Security News

Hackers Look to Steal COVID-19 Vaccine Research
2020-07-16 18:05

The advanced threat actor known as APT29 has been hard at work attempting to pilfer COVID-19 vaccine research from academic and pharmaceutical research institutions in various countries around the world, including the U.S. That's according to a joint alert from the U.S. Department of Homeland Security, the U.K.'s National Cyber Security Centre and Canada's Communications Security Establishment, issued Thursday. The 14-page advisory details the recent activity of Russia-linked APT29, including the use of custom malware called "WellMess" and "WellMail" for data exfiltration.

UK Says Russian Hackers Trying to Steal Virus Vaccine Research
2020-07-16 14:01

Britain's cyber-security agency on Thursday accused a hacking group it said "Almost certainly" operates as part of Russian intelligence services of trying to steal research into potential coronavirus vaccines. The National Cyber Security Centre said the attacks by the group APT29 were ongoing but targets have so far included UK, US and Canadian vaccine research and development organisations.

IBM Research releases differential privacy library that works with machine learning
2020-06-29 13:20

The library "Boasts a suite of tools for machine learning and data analytics tasks, all with built-in privacy guarantees," according to Naoise Holohan, a research staff member on IBM Research Europe's privacy and security team. Differential privacy allows data collectors to use mathematical noise to anonymize information, and IBM's library is special because it's machine learning functionality enables organizations to publish and share their data with rigorous guarantees on user privacy.

Week in review: The economics of security research, SOC teams battle with burnout
2020-06-28 07:00

SOC team members battle with burnout, overload and chaosWhile some organizations have increased security operations center funding, the overall gains have been meager, and the most significant issues have not only persisted, but worsened, according to Devo Technology. Privacy and security concerns related to patient data in the cloudThe Cloud Security Alliance has released a report examining privacy and security of patient data in the cloud.

Study of global hackers and the economics of security research
2020-06-25 03:30

Remarkably, the report uncovered that 13% of hackers are neurodiverse and possess neurological advantages that help them provide extraordinary depth and dimension in security testing. 6% of neurodiverse hackers experience Attention-Deficit/Hyperactivity Disorder and thrive in environments of rapid change, such as security research, where creativity and out-of-the-box thinking are rewarded generously.

Honda Ransomware Confirms Findings of Industrial Honeypot Research
2020-06-11 12:52

Multistage targeted ransomware attacks against critical infrastructure, designed to maximize damage and recovery costs, are increasingly common. The attack was captured by Cybereason's 2020 honeypot research.

New Research: "Privacy Threats in Intimate Relationships"
2020-06-05 11:13

I just published a new paper with Karen Levy of Cornell: "Privacy Threats in Intimate Relationships." Abstract: This article provides an overview of intimate threats: a class of privacy threats that can arise within our families, romantic partnerships, close friendships, and caregiving relationships.

US Says China Trying to Steal COVID-19 Vaccine Research
2020-05-13 16:06

US authorities warned healthcare and scientific researchers Wednesday that Chinese-backed hackers were attempting to steal research and intellectual property related to treatments and vaccines for COVID-19. "We are leading the world in COVID-19 treatment and vaccine research. It is immoral to target China with rumors and slanders in the absence of any evidence," Zhao said.

Danger zone! Brit research supercomputer ARCHER's login nodes exploited in cyber-attack, admins reset passwords and SSH keys
2020-05-13 15:45

One of Britain's most powerful academic supercomputers has fallen victim to a "Security exploitation" of its login nodes, forcing the rewriting of all user passwords and SSH keys. Sysadmins warned ARCHER users that their SSH keys may have been compromised as a result of the apparent attack, advising them to "Change passwords and SSH keys on any other systems which you share your ARCHER credentials with".

Danger zone! Brit research supercomputer ARCHER hit with SSH-nixing cyber attack
2020-05-13 15:45

One of Britain's most powerful academic supercomputers has fallen victim to a "Security exploitation" of its login nodes, forcing the rewriting of all user passwords and SSH keys. Sysadmins warned ARCHER users that their SSH keys may have been compromised as a result of the apparent attack, advising them to "Change passwords and SSH keys on any other systems which you share your ARCHER credentials with".