Security News > 2021

Open banking is the future, so let’s secure the APIs
2021-01-20 08:30

It may be at an early stage, but we can already see that future, as, all over the world, the banking community moves to embrace open banking. Adrian Mountstephens, business development, payments and banking at Equinix, says that in fact the entire digital future of banking is linked to APIs.

Does your cloud stack move faster than your cloud security solutions?
2021-01-20 05:30

Security in cloud environments is a far cry from securing on-premises infrastructure. To utilize Cloud Foundry effectively, DevOps, security, and R&D all have to understand the multi-tenant identity management service UAA, the Cloud Controller for directing the deployment of applications via REST API endpoints, and also the rules and best practices around service deployment.

Hacker posts 1.9 million Pixlr user records for free on forum
2021-01-20 05:05

A hacker has leaked 1.9 million Pixlr user records containing information that could be used to perform targeted phishing and credential stuffing attacks. Pixlr is a very popular and free online photo editing application with many of the same features found in a professional desktop photo editor like Photoshop.

Hacker posts 1.4 million Pixlr user records for free on forum
2021-01-20 05:05

A hacker has leaked 1.9 million Pixlr user records containing information that could be used to perform targeted phishing and credential stuffing attacks. Pixlr is a very popular and free online photo editing application with many of the same features found in a professional desktop photo editor like Photoshop.

Protecting the remote workforce to be enterprises’ prime focus in 2021
2021-01-20 05:00

Protecting the remote workforce will be enterprises' prime focus in 2021, according to a Cato Networks survey of 2,376 IT leaders. As 81% of respondents expect to continue working-from-home, 2021 will see enterprises address those other areas, evolving their remote access architectures to protect the remote workforce without compromising on the user experience.

Companies turning to MSPs as attack vectors get more sophisticated
2021-01-20 04:30

The survey of more than 1,200 business leaders has revealed that education, healthcare, and manufacturing executives all cited a need for increased security as their top reason for selecting an MSP. Security is not the only top driver. "In this ever more challenging landscape, data protection and data recovery are top priorities for MSPs serving clients, especially as attack surfaces expand and attack vectors get more sophisticated," he continued.

Research team develops fast and affordable quantum random number generator
2021-01-20 04:00

An international research team has developed a fast and affordable quantum random number generator. The device created by scientists from NUST MISIS, Russian Quantum Center, University of Oxford, Goldsmiths, University of London and Freie Universität Berlin produces randomness at a rate of 8.05 gigabits per second, which makes it the fastest random number generator of its kind.

SolarWinds Hackers Also Breached Malwarebytes Cybersecurity Firm
2021-01-20 03:27

Malwarebytes on Tuesday said it was breached by the same group who broke into SolarWinds to access some of its internal emails, making it the fourth major cybersecurity vendor to be targeted after FireEye, Microsoft, and CrowdStrike. The company said its intrusion was not the result of a SolarWinds compromise, but rather due to a separate initial access vector that works by "Abusing applications with privileged access to Microsoft Office 365 and Azure environments."

DataLocker releases encrypted USB drive with capacities up to 15.3 TB
2021-01-20 02:00

DataLocker announced the release of an entirely new breed of encrypted USB drive. The DL4 FE changes the game for security professionals by providing bulletproof security and simple remote management in a small-form-factor USB drive with capacities up to 15.3 TB. "The onslaught of attacks by state actors, hackers, and cyber cartels continues. Threat actors are trying to exfiltrate terabytes of data to hold for ransom. Some want access to essential IT systems for later exploitation."

List of DNSpooq vulnerability advisories, patches, and updates
2021-01-20 02:00

Below is a list of DNSPooq/dnsmasq advisories released by different vendors. The CERT Coordination Center is also maintaining a list of advisories shared with them.