Security News

Experts urge EU not to force insecure certificates in web browsers
2022-03-04 20:00

The particular provision requires web browsers like Chrome, Safari, and Firefox to accept QWACs, which practically compels browser developers and security advocates to ease their security stance. TLS certificates are vital for the online exchange of sensitive information with websites such as passwords, sensitive uploads, or payment details.

EU, US close to replacing defunct Privacy Shield II
2022-03-02 16:40

What is Schrems II? Schrems, a former law student, brought the latest edition of the long-running case in 2015, complaining that Ireland's data protection agency still wasn't preventing Facebook Ireland Ltd from beaming his data to the US under Privacy Shield. In July 2020, the EU Court of Justice struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US, triggering a fresh wave of legal confusion over the transfer of EU subjects' data to America.

ENISA and CERT-EU publish set of cybersecurity best practices for public and private organizations
2022-02-21 05:00

Ransomware remains a prime threat, putting millions of organizations at risk. An analysis of the rise in major threats is made available in the Agency's 2021 Annual Threat Landscape report.

EU Data Protection Watchdog Calls for Ban on Pegasus-like Commercial Spyware
2022-02-16 00:55

The European Union's data protection authority on Tuesday called for a ban on the development and the use of Pegasus-like commercial spyware in the region, calling out the technology's "Unprecedented level of intrusiveness" that could endanger users' right to privacy. "Pegasus constitutes a paradigm shift in terms of access to private communications and devices, which is able to affect the very essence of our fundamental rights, in particular the right to privacy," the European Data Protection Supervisor said in its preliminary remarks.

Privacy Shield: EU citizens might get right to challenge US access to their data
2022-02-03 21:34

Officials from the EU and US are nearing a solution in long-running negotiations over transatlantic data sharing. Previous legal arrangements for sharing data between the two jurisdictions, the so-called Privacy Shield, were struck down by the EU Court of Justice in what became known as the Schrems II ruling in 2020.

Week in review: PolKit vulnerability, fake tax apps pushing malware, EU’s bug bounty for open source
2022-01-30 09:00

PolKit vulnerability can give attackers root on many Linux distrosA memory corruption vulnerability in PolKit, a component used in major Linux distributions and some Unix-like operating systems, can be easily exploited by local unprivileged users to gain full root privileges. Attackers connect rogue devices to organizations' network with stolen Office 365 credentialsAttackers are trying out a new technique to widen the reach of their phishing campaigns: by using stolen Office 365 credentials, they try to connect rogue Windows devices to the victim organizations' network by registering it with their Azure AD. Stealthy Excel malware putting organizations in crosshairs of ransomware gangsThe HP Wolf Security threat research team identified a wave of attacks utilizing Excel add-in files to spread malware, helping attackers to gain access to targets, and exposing businesses and individuals to data theft and destructive ransomware attacks.

EU to create pan-European cyber incident coordination framework
2022-01-28 15:00

The European Systemic Risk Board proposed a new systemic cyber incident coordination framework that would allow EU relevant authorities to coordinate better when responding to major cross-border cyber incidents impacting the Union's financial sector. ESRB is an independent EU body established in 2010 that oversees the European Union's financial system to prevent and mitigate systemic risk.

EU launches bug bounty programs for five open source solutions
2022-01-25 10:55

The European Union is, once again, calling on bug hunters to delve into specific open source software and report bugs."One criteria in selecting bug bounties was their use within European public services," the European Commission Open Source Programme Office explained.

EU data watchdog to Europol: You've helped yourself to too much data
2022-01-11 11:47

The European Data Protection Supervisor has ordered European Union law enforcement agency Europol to delete any data it has on individuals that's over six months old, provided there's no link to criminal activity. The investigation concluded the law enforcement agency needed to up its game when it came to data minimisation and retention and encouraged Europol to make necessary changes and then let the EDPS know of its action plan.

EU Parliament adopts Digital Services Act, but concerns persist
2021-12-14 16:51

The European Parliament's Internal Market and Consumer Protection Committee has adopted the Digital Services Act proposal by 36 votes to 7 and 2 abstentions. The main goal of the DSA is to empower EU regulators to control large internet platforms and impose stricter mechanisms for removing "Fake news" and "Abusive content."