Security News > 2020 > July

Reply-All storm flares as email announcing privacy policy puts 500 addresses in the 'To' field, not 'BCC'
2020-07-29 04:56

In 1965, Gordon Moore published a short informal paper, Cramming more components onto integrated circuits. Based on not much more but these few data points and his knowledge of silicon chip development - he was head of R&D at Fairchild Semiconductors, the company that was to seed Silicon Valley - he said that for the next decade, component counts by area could double every year.

Security teams increasingly stressed due to lack of proper tools, executive support
2020-07-29 04:30

93% of security professionals lack the tools to detect known security threats, and 92% state they are still in need of the appropriate preventative solutions to close current security gaps, according to LogRhythm. Based on a global survey of more than 300 security professionals and executives, LogRhythm sought to understand the root causes of the stress under which security teams operate, obtain feedback on the ways in which it could be alleviated, and identify the best paths to remediation.

Industrial VPN Flaws Could Let Attackers Target Critical Infrastructures
2020-07-29 04:12

Cybersecurity researchers have discovered critical vulnerabilities in industrial VPN implementations primarily used to provide remote access to operational technology networks that could allow hackers to overwrite data, execute malicious code, and compromise industrial control systems. A new report published by industrial cybersecurity company Claroty demonstrates multiple severe vulnerabilities in enterprise-grade VPN installations, including Secomea GateManager M2M Server, Moxa EDR-G902, and EDR-G903, and HMS Networks eWon's eCatcher VPN client.

Industrial VPN Flaws Could Let Attackers Target Critical Infrastructures
2020-07-29 04:12

Cybersecurity researchers have discovered critical vulnerabilities in industrial VPN implementations primarily used to provide remote access to operational technology networks that could allow hackers to overwrite data, execute malicious code, and compromise industrial control systems. A new report published by industrial cybersecurity company Claroty demonstrates multiple severe vulnerabilities in enterprise-grade VPN installations, including Secomea GateManager M2M Server, Moxa EDR-G902, and EDR-G903, and HMS Networks eWon's eCatcher VPN client.

IBM finds cyberattacks costing companies nearly $4 million per breach
2020-07-29 04:01

Data breaches are now costing companies nearly $4 million according to a new report from IBM Security and the Ponemon Institute released Wednesday. On average, breaches now cost organizations $3.86 million per attack, with the United States having the highest average cost per breach and healthcare being the most heavily hit industry.

Public cloud environments leave numerous paths open for exploitation
2020-07-29 04:00

As organizations across industries rapidly deploy more assets in the public cloud with Amazon, Microsoft, and Google, they're leaving numerous paths open for exploitation, according to Orca Security. While public cloud providers such as AWS, Microsoft Azure, and Google Cloud Platform keep their platforms secure, customers are still responsible for securing the workloads, data, and processes they run inside the cloud - just as they do in their on-prem world.

Assessing the email security controls used by 10,000 U.S. state and local election administrators
2020-07-29 03:30

The majority of state and local election administrators have only rudimentary or non-standard technologies to protect themselves from phishing. Fewer than 3 out of 10 election administrators have basic controls to prevent phishing.

OkCupid Dating App Flaws Could've Let Hackers Read Your Private Messages
2020-07-29 03:10

Cybersecurity researchers today disclosed several security issues in popular online dating platform OkCupid that could potentially let attackers remotely spy on users' private information or perform malicious actions on behalf of the targeted accounts. According to a report shared with The Hacker News, researchers from Check Point found that the flaws in OkCupid's Android and web applications could allow the theft of users' authentication tokens, users IDs, and other sensitive information such as email addresses, preferences, sexual orientation, and other private data.

OkCupid Dating App Flaws Could've Let Hackers Read Your Private Messages
2020-07-29 03:10

Cybersecurity researchers today disclosed several security issues in popular online dating platform OkCupid that could potentially let attackers remotely spy on users' private information or perform malicious actions on behalf of the targeted accounts. According to a report shared with The Hacker News, researchers from Check Point found that the flaws in OkCupid's Android and web applications could allow the theft of users' authentication tokens, users IDs, and other sensitive information such as email addresses, preferences, sexual orientation, and other private data.

Building a quantum internet: Fast data exchange, difficult to eavesdrop
2020-07-29 03:00

Crucial steps toward building such an internet are already underway in the Chicago region, which has become one of the leading global hubs for quantum research. One of the hallmarks of quantum transmissions is that they are exceedingly difficult to eavesdrop on as information passes between locations.