Security News > 2020 > September

TikTok Gets Reprieve as Judge Halts Trump Download Ban
2020-09-28 10:16

TikTok won a last-minute reprieve late Sunday as a US federal judge halted enforcement of a politically charged ban ordered by the Trump administration on downloads of the popular video app, hours before it was set to take effect. The Trump administration order had sought to ban new downloads of the app from midnight but would allow use of TikTok until November 12, when all usage would be blocked.

Feds warn foreign disinformation will be spamming US voters well after the November election to sow discord and doubt
2020-09-28 10:06

Foreign-backed disinformation campaigns will spread fake news about the results of the upcoming US election in an effort to sow doubt and outrage among the American public. The two agencies believe that in the immediate aftermath of the presidential election on November 3, Americans will be bombarded with false stories about the vote tally, reports of voter fraud, and other issues that would stoke division as the country awaits official election results - a process that could take weeks.

Too many staff have privileged work accounts for no good reason, reckon IT bods
2020-09-28 09:07

Around 40 per cent of staff in British and American corporations have access to sensitive data that they don't need to complete their jobs, according to recent research. In a survey commissioned by IT security firm Forcepoint of just under 900 IT professionals, 40 per cent of commercial sector respondents and 36 per cent working in the public sector said they had privileged access to sensitive data through work.

Twitter Says Bug Leading to API Key Leak Patched
2020-09-28 08:52

Twitter last week started sending emails to developers to inform them of a vulnerability that might have resulted in the disclosure of developer information, including API keys. Designed to provide developers using the Twitter platform and APIs with access to documentation, community discussion, and other type of information, the portal also offers app and API key management functionality.

Naked Security Live – “SMS scams: keep yourself and your family safe!”
2020-09-28 07:59

Naked Security Live - here's the recorded version of our latest video. Enjoy.

Are injection flaws the Bohemian Rhapsody of cybersecurity?
2020-09-28 06:00

Get ready for this year’s OWASP Top 10 with us and F5 Webcast Whether you’re into cybersecurity or application development, you probably also like lists, which means you probably love the OWASP Top 10.…

Hardware security: Emerging attacks and protection mechanisms
2020-09-28 05:30

Maggie Jauregui's introduction to hardware security is a fun story: she figured out how to spark, smoke, and permanently disable GFCI wirelessly with a walkie talkie. Hardware-based security typically refers to the defenses that help protect against vulnerabilities targeting these devices, and it's main focus it to make sure that the different hardware components working together are architected, implemented, and configured correctly.

Cybersecurity lessons learned from data breaches and brand trust matters
2020-09-28 05:00

COVID-19 has put a renewed spotlight on the importance of defending against cyberattacks and data breaches as more users are accessing data from remote or non-traditional locations. The frequency and sophistication of ransomware, phishing schemes, and data breaches have the potential to destroy both brand health and financial viability.

Putin to Trump: Let's collude to stop election hacking
2020-09-28 04:32

Russia has taken the unusual step of posting a proposal for a new information security collaboration with the United States of America, including a no-hack pact applied to electoral affairs. The document, titled "Statement by President of Russia Vladimir Putin on a comprehensive program of measures for restoring the Russia - US cooperation in the filed [sic] of international information security", opens by saying "One of today's major strategic challenges is the risk of a large-scale confrontation in the digital field" before adding: "A special responsibility for its prevention lies on the key players in the field of ensuring international information security."

Measuring impact beyond a single incident
2020-09-28 04:30

In an environment where very limited transparency on the root cause and the true impact is afforded we are left with isolated examples to point to the direct cost of a security incident. For the impact on ransomware, it was the impact WannaCry had on healthcare and will likely be replaced with the awful story where a patient sadly lost their life because of a ransomware attack.