Infosecurity News

Attacks Exploiting Digital Certs Soar by 700% in Five Years
Venafi claims the enterprise attack surface is rapidly expanding

Sopra Steria Hit by New Ryuk Variant
IT services giant will take “weeks” to return to normal

Nando’s Customers Hit by Credential Stuffing Attacks
Account hijackers run up large bills with in-store orders

US Army Base's Twitter Account Hacked
Army says suggestive tweets sent from Fort Bragg account were posted by a hacker

Systems Admin Arrested for Hacking Former Employer
Systems admin allegedly hacked US department store to give former colleagues paid holidays

Judge Signs Off on $7.75m Equifax Settlement
$7.75m Equifax settlement with financial institutions over 2017 data breach ratified by judge

#SecTorCa: How One Malicious Message Could Exploit an Enterprise
Researcher reveals true depth of flaw in Microsoft Teams that was patched earlier this year

#SecTorCa: Tech for Good, and Bad
All technology comes with both promises and un-intended consequences

#SecTorCa: The Paramedic’s Guide to Surviving Cybersecurity
In both emergency services and cybersecurity, professionals deal with some of the same challenges

US and UK Issue Sanctions to Iran and Russia
UK/EU issue sanctions over cyber-attack, while US points finger at Iran over fake news campaign

Infected IoT Device Numbers Surge 100% in a Year
Nokia data reveals almost a third of devices are now compromised

#SecTorCa: Defining the Security Metrics that Matter
Some metrics are more valuable than others in making measurable improvement in security

Researcher Guesses Password to Access Trump Twitter Account
Two-factor authentication belatedly switched on after incident

#COVID19 Vaccine-Maker Shuts Global Plants After Cyber-Attack
Dr Reddy’s had just been granted permission to start trials

#SecTorCa: A Hacker’s Perspective on Your Infrastructure
At the SecTor virtual security conference, pen tester outlines the security issues that give hackers easy access to attack users

Oregon Retailer Suffers Sustained Data Breach
Data breach at Made in Oregon goes unnoticed for six months

Attackers Spoof Microsoft Teams
Cyber-criminals impersonate Microsoft Teams to phish for employees’ credentials

#InfosecurityOnline: Adapting Security Strategies to Growing Digitalization
Security practices need to keep up-to-date with increasing digitalization

Fraud Analysts Miss Dark Web Data
Nearly half of fraud analysts investigating financial crimes are not able to follow leads into the dark web

#InfosecurityOnline: Tactics for Defending Against Credential Stuffing
How to spot and defeat credential stuffing attacks using bot detection and network visibility



