Security News > 2020 > January

Analysis: Countering Nation-State Attacks in 2020
2020-01-03 13:03

The latest edition of the ISMG Security Report discusses countering the threat of nation-state cyberattacks in 2020. Also featured: an update on France's experiment with facial recognition...

Don't Xiaomi pics of other people's places! Chinese kitmaker fingers dodgy Boxing Day cache update after Google banishes it from Home
2020-01-03 12:47

Xiaomi has blamed some post-Christmas cache digestion problems after finding itself plonked on the naughty step by Google - which blocked the Chinese tech conglomerate's devices from its Nest Hub and Assistant last night. The Xiaomi Mijia 1080P Smart IP Security Camera retails for £38 on Amazon, and can be bought from Chinese retailers like BangGoood and GearBest for about $25. Dio-V says he bought his camera new from AliExpress, and it was running the latest firmware version.

Don't Xiaomi pics of other people's places! Chinese kitmaker fingers dodgy Boxing Day cache update after Google banishes it from Home
2020-01-03 12:47

Xiaomi has blamed some post-Christmas cache digestion problems after finding itself plonked on the naughty step by Google - which blocked the Chinese tech conglomerate's devices from its Nest Hub and Assistant last night. The Xiaomi Mijia 1080P Smart IP Security Camera retails for £38 on Amazon, and can be bought from Chinese retailers like BangGoood and GearBest for about $25. Dio-V says he bought his camera new from AliExpress, and it was running the latest firmware version.

Chrome Extension Stealing Cryptocurrency Keys and Passwords
2020-01-03 12:09

According to Denley, the extension is dangerous to users in two ways. First, any funds managed directly inside the extension are at risk.

This page is currency unavailable... Travelex scrubs UK homepage, kills services, knackers other sites amid 'software virus' infection
2020-01-03 05:53

Foreign currency mega-exchange Travelex said on Thursday it was forced offline by a "Software virus" infection, bring down a number of currency-exchange websites with it. The outage at Travelex has had a knock-in effect in that it knackered currency-swap services for a number of UK banks and organizations relying on the exchange.

Xiaomi Cameras Connected to Google Nest Expose Video Feeds From Others
2020-01-03 02:58

In one such recent privacy mishap, smart IP cameras manufactured by Chinese smartphone maker Xiaomi found mistakenly sharing surveillance footage of Xiaomi users with other random users without any permission. The issue appears to affect Xiaomi IP cameras only when streamed through connected Google's Nest Hub, which came into light when a Reddit user claimed that his Google Nest Hub is apparently pulling random feeds from other users instead of his own Xiaomi Mijia cameras.

And we now go live to Apple v Corellium, where the iTitan is still lobbing copyright fireballs at the virtual iPhone upstart
2020-01-03 01:02

The case - essentially a US copyright infringement claim - centers on Apple's allegations that Corellium illegally copied the mobile operating system, and unlawfully made derivative versions by modifying the software to run on Corellium's iPhone hypervisor. While Corellium argued that Apple is trying to crack down on who can rifle through iOS for bugs and exploitable flaws, and snuff out jailbreaking efforts, the iGiant's latest paperwork homes in on its central allegations that Corellium is trying to make a fast buck by ripping off iOS and its bundled apps and user interface - technology that Apple has not licensed to Corellium.

Data Breach Affects 63 Landry’s Restaurants
2020-01-02 20:55

Dining giant Landry's disclosed a data breach, Thursday, warning that malware had infected its order-entry systems to steal customers' payment card information. Landry's, which owns over 600 popular American restaurants across 35 states, such as Del Frisco's Grill, McCormick & Schmick's, Rainforest Café and more, said that 63 of these restaurants were impacted by malware that targeted customers' payment card data.

Ambulance Company Slapped With HIPAA Fine
2020-01-02 20:18

Federal regulators have smacked a Georgia-based ambulance company with a $65,000 financial settlement and corrective action plan in a case involving "Longstanding" HIPAA compliance issues. OCR's says its investigation "Uncovered longstanding noncompliance" with the HIPAA rules, including failures to conduct a risk analysis, provide a security awareness and training program and implement HIPAA Security Rule policies and procedures.

Alert overload is burning out security analysts
2020-01-02 20:02

Alert overload is changing the work focus in security operations centers and increasing the risk of burnout among analysts, according to a survey by CriticalStart. Analyzing and remediating security threats: 41%.Reducing the time it takes to investigate a security alert: 25%.Investigating as many alerts as possible: 18%.Limiting the number of alerts sent to clients for review: 13%. That last responsibility-limiting contact with clients-seems to be the default approach for 57% of the respondents.