Infosecurity News

KnowBe4 Gets Whopping $300m in Funding
Dubbed a cybersecurity unicorn, KnowBe4's valuation soars to $1bn.

Philly Courts Still Down After Cyber-Attack
Some Philadelphia Court systems are still down three weeks post-attack

Flaw in SymCrypt Can Trigger DDoS
A Google researcher reported a Windows vulnerability as part of Project Zero.

XSS is Most Rewarding Bug Bounty as CSRF is Revived
XSS is the most rewarding security vulnerability, according to data on the number of bug bounties paid

Microsoft Fixes Four SandboxEscaper Zero-Days
Patch Tuesday sees updates for 88 flaws

FBI: Don’t Trust HTTPS or Padlock on Websites
Feds warn that hackers are increasingly using certs to ‘secure’ their phishing sites

Code Signing Shortcomings Leave Gaps for Hackers
Venafi research finds just 14% of European firms have security in place

Radiohead Officially Releases Music Stolen in Hack
Rather than pay the $150K ransom, Radiohead has made the stolen tracks available to fans.

SOCs Struggle with Staffing, Reporting and Visibility
Alert overload and false positives remain a problem in the SOC.

HaveIBeenPwned.com Open to Acquisition
Maintaining the site at its level of growth has become overwhelming for Troy Hunt.

FTSE 250+ Demonstrate Weak Security, But Low SMB Exposure
FTSE 250+ organizations leave an average of 35 servers and devices exposed

Welsh Man Gets Four Years for TalkTalk Attack
Asperger’s syndrome sufferer sentenced to young offender institute

US Customs Contractor Hack Breaches Traveller Images
Data on tens of thousands is reportedly stolen

Chinese Uni Exposes 8TB+ of Email Metadata
Misconfigured Elasticsearch database again to blame

Criminals Try to Schedule Spam in Google Calendar
Spammers using Google services, including Calendar, Photos and Forms.

Data of 1m Users Lost in EmuParadise Breach
Community members learn of breach from haveibeenpwned.com notice.

Vectra Raises $100m in Series E Funding
Total funding surpasses $200 million.

UK Taxpayers Overwhelmed with Phishing Scams
FOI request reveals 2.6m reports over past three years

Microsoft Warns of Campaign Exploiting 2017 Bug
Phishing emails contain malicious RTF files

GoldBrute Campaign Brute Forces 1.6m RDP Servers
Researchers warn of new automated password-cracking threat



