Cybersecurity News
Outgoing FCC Chair Issues Final Security Salvo Against China
Ajit Pai says Chinese telecom companies ‘biggest national security threat’ for regulators in exit interview.25 January 2021
2.28M MeetMindful Daters Compromised in Data Breach
The ShinyHunters hacking group offer a raft of information, from location and contact info to dating preferences and bodily descriptions, as a free download.25 January 2021
Small Security Teams Have Big Security Fears, CISOs Report
Researchers poll security leaders who are tasked with protecting large organizations but have a small presence and budget.25 January 2021
Cisco DNA Center Bug Opens Enterprises to Remote Attack
The high-severity security vulnerability (CVE-2021-1257) allows cross-site request forgery (CSRF) attacks.25 January 2021
SonicWall Breach Stems from ‘Probable’ Zero-Days
The security vendor is investigating potential zero-day vulnerabilities in its Secure Mobile Access (SMA) 100 series.25 January 2021
Dutch COVID-19 patient data sold on the criminal underground
Two individuals have been arrested in the Netherlands last week for selling data from Dutch COVID-19 systems on Telegram, Snapchat and Wickr.25 January 2021
How to Better Secure Your Microsoft 365 Environment
Security experts offer Microsoft 365 security guidance as more attackers target enterprise cloud environments.25 January 2021
2020's COVID Accelerated Digitalization Demands Stronger Cybersecurity in 2021
As critical infrastructure faces increasing and sophisticated attacks, these trends will enable the energy sector to shore up its cybersecurity defenses.25 January 2021
Data of BuyUcoin cryptocurrency exchange traders allegedly leaked online
A customer update, since removed, claimed the leak was “dummy data.”25 January 2021
Comparing Different AI Approaches to Email Security
Get to know the difference between "supervised" and "unsupervised" machine learning.25 January 2021
DreamBus botnet targets enterprise apps running on Linux servers
DreamBus botnet uses exploits and brute-force to target PostgreSQL, Redis, SaltStack, Hadoop, Spark, and others.25 January 2021
Tesla sues ex-employee over alleged 'brazen' theft of confidential code, files
The court case claims an engineer swiped files and then tried to delete the evidence.25 January 2021
Insurers 'funding organised crime' by paying ransomware claims
Exclusive: former cybersecurity chief calls for law change and warns situation is ‘close to getting out of control’
Insurers are inadvertently funding organised crime by paying out claims from companies who have paid ransoms to regain access to data and systems after a hacking attack, Britain’s former top cybersecurity official has warned.
Ciaran Martin, who ran the National Cyber Security Centre until last August, said he feared that so-called ransomware was “close to getting out of control” and that there was a risk that NHS systems could be hit during the pandemic.
Continue reading...24 January 2021
Hacker leaks data of 2.28 million dating site users
Data belongs to dating site MeetMindful and includes everything from real names to Facebook account tokens, and from email addresses and geo-location information.24 January 2021
Rogue CCTV technician spied on hundreds of customers during intimate moments
Prosecutors said the technician accessed more than 200 customer CCTV systems on more than 9,600 occasions to spy on them getting naked and engaging in sexual activity.23 January 2021
SonicWall says it was hacked using zero-days in its own products
The networking device vendor has published a series of mitigations as it's investigating the incident and preparing patches.23 January 2021
Intel Confirms Unauthorized Access of Earnings-Related Data
News likely contributed to slide of over 9% in chipmaker's stock at one point Friday.22 January 2021
Microsoft Edge, Google Chrome Roll Out Password Protection Tools
The new tools on Chrome and Edge will make it easier for browser users to discover - and change - compromised passwords.22 January 2021
Amazon Kindle RCE Attack Starts with an Email
The "KindleDrip" attack would have allowed attackers to siphon money from unsuspecting victims.22 January 2021
Speed of Digital Transformation May Lead to Greater App Vulnerabilities
The fastest-moving industries are struggling to produce secure code, according to AppSec experts.22 January 2021