Security News

SolarWinds Attackers Accessed DHS Emails, Report
2021-03-30 16:54

The SolarWinds cyberattackers compromised the head of the Department of Homeland Security under former president Trump and other top-ranking members of the department's cybersecurity staff, according to a report. With Sunburst embedded, the attackers were then able to pick and choose which organizations to further penetrate, in a massive cyberespionage campaign that has hit nine U.S. government agencies, tech companies like Microsoft and 100 others hard.

Report finds requiring customers to use passwords is bad for business
2021-03-30 10:00

While it will not come as shock to anyone, a new report finds that people still hate passwords. That's the conclusion of the Impact of Passwords on Your Business report from Transmit Security, an identity management company.

'Russian Hackers' Again Target German MPs: Report
2021-03-26 20:19

Several German lawmakers have once again fallen victim to a cyber attack, local media said Friday, with security experts pointing the finger at Russian hackers. Hackers used phishing emails to gain access to the computers of at least seven federal MPs and 31 lawmakers in regional parliaments, according to Der Spiegel weekly.

Report: US Gov Executive Order to Mandate Data Breach Disclosure
2021-03-26 16:54

A proposed executive order would set new rules on the disclosure of data breaches that also affect United States government agencies, according to a Reuters news report. The report said the executive order, which could be released as soon as the next week, would require software vendors to notify U.S. government customers of cyber-security breaches that also affect them.

Report: 40% of SaaS application users have lost data
2021-03-25 19:34

Forty percent of people have lost data stored in their online tools, according to the findings from a recent survey of Software-as-a-Service users across a mix of industries by cloud backup provider Rewind. The company is encouraging businesses of all sizes to assess their current cloud data protection initiatives and have comprehensive backups in place for primary business applications ahead of World Backup Day on March 31.

Engineer reports data leak to nonprofit, hears from the police
2021-03-25 08:35

A security engineer and ex-contributor to an open systems non-profit organization recently reported a data leak to the organization. On discovering this GitHub repository which, the engineer says, was public since at least 2019, the engineer privately reported it to Apperta, and got thanked by them.

Engineer reports data leak to Apperta, hears from the police
2021-03-25 08:35

A security engineer and ex-contributor to an open systems non-profit organization recently reported a data leak to the organization. On discovering this GitHub repository which, the engineer says, was public since at least 2019, the engineer privately reported it to Apperta, and got thanked by them.

REvil ransomware says they hit Acer, Acer reports "abnormal situations"
2021-03-19 15:11

Computer giant Acer has been hit by a REvil ransomware attack where the threat actors are demanding the largest known ransom to date, $50,000,000. Yesterday, the ransomware gang announced on their data leak site that they had breached Acer and shared some images of allegedly stolen files as proof.

REvil ransmoware says they hit Acer, Acer reports "abnormal situations"
2021-03-19 15:11

Computer giant Acer has been hit by a REvil ransomware attack where the threat actors are demanding the largest known ransom to date, $50,000,000. Yesterday, the ransomware gang announced on their data leak site that they had breached Acer and shared some images of allegedly stolen files as proof.

Ripoff Report Hacker Gets 12 Months in Prison
2021-03-18 10:44

The United States Department of Justice on Wednesday announced that a Cypriot national who admitted to hacking the websites of various U.S.-based companies was sentenced to 12 months and one day in prison, on top of the four years already served in custody. In January 2021, Epifaniou admitted in court to perpetrating a scheme in which he hacked the websites of multiple companies, exfiltrated data of interest, and then contacted the victim organizations to demand a ransom payment, threatening to make the data public.