Infosecurity News

Government Payment Service Exposes 14m Records
Names, addresses, phone numbers and card digits could be accessed

FBI Warns Parents of Edtech Security Risk
Data-collection tools could be a target for hackers

Altaba Announces Class Action Settlement of $47m
Plaintiffs and defendants in the Yahoo suit reach a settlement agreement.

Bill for Financial Services Breach Notification Passed
The US Congress approved a national standard on data breach notifications in financial sector, and states are not happy.

Campaign Targets Nonresidents with Fake IRS Email
A new phishing campaign uses the subject line “2018 UPDATE: NON RESIDENT ALIEN TAX WITHHOLDING,” says Fortinet.

North Korea: US Indictment is Vicious Smear
Alleged hacker is “non-entity,” says Pyongyang

Bristol Airport Hit by Ransomware Blackout
Staff forced to hand-write flight information on white boards

UK Universities Face Growing DDoS Threat
Students blamed for many attacks

Microsoft Office Macros Still No. 1 Malware Delivery
Phishing attacks remain successful by leveraging macros.

Senators Bash State Department on Cybersecurity
Lawmakers are critical of the State Department for failure to meet basic cybersecurity standards.

Cloud-Native Attacks Executed Against Known CVEs
A new survey finds nearly all attacks automatically executed are against outdated code.

#44CON: In a Time of Genuine Threats, Talk Sensibly & Act Efficiently
Let’s change the way we talk about security, as global news and incidents are creating new threats

Magecart Back Again as Feedify is Hit
Malicious script injected into supplier’s JavaScript library

ICO Swamped with GDPR Breach Over-Reporting
UK regulator receives 500 calls a week as firms play it safe

NCSC: Time for Boards to Get Cyber Literate
Simply buying in expertise will not help boards manage risk, says Martin

#RockYourSOC Spotlight on Insider Threat
The keys to a successful insider threat program are people, process and technology.

Bomgar to Acquire BeyondTrust
A new acquisition aims to enhance security with BeyondTrust’s privileged access management platform.

European Court Rules Against UK Mass Surveillance
Lack of independent oversight means old regime breaks the law

Veeam Manages to Expose Data in MongoDB Snafu
Leak makes 445 million records publicly available for days

Edinburgh Uni Hit by Major Cyber-Attack
Main website still out of action



