Security News > 2021

Want to Modernize Your SOC? Start with Data
2021-03-18 13:24

Many organizations today deal with data that is noisy and unstructured, decentralized without prioritization, and managed with spreadsheets. To gain a comprehensive understanding of the threats you are facing and what you must defend, you need to start by aggregating internal data from across the entire ecosystem - the telemetry, content and data created by each layer in your security architecture, on-premises and in the cloud.

Chinese nation state hackers linked to Finnish Parliament hack
2021-03-18 13:10

Chinese nation-state hackers have been linked to an attack on the Parliament of Finland that took place last year and led to the compromise of some parliament email accounts. "Some parliament e-mail accounts may have been compromised as a result of the attack, among them e-mail accounts that belong to MPs," Parliament officials said at the time.

U.S. Says Russia, Iran Attempted Interference in 2020 Presidential Election
2021-03-18 12:30

A declassified joint report from several United States agencies assesses that Russian and Iranian threat actors did attempt to meddle in the 2020 U.S. presidential election, but claims that the technical integrity of the voting process wasn't affected. The joint report is meant to provide information on the extent to which foreign actors attempted interference with the 2020 U.S. elections, along with details on whether these adversaries targeted political organizations, campaigns, or election candidates, and an assessment on whether the attacks were able to successfully compromise the targeted infrastructure.

Identity Verification Company Socure Raises $100 Million at $1.3 Billion Valuation
2021-03-18 12:00

Digital identity verification firm Socure this week announced raising $100 million in a Series D funding round. The round, which brings the total invested into the company to $196 million, was led by Accel, with participation from Commerce Ventures, Scale Venture Partners, Flint Capital, Citi Ventures, Wells Fargo Strategic Capital, Synchrony, Sorenson, and Two Sigma Ventures, among others.

Tutor LMS for WordPress Open to Info-Stealing Security Holes
2021-03-18 11:50

Security vulnerabilities in Tutor LMS, a WordPress plugin installed on more than 20,000 sites, open the door to information theft and privilege escalation, according to researchers. Tutor LMS is a learning-management system for educators that allows them to digitally reach their students.

Exploiting Spectre Over the Internet
2021-03-18 11:17

Google has demonstrated exploiting the Spectre CPU attack remotely over the web: Today, we’re sharing proof-of-concept (PoC) code that confirms the practicality of Spectre exploits against...

Ripoff Report Hacker Gets 12 Months in Prison
2021-03-18 10:44

The United States Department of Justice on Wednesday announced that a Cypriot national who admitted to hacking the websites of various U.S.-based companies was sentenced to 12 months and one day in prison, on top of the four years already served in custody. In January 2021, Epifaniou admitted in court to perpetrating a scheme in which he hacked the websites of multiple companies, exfiltrated data of interest, and then contacted the victim organizations to demand a ransom payment, threatening to make the data public.

Polish State Websites Hacked and Used to Spread False Info
2021-03-18 09:46

Two Polish government websites were hacked Wednesday and used briefly to spread false information about a non-existent radioactive threat, in what a Polish government official said had the hallmarks of a Russian cyberattack. The National Atomic Energy Agency and Health Ministry websites briefly carried claims of a supposed nuclear waste leak coming from neighboring Lithuania and threatening Poland.

The Roaring Twenties: Future foreign policy will rely on rejuvenated 'cyber' sector, UK government claims
2021-03-18 09:30

In terms of "Things that will flow from this" the Integrated Review mentioned only the National Cyber Security Centre and the nascent National Cyber Force, both already in existence. Under the heading "Responsible, democratic cyber power" the government promised to "Use cyber capabilities to influence events in the real world," including more use of "Offensive cyber" - and, eye-catchingly for the UK infosec sector, UK.gov plans to build "An advantage in critical cyber technologies."

With data volumes and velocity multiplying, how do you choose the right data security solution?
2021-03-18 08:35

Finding a data security solution that will fit an organization's needs - current and future - has always been a challenge. Jean Le Bouthillier, CEO of Canadian data security startup Q​ohash​, says that organizations have had many issues with solutions that generate large volumes of not relevant and not actionable data.