Security News

Indian stock exchange finally encrypting all messages to traders
2024-05-30 05:36

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Intercontinental Exchange to pay $10M SEC penalty over VPN breach
2024-05-22 17:20

The Intercontinental Exchange will pay a $10 million penalty to settle charges brought by the U.S. Securities and Exchange Commission after failing to ensure its subsidiaries promptly reported an April 2021 VPN security breach. ICE is an American company listed on the Fortune 500 that owns and operates financial exchanges and clearing houses worldwide, including the New York Stock Exchange.

MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks
2024-05-22 07:41

An unknown threat actor is exploiting known security flaws in Microsoft Exchange Server to deploy a keylogger malware in attacks targeting entities in Africa and the Middle East. Russian...

Russian Operator of BTC-e Crypto Exchange Pleads Guilty to Money Laundering
2024-05-07 09:32

A Russian operator of a now-dismantled BTC-e cryptocurrency exchange has pleaded guilty to money laundering charges from 2011 to 2017. Alexander Vinnik, 44, was charged in January 2017 and taken...

Microsoft releases Exchange hotfixes for security update issues
2024-04-23 19:50

Microsoft has released hotfix updates to address multiple known issues impacting Exchange servers after installing the March 2024 security updates.Although the April 2024 HU is optional, it also adds support for ECC certificates and Hybrid Modern Authentication for OWA/ECP. If you have installed the March 2024 SU and have not experienced any known issues fixed in the optional update and do not need the new features, you can wait for the next Exchange Server SU, which will also include these hotfixes.

Microsoft will limit Exchange Online bulk emails to fight spam
2024-04-15 19:11

Microsoft has announced plans to fight spam by imposing a daily Exchange Online bulk email limit of 2,000 external recipients starting January 2025.Exchange Online doesn't support sending bulk or high volumes of emails from a single account, and until now, Microsoft has not placed any restrictions on bulk emails.

Ex-Security Engineer Jailed 3 Years for $12.3 Million Crypto Exchange Thefts
2024-04-13 14:25

A former security engineer has been sentenced to three years in prison in the U.S. for charges relating to hacking two decentralized cryptocurrency exchanges in July 2022 and stealing over $12.3...

Ex-Amazon engineer gets 3 years for hacking crypto exchanges
2024-04-12 17:54

Former Amazon security engineer Shakeeb Ahmed was sentenced to three years in prison for hacking two cryptocurrency exchanges in July 2022 and stealing over $12 million. The breached entities are Nirvana Finance, a decentralized crypto exchange, and an unnamed exchange on the Solana blockchain platform that Ahmed hacked using his smart contract reverse engineering and blockchain audit skills.

US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack
2024-04-09 13:56

US Cyber Safety Review Board released a report on the summer 2023 hack of Microsoft Exchange by China. The Board finds that this intrusion was preventable and should never have occurred.

Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack
2024-04-04 00:21

The U.S. Department of Homeland Security's Cyber Safety Review Board has released a scathing report on how Microsoft handled its 2023 Exchange Online attack, warning that the company needs to do better at securing data and be more truthful about how threat actors stole an Azure signing key. Almost 10 months after Microsoft started the investigation, the CSRB states there isn't any definitive evidence on how the threat actor obtained the signing key, regardless of what Microsoft previously claimed.