Security News > 2020 > December

uCloudlink and Vodafone extend partnership on data procurement
2020-12-22 00:30

uCloudlink has extended its partnership with Vodafone on data procurement, which has spanned six years. Under the partnership, Vodafone works as one of uCloudlink's data suppliers and ensures the company's occasional expansion of data traffic capacity and coverage.

Cognizant acquires Inawisdom to help businesses improve business outcomes
2020-12-22 00:00

Cognizant announced it has acquired Inawisdom to help businesses make better, faster decisions that improve business outcomes. "We are pleased to welcome Inawisdom's skilled team to Cognizant and further accelerate our innovation on data modernization and intelligent decision-making. Cognizant and Inawisdom's clients will benefit from our shared, deep relationships with AWS and our combined expertise with AI, machine learning, cloud, and data analytics."

May Mitchell joins iboss as Senior Vice President of Marketing
2020-12-21 23:45

Iboss announces that May Mitchell has joined the firm as Senior Vice President of Marketing. In her new role, Mitchell will oversee sales and marketing of the company's industry-leading Secure Access Service Edge cloud network security services and Zero Trust Network Access solution.

OneLogin expands leadership team with the appointment of two new members
2020-12-21 23:30

OneLogin announced the appointment of two new members to its leadership team, strengthened at the end of a landmark year for OneLogin which saw it named a leader in the 2020 Gartner Magic Quadrant for Access Management. Alongside Damon, OneLogin has also announced the internal appointment of Matt Hurley as Chief Revenue Officer.

Nosy Ex-Partners Armed with Instagram Passwords Pose a Serious Threat
2020-12-21 21:48

Smart-security practices like not sharing passwords with anyone and multi-factor authentication are two simple ways to prevent this type of personal insider threat, Dan Conrad, field strategist with One Identity, told Threatpost. "People assume that they should change their passwords after a big life event if you're following strong password hygiene practices, an individual's password shouldn't be affected by [this], as no one else should have access to the password in the first place," Conrad said in an emailed response to the report.

Smart Doorbell Disaster: Many Brands Vulnerable to Attack
2020-12-21 21:35

That fresh assessment comes from NCC Group, which published a report last week outlining "Domestic IoT nightmares." In partnership with the publication Which?, it assessed smart doorbell models made by three vendors Victure, Qihoo and Accfly along with white-box offerings from three additional doorbell makers. Smart doorbells lead the charge when it came to a 33 percent increase in smart home gadgets flooding U.S homes in 2020, according to Hub Entertainment Research.

Defending Against State and State-Sponsored Threat Actors
2020-12-21 21:01

State actors can draw upon the skills and resources of their national intelligence communities, while state-sponsored actors, while not actually part of a state organization, can still draw upon the financial and technical assets of their sponsors. Another fundamental difference between "Civilian" and "State" actors is that law-enforcement agencies are better equipped to address threat actors who don't have state backing.

Cybersecurity pros: Are humans really the weakest link?
2020-12-21 21:00

Including Ciarán Mc Mahon, Ph.D., a faculty member at University College Dublin and director of the Institute of Cyber Security, suggests that quote is why the adage "Humans are the weakest link" is part and parcel to the digital world. If we humans are the weakest link, that means the other links in the chain-hardware and software, for example-are more robust and more secure.

Zero-Click Apple Zero-Day Uncovered in Pegasus Spy Attack
2020-12-21 19:38

All of the operators used the NSO Group's infamous Pegasus spyware as their final payload. Pegasus is a mobile phone-surveillance solution that enables customers to remotely exploit and monitor devices. The latest version of the Pegasus implant has a number of capabilities, according to Citizen Lab, including: Recording audio from the microphone including both ambient "Hot mic" recording and audio of encrypted phone calls; taking pictures; tracking device location; and accessing passwords and stored credentials.

Critical Vulnerabilities Expose Dell Wyse Thin Client Devices to Attacks
2020-12-21 19:04

Dell on Monday informed customers that updates released for some of its Wyse Thin Client products patch a couple of critical vulnerabilities that can be exploited remotely without authentication to compromise devices. Dell Wyse Thin Client is a small form-factor PC series that runs an operating system named ThinOS, which Dell advertises as "The most secure thin client operating system." According to CyberMDX, there are more than 6,000 organizations using these products, including many healthcare providers, in the U.S. alone.