Security News

Report: ‘BlueLeaks’ Exposes Sensitive Data From Police Departments
2020-06-22 21:31

Thousands of sensitive police department files - including police and FBI reports - were published on Friday by DDoSecrets, a self-proclaimed "Transparency collective" that publishes covert data. DDoSecrets said on Twitter that it contains ten years of data, from over 200 police departments, law enforcement training and support resources and fusion centers, which are state-owned entities that gather public safety data.

No Wiggle room: Two weeks after angry bike shop customers report mystery orders on their accounts, firm confirms payment cards delinked
2020-06-16 16:00

Brit cycling equipment shop Wiggle confirmed to The Reg today it was delinking customers' payment cards from their accounts, two weeks after first receiving complaints that orders were appearing on customers' accounts that they had not made themselves. Ross Clemmow, CEO at Wiggle, told The Reg: "[W]e understand a small number of customers' login details have been acquired outside of Wiggle's systems and some have been used to gain access to Wiggle accounts and purchases made.

Report: Most companies unaware of third-party IoT security measures
2020-06-12 19:14

Only 37% of "High performer" organizations monitor the risk of IoT devices used by third parties, and current IoT risk-management programs can't keep pace, study said. The report, A New Roadmap for Third Party IoT Risk Management, offered up a chart chronicling the differences between 2017, 2018, 2019, and 2020 in IoT and TPRM, and this year definitely shows an increase.

Dell report details rise in cyberattacks and disruptive events
2020-06-12 18:52

Dell Technologies' Global Data Protection Index 2020 Snapshot takes a closer look at the disruptions plaguing organizations around the globe. "Vulnerabilities, if not addressed, can do lasting damage to a company. Businesses must become more resilient, such as implementing air-gapped solutions that are physically disconnected while protecting their data, as cyber criminals continue to seize new opportunities to cause disruptions," said Nelson Hsu, director of data protection solutions marketing at Dell Technologies.

Report: Working from home is the new normal, but cybersecurity isn't keeping up
2020-06-11 13:00

COVID-19 has completely changed the work world, but many organizations have seemingly failed to realize that security risks are changing as well, a new report finds. The report found that the shift to remote work has been massive: There has been a 39% decrease in companies with less than 25% of their staff working remotely, and a whopping 250% increase in companies with more than three-quarters of their full-time employees working from home.

Cryptomining criminals under the spotlight – a SophosLabs report
2020-06-09 13:59

Sadly unlawful cryptomining is still a thing, and SophosLabs has just published a report that follows the evolution and operation of the cybercrime gang behind a botnet known as Kingminer. Servers have two desirable properties for cryptomining abuse, namely that they're always on, so any unauthorised mining runs 24/7, and they're usually much more powerful than the average laptop, so the crooks can dial in decent earnings without taking over the server so completely that they get noticed.

10 takeaways from Mimecast's 2020 email security report
2020-06-09 09:30

Security vendor Mimecast has released its fourth annual State of Email Security report for 2020. The report is filled with data about email security, but for those looking for action items Mimecast has provided a list of 10 takeaways that point out particular risks and provide IT security decision makers with some avenues to focus on in the coming months.

Have I Been Pwned breach report email pwned entire firm's helldesk ticket system
2020-06-04 17:45

A hapless IT bod found the Have I Been Pwned service answering its own question in a way he really didn't want - after a breach report including a SQL string KO'd his company's helpdesk ticket system. A pseudonymous blogger posting under the name Matt published a tortured account of what happened when a breach notification email from HIBP was ingested into his firm's helpdesk ticket system and was automatically assigned a ticket ID. The company used version 9.4.5 of the GLPi open source helpdesk system, a rather old product but quite functional.

Report: Working from home jeopardizes network security
2020-06-03 12:30

Here's how employees in the US, UK, France and Germany are putting systems at risk, according to CyberArk. As companies have responded to the coronavirus pandemic by shifting employees from the physical workspace to the home office, the remote working environment has greatly expanded-and with this new normal, come some challenges to corporate security. "The security posture of organizations continues to be tested as many remote employees face daunting challenges balancing productivity and security across their professional and personal workspaces," said Marianne Budnik, CMO of CyberArk, in the press release.

Majority of COVID phishing attacks coming from US IP addresses, report finds
2020-05-27 19:23

COVID-19 phishing emails have been bombarding inboxes since the virus began to spread in December and January. Cybersecurity company INKY pored through the months of coronavirus-themed phishing emails and compiled a report on where most of them were coming from, finding that the majority of IP addresses found in email headers originated from the United States.