Security News > 2020

Encoding Stolen Credit Card Data on Barcodes
2020-02-18 18:00

Crooks are constantly dreaming up new ways to use and conceal stolen credit card data. According to the U.S. Secret Service, the latest scheme involves stolen card information embedded in barcodes affixed to phony money network rewards cards.

Dell to Sell RSA Security Unit for $2 Billion
2020-02-18 17:51

Dell Technologies on Tuesday said that it has agreed to sell its RSA Security unit to a private equity group for roughly $2.075 billion in cash. Under the terms of the agreement, a consortium led by Symphony Technology Group, Ontario Teachers' Pension Plan Board and AlpInvest Partners, will acquire RSA assets including RSA Archer, RSA NetWitness Platform, RSA SecurID, RSA Fraud and Risk Intelligence and the RSA Conference.

Dell to Sell RSA to Private Equity Firm for $2 Billion
2020-02-18 17:48

Dell Technologies has agreed to sell its RSA security division to private equity firm Symphony Technology Group in an all cash deal worth more than $2 billion, the companies announced Tuesday. Dell acquired RSA in 2016, along with VMware and Pivotal, as part of a blockbuster $67 billion deal for EMC, a company best known for its storage products.

$2.07bn? That's one Dell of a deal offloads infosec biz RSA
2020-02-18 17:30

Dell Technologies is flogging its infosec business RSA for $2.075bn as it tries to reduce its longstanding debt. "The transaction will further simplify our business and product portfolio. It also allows Dell Technologies to focus on our strategy to build automated and intelligent security into infrastructure, platforms and devices to keep data safe, protected and resilient."

Active Exploits Hit Vulnerable WordPress ThemeGrill Plugin
2020-02-18 17:27

Researchers are urging users of a vulnerable WordPress plugin, ThemeGrill Demo Importer, to update as soon as possible after discovering attackers are actively exploiting a flaw in the plugin. This WordPress plugin helps users import and manage ThemeGrill templates on their sites.

Shipping is so insecure we could have driven off in an oil rig, says Pen Test Partners
2020-02-18 16:45

Penetration testers looking at commercial shipping and oil rigs discovered a litany of security blunders and vulnerabilities - including one set that would have let them take full control of a rig at sea. Making heavy use of the word "Poor" to summarise what he had seen over the past year, Hearne wrote that he and his colleagues had examined everything from a deep water exploration and the aforementioned drilling rig to a brand new cruise ship to a Panamax container vessel, and a few others in between.

Encryption Firm With NSA Roots Raises $10 Million
2020-02-18 16:43

Enveil, a Fulton, Maryland-based data security company, today announced that it has secured $10 million in Series A funding. Founded in 2016, Enveil launched ZeroReveal in July 2018, its commercial homomorphic encryption product that helps protect data while it's being used or processed.

F-Secure Patches Old AV Bypass Vulnerability
2020-02-18 15:37

A vulnerability addressed by F-Secure in some of its business products could have been exploited to bypass their scanning engine using malformed archives. The patched issue is actually over a decade old - it was initially detailed in 2009 by security researcher Thierry Zoller - and resides in an anti-virus application's inability to scan a compressed archive that a user can access.

Egnyte Launches New Content Visibility and Control Platform
2020-02-18 15:35

Mountain View, CA-based Egnyte is combining its Protect and Connect platforms into a single Content Services platform. "Digital content represents the lion share of data for most companies. In only the past few years we've seen its volume and value grow exponentially - and with that, its business risk," said Egnyte CEO, Vineet Jain.

ExtraHop Expands Enterprise IoT Security Features
2020-02-18 15:11

The introduction of IoT devices into the enterprise can improve the work experience and productivity of staff, but often comes with increased security risk. IoT devices notoriously bring additional vulnerabilities to the new edge without being adequately protected by the organization's network security.