Security News > 2020 > March

Small business loans app blamed as 500,000 financial records leak out of ... you guessed it, an open S3 bucket
2020-03-18 11:30

A now-defunct mobile app for loaning money to small business owners has been pinned down as the source of an exposed archive containing roughly 500,000 personal and business financial records. The research team at vpnMentor said it traced an exposed database of financial records back to a former Android/iOS app called MCA Wizard, developed jointly by Advantage Capital Funding and Argus Capital Funding back in 2018.

Human traffickers use social media oversharing to gain victims’ trust
2020-03-18 10:57

On Monday, the FBI's online crime division - the Internet Crime Complaint Center - issued a warning that human traffickers are increasingly using online platforms, including popular social media and dating platforms, to recruit and to advertise sex trafficking victims. Human trafficking victims are beaten, starved, deceived, and forced into sex work or agricultural, domestic, restaurant, or factory jobs with little to no pay.

SoftIron HyperSwitch: Built to maximize the flexibility of an open source network OS
2020-03-18 10:21

The leader in purpose-built and performance-optimized data center appliances, announced the availability of the HyperSwitch, its next-generation top-of-rack switch built to maximize the performance and flexibility of SONiC, an open source network operating system built by Microsoft for scale-out performance networking. HyperSwitch units add power and extensibility by including an AMD EPYC Embedded 3000 Processor that can be used flexibly by network operators for network security applications such as firewalls, or for dedicated storage managers, and virtually any other software desired for custom networking operations.

How CISOs Should Prepare for Coronavirus Related Cybersecurity Threats
2020-03-18 10:04

Cybersecurity firm Cynet today revealed new data, showing that the Coronavirus now has a significant impact on information security and that the crisis is actively exploited by threat actors. In light of these insights, Cynet has also shared a few ways to best prepare for the Coronavirus derived threat landscape and provides a solution to protect employees that are working from home with their personal computers because of the Coronavirus.

How CISOs Should Prepare for Coronavirus Related Cybersecurity Threats
2020-03-18 10:04

Cybersecurity firm Cynet today revealed new data, showing that the Coronavirus now has a significant impact on information security and that the crisis is actively exploited by threat actors. In light of these insights, Cynet has also shared a few ways to best prepare for the Coronavirus derived threat landscape and provides a solution to protect employees that are working from home with their personal computers because of the Coronavirus.

Some commercial password managers vulnerable to attack by fake apps
2020-03-18 09:30

Researchers at the University of York have shown that some commercial password managers may not be a watertight way to ensure cybersecurity. After creating a malicious app to impersonate a legitimate Google app, they were able to fool two out of five of the password managers they tested into giving away a password.

Magecart Cyberattack Targets NutriBullet Website
2020-03-18 09:00

A faction under the Magecart umbrella, Magecart Group 8, targeted the website of the blender manufacturer, NutriBullet, in an attempt to steal the payment-card data of its online customers. Yonathan Klijnsma, threat researcher with RiskIQ, said in a Wednesday post that a JavaScript web skimmer code was first inserted on the website of the blender retailer on Feb. 20, specifically targeting the website's checkout page, where customers input their payment information.

Pervasive digital surveillance of citizens deployed in COVID-19 fight, with rules that send genie back to bottle
2020-03-18 06:38

Pervasive surveillance through digital technologies is the business model of Facebook and Google. Speaking elsewhere, Netanyhau said the digital tools are those used by Israeli security agency Shin Bet to observe terrorists.

Security is leaving the data center and moving to the edge
2020-03-18 05:58

The traditional network security model, in which traffic is routed through the data center for inspection and policy enforcement, is for all intents and purposes obsolete. The writing is on the wall: security needs to move from the data center to the edge of the network.

Healthcare cybersecurity in the time of coronavirus
2020-03-18 05:36

Patients might end up bearing the brunt of successful cyber attacks but, Covid-19 or no Covid-19, the danger for healthcare organizations has effectively remained the same - only the stakes got higher. It is crucial for healthcare organizations and agencies not to ignore cybersecurity and data protection at this moment.