Security News

Equilend warns employees their data was stolen by ransomware gang
2024-03-11 18:00

New York-based securities lending platform EquiLend Holdings confirmed in data breach notification letters sent to employees that their data was stolen in a January ransomware attack. Days later, Equilend said that all client-facing services were back online and had yet to find evidence that "Client transaction data was accessed or exfiltrated" during the cyberattack.

Over 15,000 hacked Roku accounts sold for 50¢ each to buy hardware
2024-03-11 17:49

Roku has disclosed a data breach impacting over 15,000 customers after hacked accounts were used to make fraudulent purchases of hardware and streaming subscriptions. On Friday, Roku first disclosed the data breach, warning that 15,363 customer accounts were hacked in a credential stuffing attack.

OneLogin vs. Okta (2024): Which IAM Solution Is Better?
2024-03-11 17:09

OneLogin and Okta are enterprise-grade IAM platforms offering security products that customers can mix-and-match to create a customized solution. Feature comparison: OneLogin vs. Okta Single Sign-On. Both OneLogin and Okta offer SSO for on-premises and cloud-based applications, as well as endpoint devices like laptops and mobile phones.

Fake Leather wallet app on Apple App Store is a crypto drainer
2024-03-11 14:54

The developers of the Leather cryptocurrency wallet are warning of a fake app on the Apple App Store, with users reporting it is a wallet drainer that stole their digital assets. Last week, the genuine Leather wallet warned its community about a fake version of its wallet on the Apple App Store, making it clear that the company does not yet offer an iOS app.

New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics
2024-03-11 14:47

Users in Brazil are the target of a new banking trojan known as CHAVECLOAK that's propagated via phishing emails bearing PDF attachments. "This intricate attack involves the PDF downloading a ZIP...

British Library pushes the cloud button, says legacy IT estate cause of hefty rebuild
2024-03-11 13:30

The British Library says legacy IT is the overwhelming factor delaying efforts to recover from the Rhysida ransomware attack in late 2023. Rhysida broke into the British Library in October last year, making off with 600GB worth of data and, crucially, destroying many of its servers which are now in the process of being replaced.

Microsoft: Russian hackers accessed internal systems, code repositories
2024-03-11 12:00

Midnight Blizzard, a group of Russian hackers tied to the country's Foreign Intelligence Service, has leveraged information stolen from Microsoft corporate email systems to burrow into the company's source code repositories and internal systems."It is apparent that Midnight Blizzard is attempting to use secrets of different types it has found. Some of these secrets were shared between customers and Microsoft in email, and as we discover them in our exfiltrated email, we have been and are reaching out to these customers to assist them in taking mitigating measures," the company's Security Response Center shared on Friday.

Guide: On-Prem is Dead. Have You Adjusted Your Web DLP Plan?
2024-03-11 11:33

As the shift of IT infrastructure to cloud-based solutions celebrates its 10-year anniversary, it becomes clear that traditional on-premises approaches to data security are becoming obsolete....

How do you lot feel about Pay or say OK to ads model, asks ICO
2024-03-11 11:16

The UK's Information Commissioner's Office has opened a consultation on "Consent or pay" business models. While the ICO studiously avoided naming any companies or organizations in particular, one of the most famous examples of the practice comes from Meta, which asked EU subscribers to choose between either paying to lose ads and allow data processing for advertising.

Using LLMs to Unredact Text
2024-03-11 11:01

About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.