Security News

Uber Fined $1.2 Million in EU for Breach Disclosure Delay
2018-11-27 14:48

Credential Stuffing Attack Cracked Uber's Amazon S3 Buckets, Investigators SayUber has been slammed with $1.2 million in fines by U.K. and Dutch privacy regulators for its cover-up of a 2016 data...

Uber Fined $1.2 Million by EU for Breach Disclosure Delay
2018-11-27 12:18

Credential Stuffing Attack Cracked Uber's Amazon S3 Buckets, Investigators SayUber has been slammed with $1.2 million in fines by U.K. and Dutch privacy regulators for its cover-up of a 2016 data...

A Strong Message on Improper PHI Disclosure to News Media
2018-11-26 21:18

HHS Imposes Penalty on Small Clinic and Demands ActionIn at least the fourth federal HIPAA case involving improper disclosure of patient information to the media, federal regulators have slapped a...

Oracle and "Responsible Disclosure"
2018-11-14 12:46

I've been writing about "responsible disclosure" for over a decade; here's an essay from 2007. Basically, it's a tacit agreement between researchers and software vendors. Researchers agree to...

What the Onslow Water and Sewer Authority Can Teach About Responsible Disclosure
2018-11-13 15:40

Critical Infrastructure Operators Must Plan for Scenarios in Which a Physical and Cyber Event Occur Simultaneously read more

Google Criticizes Apple Over Safari Security, Flaw Disclosures
2018-10-08 10:03

One Year After Release, Google Fuzzer Still Finds Many Flaws in Safari One year after it was released as open source by Google Project Zero, the Domato fuzzer has still found a significant number...

Variations in State Data Breach Disclosure Laws Complicate Compliance
2018-09-26 07:11

New data breach notification laws are good news for consumers, better news for attorneys, but not very good news for businesses already struggling to stay on top of a constantly evolving...

The Vulnerability Disclosure Process: Still Broken
2018-09-05 17:03

Despite the advent to bug bounty programs and enlightened vendors, researchers still complain of abuse, threats and lawsuits.

Information Disclosure, DoS Flaws Patched in Apache Tomcat
2018-07-24 04:59

The Apache Software Foundation informed users over the weekend that updates for the Tomcat application server address several vulnerabilities, including issues that can lead to information...

Vulnerability research and responsible disclosure: Advice from an industry veteran
2018-07-23 12:30

“Everything changes once you have to supervise and mentor and schedule and coordinate and keep in mind all the things others don’t. You often have to hold back your own wish to research a certain...