Security News > 2020 > October

#BeCyberSmart – why friends don’t let friends get scammed
2020-10-01 11:00

Starting in about 2000 or 2001, cybercrooks figured out not only how to spread mayhem with malware, but also how to make money illegally, too. Simply put: a cybersecurity injury to you can quickly turn into a cybersecurity injury to everyone else.

Twitter Removes Iran-Linked Accounts Aimed at Disrupting U.S. Presidential Debate
2020-10-01 10:48

Twitter on Wednesday announced that it removed 130 accounts originating from Iran that were aimed at disrupting the first 2020 U.S. presidential debate. The social platform also explains that it was able to quickly identify the accounts and remove them.

UK privacy watchdog confirms probe into NHS England COVID-19 app after complaints of spammy emails, texts
2020-10-01 09:05

Britain's Information Commissioner's Office has confirmed it is investigating grumbles about heavy-handed marketing emails and texts promoting the NHS COVID-19 contact-tracing app in England. Between 26 and 27 September, NHS Test and Trace messaged anyone resident in the country who was over the age of 16 and had previously provided their contact details to a GP. Those contacted had not specifically opted in to receive marketing communications regarding the NHS COVID-19 app.

UK privacy watchdog confirms probe into NHS England COVID-19 app after complaints of spammy emails, texts
2020-10-01 09:05

Britain's Information Commissioner's Office has confirmed it is investigating grumbles about heavy-handed marketing emails and texts promoting the NHS COVID-19 contact-tracing app in England. Between 26 and 27 September, NHS Test and Trace messaged anyone resident in the country who was over the age of 16 and had previously provided their contact details to a GP. Those contacted had not specifically opted in to receive marketing communications regarding the NHS COVID-19 app.

Microsoft Publishes Guide to Securing Systems Vulnerable to Zerologon Attacks
2020-10-01 08:47

Microsoft has published a support article to provide guidance on what organizations need to do to ensure that they are not exposed to attacks targeting the Zerologon vulnerability. Addressed on August 2020 Patch Tuesday, the flaw was identified in the Microsoft Windows Netlogon Remote Protocol and can be abused by remote attackers to compromise Active Directory domain controllers and gain administrator access.

AWS launches Amazon Timestream, a serverless time series database for IoT and operational applications
2020-10-01 07:33

Amazon Timestream addresses these challenges by giving customers a purpose-built, serverless time series database for collecting, storing, and processing time series data. Amazon Timestream integrates with popular data collection, visualization, and machine learning tools that customers use today, including services like AWS IoT Core, Amazon Kinesis and Amazon MSK, Amazon QuickSight, and Amazon SageMaker, as well as open source, third-party tools like Grafana and Telegraf.

InterPlanetary Storm Botnet Infects 13K Mac, Android Devices
2020-10-01 07:00

A new variant of the InterPlanetary Storm malware has been discovered, which comes with fresh detection-evasion tactics and now targets Mac and Android devices. Researchers say, the malware is building a botnet with a current estimated 13,500 infected machines across 84 countries worldwide - and that number continues to grow.

Chap beats rap in WhatsApp zap flap: Russian banker walks from insider trading case after deleting software
2020-10-01 06:53

Konstantin Vishnyak, 42, was cleared by Southwark Crown Court in London, England, of destroying documents relevant to a now-discontinued investigation into insider trading. It was reported that Vishnyak, formerly of VTB Capital, deleted the app and messages from his iPhone - one of two handsets he gave to police - not out of fear of an investigation into insider trading, but rather in an effort to conceal his friendship with Andrei Lugovoi, the Russian politician wanted in connection with the polonium poisoning of Alexander Litvinenko in 2006.

Three immediate steps to take to protect your APIs from security risks
2020-10-01 05:30

If there's no larger, cohesive conversation, then various development and operational teams could be taking conflicting approaches to mitigating API security risks. To improve an organization's API security posture, it's critical that outstanding questions are asked and answered immediately so that gaps in security are reduced and closed.

Singapore to treat infosec as equivalent public good to fresh running water
2020-10-01 05:13

The deputy chief executive of Singapore's Cyber Security Agency, Brigadier General Gaurav Keerthi, says the island nation now considers providing a secure environment to citizens and businesses the equivalent of providing fresh water and sewerage services, and will next week improve digital hygiene with a voluntary "Cybersecurity Labelling Scheme" that will rate consumer broadband gateways. Speaking at the Black Hat Asia conference in Singapore today, Keerthi explained that it's his job to defend Singapore from cyber-threats.