Security News

UK Fines British Airways for Failures in 2018 Data Hack
2020-10-16 12:57

Britain's information commissioner has fined British Airways 20 million pounds for failing to protect personal data for some 400,000 customers, the largest fine the agency has ever issued. The ICO said in a statement Friday that the airline was processing personal data without adequate security measures.

One alleged Dridex money-launderer set for US extradition, beams UK's National Crime Agency
2020-10-15 19:28

Britain's National Crime Agency arrested six men in London on suspicion of laundering "Tens of millions" for the Trickbot and Dridex banking malware gangs, the not-quite-police agency declared today. The six, a mixture of British and Eastern European citizens, were arrested around a year ago, said the NCA as EU police agency Europol jointly boasted of a further 14 arrests in the political bloc, the US and Australia.

Minerva Elite Performance joins (ISC)² Official Training Provider programme for the UK
2020-10-15 00:00

announced that Minerva Elite Performance has joined its Official Training Provider programme for the UK, expanding the range of leading training organizations delivering official² certification preparation training to cybersecurity professionals in the region. As the latest² Official Training Provider in the UK, Minerva Elite Performance will deliver certification exam preparation courses taught by authorised and accredited trainers, using official² training materials and setting up students with all the resources they need to prepare for their exam and complete their journey to certification.

Hackers hack Hackney: Local government cries 'cyberattack' while UK infosec officials rush to figure out what happened
2020-10-13 12:32

Hackney Council in East London has declared that it was hit by a "Cyberattack" - but both the authority and officials from the National Cyber Security Centre remain tight-lipped about what actually happened. In a statement published on the council website this morning, local mayor Philip Glanville said: "Hackney Council has been the target of a serious cyberattack, which is affecting many of our services and IT systems."

Email-spamming COVID profiteers deleted database with 'key evidence' when UK watchdog came knocking
2020-10-09 08:30

"The ICO investigation found that the company was not involved in the business of supplying PPE, but that the director had decided to buy face masks to sell on at a profit," the data regulator said in a statement. The firm is also said to have "Deleted a database of key evidence which would have shown the full extent of the volume of emails they had sent" after ICO investigators contacted the company.

UK, French, Belgian blanket spying systems ruled illegal by Europe’s top court
2020-10-07 06:54

Mass surveillance programs run by the UK, French and Belgian governments are illegal, Europe's top court has decided in a huge win for privacy advocates. The European Court of Justice announced on Tuesday that legislation passed by all three countries that allows the government to demand traffic and location data from internet and mobile providers in "a general or indiscriminate way" breaks EU data privacy laws - even when national security concerns are invoked.

Russia and China's 'digital authoritarianism' means we need to better arm our cyber troops, warns top UK general
2020-10-02 09:15

Britain's enemies are investing more and more in cyber warfare capabilities, the UK's top general has warned - singling out Russia and its "Digital authoritarianism". "China's new Strategic Support Force is designed to achieve dominance in the space and cyber domains," said the professional head of the armed forces.

Huawei's UK code reviewers say Chinese mega-corp is still totally crap at basic software security. Bad crypto, buffer overflows, logic errors...
2020-10-01 13:00

The Huawei Cyber Security Evaluation Centre - mostly run by GCHQ offshoot the National Cyber Security Centre, though it is also staffed by some Huawei personnel - sighed that the Chinese company has made "Limited" progress on last year's recommendations to toughen up its act. Code reviewers found "Evidence that Huawei continues to fail to follow its own internal secure coding guidelines. This is despite some minor improvements over previous years." In addition, "The Cell" said it had found more vulnerabilities during 2019 than it had in previous years - though Huawei was keen to paint this finding as "Proof the review system is working", something NCSC guardedly agreed with.

Huawei's UK code reviewers say the company is still crap at basic software security
2020-10-01 13:00

The Huawei Cyber Security Evaluation Centre - mostly run by GCHQ offshoot the National Cyber Security Centre, though it is also staffed by some Huawei personnel - sighed that the Chinese company has made "Limited" progress on last year's recommendations to toughen up its act. Code reviewers found "Evidence that Huawei continues to fail to follow its own internal secure coding guidelines. This is despite some minor improvements over previous years." In addition, "The Cell" said it had found more vulnerabilities during 2019 than it had in previous years - though Huawei was keen to paint this finding as "Proof the review system is working", something NCSC guardedly agreed with.

UK privacy watchdog confirms probe into NHS England COVID-19 app after complaints of spammy emails, texts
2020-10-01 09:05

Britain's Information Commissioner's Office has confirmed it is investigating grumbles about heavy-handed marketing emails and texts promoting the NHS COVID-19 contact-tracing app in England. Between 26 and 27 September, NHS Test and Trace messaged anyone resident in the country who was over the age of 16 and had previously provided their contact details to a GP. Those contacted had not specifically opted in to receive marketing communications regarding the NHS COVID-19 app.