Security News > 2020 > October

IoT Device Takeovers Surge 100 Percent in 2020
2020-10-23 20:49

IoT devices are now responsible for 32.72 percent of all infections observed in mobile and Wi-Fi networks - up from 16.17 percent in 2019. Researchers with Nokia's Threat Intelligence Lab said, in the Threat Intelligence Report 2020 released this week, that they believe that number of IoT infections will continue to grow "Dramatically" as connected devices continue to populate in homes and enterprise settings alike.

Louisiana Calls Out National Guard to Fight Ransomware Surge
2020-10-23 20:28

The National Guard has been called in to help stop a series of government-focused ransomware attacks in Louisiana, according to a report. The Louisiana National Guard has declined to comment on the incidents.

Election Security: Beyond Mail-In Voting
2020-10-23 19:10

That presents a fresh set of security concerns, which include a lack of transparency over the security measures and voter auditing applied to each type of voting method. The lack of resources needed to adapt and secure the mail-in voting process by the early November election date is has been another cause for concern.

YouTube-dl removed from GitHub after RIAA DMCA notice
2020-10-23 18:35

The Recording Industry Association of America, Inc. has taken down YouTube-dl's GitHub repositories using a DMCA takedown notice. Today, the RIAA took down the YouTube-dl GitHub repositories by filing a DMCA infringement notice with GitHub.

HPE fixes maximum severity remote auth bypass bug in SSMC console
2020-10-23 18:22

Hewlett Packard Enterprise has fixed a maximum severity remote authentication bypass vulnerability affecting the company's HPE StoreServ Management Console data center storage management solution. HPE SSMC is a management and reporting console for HPE Primera and HPE 3PAR StoreServ systems data center arrays.

Georgia Election Data Hit in Ransomware Attack
2020-10-23 18:21

Ransomware gangs have officially entered the 2020 election fray, with reports of one of the first breaches of the voting season, on Hall County, Ga. The county's database of voter signatures was impacted in the attack along with other government systems. Although the county said the voting process hasn't been impacted by the ransomware attack, the incident is a warning to other municipalities to lock down their systems, particularly in these last days leading up to the election.

Palo Alto Networks threatens to sue security startup for comparison review, says it breaks software EULA
2020-10-23 17:58

Palo Alto Networks has threatened a startup with legal action after the smaller biz published a comparison review of one of its products. Israel-based Orca Security received a cease-and-desist letter from a lawyer representing Palo Alto after Orca uploaded a series of online videos reviewing of one of Palo Alto's products and compared it to its own.

The Week in Ransomware - October 23rd 2020 - From Russia with Love
2020-10-23 17:38

Jakub Kroustek found new Dharma ransomware variants that append the. Jakub Kroustek found a new Dharma ransomware variant that appends the.259 extension to encrypted files.

S3 Ep3: Cryptography, hacking and pwning Chrome [Podcast]
2020-10-23 17:18

This week: the DOJ's attempt to reignite the Battle to Break Encryption; the story of the Russian hackers behind the Sandworm Team; a zero-day bug just patched in Chrome; and why your vocabulary needs the word "Restore" even more than it needs "Backup". WHERE TO FIND THE PODCAST ONLINE. You can listen to us on Soundcloud, Apple Podcasts, Google Podcasts, Spotify, Stitcher, Overcast and anywhere that good podcasts are found.

75% of all 56 US states and territories show signs of vulnerable election IT infrastructure, report finds
2020-10-23 17:15

SecurityScorecard released a report earlier this month that looked through the overall cybersecurity posture of all 56 US states and territories leading up to the presidential election. The study found that 75% of all states and territories had IT infrastructures that are vulnerable to a variety of cyberattacks.