-states aren’t focused on me and my…

Super Tuesday Marks First Major Security Test of 2020

Tuesday’s presidential primaries across 14 states mark the first major security test since the 2018 midterm elections, with state and local election officials saying they are prepared to deal with everything from equipment problems to false information about the coronavirus.…

Telecom Sector Increasingly Targeted by Chinese Hackers: CrowdStrike

Threat actors linked to China increasingly targeted the telecommunications sector in 2019, according to endpoint security firm CrowdStrike. CrowdStrike on Tuesday published its 2020 Global Threat Report, which provides data on both state-sponsored and financially-motivated operations observed by the company…

U.S. Government Warns of Continuous Election Meddling Efforts

Foreign actors continue to attempt to interfere with the election process, multiple United States departments and agencies warned in a joint statement released ahead of Tuesday’s presidential primaries. read more   Advertise on IT Security News. Read the complete article:…

Advancing DevSecOps Into the Future

If DevOps represents the union of people, process, and technology to continually provide value to customers, then DevSecOps represents the fusion of value and security provided to those same customers. read more   Advertise on IT Security News. Read the…

Businesses at Risk for Cyberattack But Take Few Precautions

Although businesses are increasingly at risk for cyberattacks on their mobile devices, many aren’t taking steps to protect smartphones and tablets. read more   Advertise on IT Security News. Read the complete article: Businesses at Risk for Cyberattack But Take…

Walgreens Discloses Data Breach Related to Mobile App

Pharmacy store chain Walgreens has started informing some users of its mobile application that their personal and health-related information may have been seen by other customers. read more   Advertise on IT Security News. Read the complete article: Walgreens Discloses…

NVIDIA Patches DoS Flaws in GPU Driver and vGPU Software

Software security updates NVIDIA released on Friday address multiple denial-of-service (DoS) vulnerabilities in GPU display drivers and Virtual GPU Manager software. read more   Advertise on IT Security News. Read the complete article: NVIDIA Patches DoS Flaws in GPU Driver…

Railroad Construction Firm RailWorks Falls Victim to Ransomware

Rail contractor RailWorks Corporation is notifying employees and third-parties that it recently fell victim to a ransomware attack in which sensitive information might have been compromised. read more   Advertise on IT Security News. Read the complete article: Railroad Construction…

Regulators Move to Fine Telecoms for Selling Location Data

US regulators moved to impose fines Friday against the nation’s four major wireless carriers for selling location data of customers without their consent. The Federal Communications Commission proposed fining T-Mobile more than $91 million; AT&T some $57 million; Verizon $48…

Microsoft Boosts PUA Protections in Edge

Microsoft this week announced new features in its Edge browser to prevent the download of potentially unwanted applications (PUA). read more   Advertise on IT Security News. Read the complete article: Microsoft Boosts PUA Protections in Edge

Assange’s UK Extradition Hearing Paused Until May

A British judge on Thursday paused Julian Assange‘s extradition hearing following four days of intense legal wrangling over Washington’s request for the WikiLeaks founder to stand trial there on espionage charges. read more   Advertise on IT Security News. Read…

Let’s Encrypt Issues Over 1 Billion Certificates

Free and open certificate authority Let’s Encrypt on Thursday issued its billionth certificate, four and a half years after issuing the first certificate. read more   Advertise on IT Security News. Read the complete article: Let’s Encrypt Issues Over 1…

Facebook Sues Analytics Firm for Data Misuse

Facebook on Thursday filed a federal lawsuit against oneAudience data intelligence firm over a tactic it used to gather information about users of social media platforms. read more   Advertise on IT Security News. Read the complete article: Facebook Sues…

Cybercriminals Target Lincoln Health Care Company

A Lincoln health care company has been targeted by cybercriminals, but company officials said there’s no evidence of any patient data being compromised. read more   Advertise on IT Security News. Read the complete article: Cybercriminals Target Lincoln Health Care…

The Urgency for Having a True Security Platform

Ever since the birth of the Next-Generation Firewall, organizations have come to expect security devices that combine a variety of critical features and functions into a single package. To meet that demand, the number of security vendors referring to their…

McAfee Buys Browser Isolation Firm Light Point Security

Santa Clara, Calif-based McAfee has entered into a definitive agreement to acquire Baltimore, MD-based Light Point Security. Financial details have not been disclosed, but on completion of the acquisition, the Light Point staff will join McAfee, while the Light Point…

