Security News > 2017 > August

Snapchat Pays $20,000 for Vulnerable Jenkins Instances (Security Week)
2017-08-24 12:22

Snapchat has awarded researchers a total of $20,000 for finding exposed Jenkins instances that allowed arbitrary code execution and provided access to sensitive data. read more

Accused 'Hacker for Hire' for Russia Pleads Not Guilty (InfoRiskToday)
2017-08-24 12:02

Canadian Allegedly Aided Russians Who Perpetrated Massive Yahoo Data BreachExtradited Canadian national Karim Baratov, who's been accused of helping the Russian intelligence officers who allegedly...

Massive Government Data Leak in Sweden (Schneier on Security)
2017-08-24 11:30

Seems to be incompetence rather than malice, but a good example of the dangers of blindly trusting the cloud....

Zerodium Offers $500,000 For Messaging, Email App Exploits (Security Week)
2017-08-24 11:07

Zerodium has made some changes to its exploit acquisition program and the company is now offering up to $500,000 for remote code execution and privilege escalation vulnerabilities affecting...

Beware of Windows/MacOS/Linux Virus Spreading Through Facebook Messenger (The Hackers News)
2017-08-24 09:31

If you came across any Facebook message with a video link sent by anyone, even your friend — just don’t click on it. Security researchers at Kaspersky Lab have spotted an ongoing cross-platform...

Here's How CIA Spies On Its Intelligence Liaison Partners Around the World (The Hackers News)
2017-08-24 03:41

WikiLeaks has just published another Vault 7 leak, revealing how the CIA spies on their intelligence partners around the world, including FBI, DHS and the NSA, to covertly collect data from their...

A Company Offers $500,000 For Secure Messaging Apps Zero-Day Exploits (The Hackers News)
2017-08-24 00:27

How much does your privacy cost? It will soon be sold for half a Million US dollars. A controversial company specialises in acquiring and reselling zero-day exploits is ready to pay up to...

Analysis: The Merits of Medical Device Security Legislation (InfoRiskToday)
2017-08-23 21:03

Could proposed legislation force manufacturers and healthcare entities to put more effort into bolstering the cybersecurity of medical devices? In an interview, cybersecurity expert Joshua Corman...

Delaware Toughens Data Breach Notification Law (InfoRiskToday)
2017-08-23 20:33

Will Other States Follow and Adopt Similar Measures?Delaware has become the second state - the first was Connecticut - to require organizations to provide residents one year of free credit...

7 Tips for Recruiting the Infosec Talent You Need Now (InfoRiskToday)
2017-08-23 20:03

New Ways to Attract Job Candidates and Keep Them AroundHiring managers will need to get increasingly creative to find talent to fill their vacant information security positions, particularly in a...