Security News

Week in review: Most used MITRE ATT&CK tactics, boosting the “Sec” in DevSecOps
2021-02-21 08:55

Phishers tricking users via fake LinkedIn Private Shared DocumentPhishers are trying to trick users into opening a "LinkedIn Private Shared Document" and entering their login credentials into a fake LinkedIn login page, security researcher JB Bowers warns. Apple details major security, privacy enhancements in its devicesApple has released on Thursday a newer version of its Platform Security Guide, outlining the security and privacy innovations and improvements its users will be able to take advantage of.

Tips for boosting the “Sec” part of DevSecOps
2021-02-17 08:31

"In my experience, this is due to the 'I'm from Security and I'm here to save you' mentality that continues to pervade the security industry, and the only way to overcome this is with a big bucket of humility," he noted. "Security has not actually spent the last 20 years doing a good job of 'security things' and we do not have a strong position to say that we have all of the answers. I know that it sounds relatively simplistic, but it really is a case of taking the path of the beginner's mind and working with developers, operators, and DevOps staff to learn their perspective and then apply domain-specific security knowledge."

US Offers $2mn Bounty for Ukrainian SEC Hackers
2020-07-22 15:01

The US State Department and Secret Service offered $2 million in reward money Wednesday for help capturing two Ukrainians charged with hacking and selling valuable insider corporate information from the Securities and Exchange Commission. The agencies offered a bounty of $1 million each for information leading to the arrest and/or conviction of Artem Viacheslavovich Radchenko and Oleksandr Vitalyevich Ieremenko on charges of international cybercrime.

SEC Settles With Two Traders Charged in EDGAR Hacking Case
2020-04-13 10:53

The United States Securities and Exchange Commission last week announced that it reached a settlement with two of the traders charged last year over their roles in a scheme that involved hacking the organization's EDGAR electronic filing system. The SEC revealed in September 2017 that a breach of its EDGAR system detected in 2016 had allowed hackers to obtain non-public information that was used by some traders to make a profit.

SEC Shares Cybersecurity and Resiliency Observations
2020-01-30 20:09

The U.S. Securities and Exchange Commission (SEC) has published a report detailing cybersecurity and operational resiliency practices that market participants have adopted.

SEC Consult Open Sources Hardware Analysis Tool
2019-12-04 17:58

Austria-based IT security services and consulting company SEC Consult on Wednesday announced the release as open source of its SEC Xtractor assisted hardware analysis tool. read more

US insurers face SEC probe over web-access bungle that exposed 'up to 885 million' files
2019-08-13 11:57

But it claims just 32 people had 'non-public' info disclosed. Eh? The American Securities and Exchange Commission is said to be investigating a US insurance company that allegedly left 885 million...

Report: SEC Investigates First American Data Exposure
2019-08-13 10:48

Title and Settlement Company Exposed Hundreds of Millions of Data RecordsThe U.S. Securities and Exchange Commission is investigating the exposure of personal and mortgage-related records from...

SEC Investigating Data Leak at First American Financial Corp.
2019-08-12 20:30

The U.S. Securities and Exchange Commission (SEC) is investigating a security failure on the Web site of real estate title insurance giant First American Financial Corp. that exposed more than 885...

New UK Home Sec invokes infosec nerd rage by calling for end to end-to-end encryption
2019-07-31 14:28

Yep, Patel continues age-old tradition. Plus: Five Eyes word games Newly assigned UK Home Secretary Priti Patel has declared war on encryption safeguards, demanding they be torn up for the...