Google Boosts Detection of Malicious Documents in Gmail

New scanning capabilities that Google rolled out to Gmail have resulted in an increased overall detection rate of malicious documents. read more   Advertise on IT Security News. Read the complete article: Google Boosts Detection of Malicious Documents in Gmail

Iranian Cyberspies Focus on Long-Running Operations

The Iranian cyber-espionage group referred to as MuddyWater continues to focus on long-running operations even after a U.S. airstrike killed General Qassem Soleimani on January 2. read more   Advertise on IT Security News. Read the complete article: Iranian Cyberspies…

Massachusetts Electric Utility Hit by Ransomware

The Reading Municipal Light Department (RMLD), an electric utility in Massachusetts, informed customers on Monday that its systems were targeted last week in a ransomware attack. RMLD says it serves over 68,000 residents in the towns of Reading, North Reading,…

OpenSMTPD Vulnerability Leads to Command Injection

An update released this week for the OpenSMTPD mail server addresses an out-of-bounds read vulnerability that could lead to arbitrary command execution. OpenSMTPD is the open source implementation of the Simple Mail Transfer Protocol (SMTP) in OpenBSD, and its portable…

UK Financial Regulator Admits to Data Breach

Britain’s Financial Conduct Authority on Tuesday admitted to a data breach, in an embarrassing revelation for the regulator and its boss, who shortly takes over at the Bank of England. read more   Advertise on IT Security News. Read the…

Firefox Gets DNS-over-HTTPS as Default in U.S.

Mozilla has started rolling out encrypted DNS-over-HTTPS (DoH) by default for its Firefox users in the United States.  read more   Advertise on IT Security News. Read the complete article: Firefox Gets DNS-over-HTTPS as Default in U.S.

Samsung Says it Leaked Data on Handful of UK Customers

Samsung said Tuesday that a “technical error” caused its website to display other customers’ personal information. The technology company said the error affected only its U.K. website at http://samsung.com/UK and affected fewer than 150 customers. read more   Advertise on…

HackerOne Surpasses $82 Million in Paid Bounties

With $40 million in bug bounties paid in 2019, hacker-powered bug bounty platform HackerOne nearly doubled the amount paid out in all previous years combined, reaching $82 million. read more   Advertise on IT Security News. Read the complete article:…

Google Patches Chrome Vulnerability Exploited in the Wild

A Chrome 80 update released on Monday patches three high-severity vulnerabilities, including one that Google says has been exploited in the wild. read more   Advertise on IT Security News. Read the complete article: Google Patches Chrome Vulnerability Exploited in…

Pentagon Adopts New Ethical Principles for Using AI in War

The Pentagon is adopting new ethical principles as it prepares to accelerate its use of artificial intelligence technology on the battlefield. The new principles call for people to “exercise appropriate levels of judgment and care” when deploying and using AI…

Canada Privacy Watchdog Probes Facial Recognition Startup

Canada’s privacy watchdog on Friday announced an investigation into a US software startup reportedly capable of matching images of unknown faces to photos it mined from millions of websites and social media networks. read more   Advertise on IT Security…

Slickwraps Discloses Data Breach

Slickwraps, a company that provides protection solutions and accessories for phones, computers and other devices, has revealed that user data was compromised recently after a third party accessed an unprotected database left accessible from the Internet. read more   Advertise…

Cisco Unveils SecureX Security Platform

Cisco on Monday unveiled SecureX, a new cloud-native security platform designed to improve visibility, deliver analytics, and automate common security workflows. read more   Advertise on IT Security News. Read the complete article: Cisco Unveils SecureX Security Platform

Malware Attack Takes ISS World’s Systems Offline

Workplace experience and facility management company ISS World was hit this week by a malware attack that forced its systems offline. read more   Advertise on IT Security News. Read the complete article: Malware Attack Takes ISS World’s Systems Offline

FireEye Spotted Over 500 New Malware Families in 2019

FireEye’s incident response division Mandiant observed more than 500 new malware families last year, the company revealed in its M-Trends 2020 report released this week. FireEye analyzed 1.1 million malware samples per day in 2019 and it tracked a total…

U.S. Combat Support Agency Discloses 2019 Data Breach

The United States’ Defence Information Systems Agency (DISA) has started notifying people that their personal information may have been compromised as a result of a data breach that occured in 2019. read more   Advertise on IT Security News. Read…

Fraudulent Login Attacks Against Banks Surge: Akamai

On August 7, 2019, a single credential stuffing attack against a financial services company recorded 55,141,782 malicious login attempts. To put that in perspective, it is more than twice the daily average (22,682,022) of credential abuse attacks detected by Akamai…