Security News

DNA testing firm discloses data breach affecting 2.1 million people
2021-11-30 13:26

An Ohio-based DNA testing company, has disclosed a hacking incident that affects 2,102,436 persons. The incident resulted in a confirmed data breach that occurred between May 24, 2021, and July 28, 2021, but the firm discovered it only on October 29, 2021.

Cisco DNA Center Bug Opens Enterprises to Remote Attack
2021-01-25 17:53

A cross-site request forgery vulnerability in the Cisco Digital Network Architecture Center could open enterprise users to remote attack and takeover. The flaw, tracked as CVE-2021-1257, exists in the web-based management interface of the Cisco DNA Center, which is a centralized network-management and orchestration platform for Cisco DNA. It carries a CVSS vulnerability-severity score of 7.1, making it high-severity.

Cisco Patches Critical Vulnerabilities in SD-WAN, DNA Center, SSMS Products
2021-01-21 14:05

Cisco this week released patches to address a significant number of vulnerabilities across its product portfolio, including several critical flaws in SD-WAN products, DNA Center, and Smart Software Manager Satellite. Several command injection bugs addressed in SD-WAN products could allow an attacker to perform actions as root on the affected devices, the most important of which is rated critical severity, featuring a CVSS score of 9.9.

Friday Squid Blogging: Searching for Giant Squid by Collecting Environmental DNA
2021-01-08 22:02

The idea is to collect and analyze random DNA floating around the ocean, and using that to figure out where the giant squid are. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered.

Theoretical Attack on Synthetic DNA Orders Highlights Need for Better Cyber-Biosecurity
2020-12-01 04:34

Threat actors could target DNA researchers with malware in an effort to modify synthetic DNA orders and create pathogens or toxins, researchers warn. In a newly published article in Nature, a group of academic researchers from Israel's Interdisciplinary Center Herzliya and Ben-Gurion University of the Negev detail a cyberattack that exploits gaps within the security of the DNA procurement process for malicious purposes.

Website Security Breach Exposes 1 Million DNA Profiles
2020-07-24 11:25

A genealogy website used to catch one of California's most wanted serial killers remained shut down Thursday after a security breach exposed the DNA profiles of more than a million people to law enforcement agencies. GEDmatch said in a message emailed to members and posted Wednesday on its Facebook page that on Sunday a "Sophisticated attack" on their servers through an existing user account made the DNA profiles of its members available for police to search for about three hours.

Friday Squid Blogging: More on the Giant Squid's DNA
2020-01-24 22:18

In rather more ways than many readers hea suspect, most security problems happen due to people not noticing or disregarding information in the form of observations. Remember an attacker will almost always select your weaknesses to their advantage and "Pinning you down" is a very standard millitary tactic to gain significant advantage over much greater numbers.

Warrant let police search online DNA database
2019-11-07 12:02

This is a "game changer" when it comes to genetic privacy rights, experts say.

U.S. to Collect DNA of All Undocumented Migrants
2019-10-03 01:23

The US government plans to collect the DNA of all migrants detained after entering the country illegally, officials said Wednesday. read more

Relatives’ DNA in geneology database leads to murder conviction
2019-07-02 09:39

Privacy advocates may question the use of genealogy data in forensics, but defense attorneys in this case did not.