Infosecurity News

Cisco Protocol Abused by Nation State Hackers
Over 160,000 systems remain vulnerable, says Talos

Raróg Crypto-Miner Allows Affordable Criminality
It mines unsuspecting victim machines for Monero and other virtual currencies, but its most unusual characteristic is how cheap it is.

One-Fifth of Open-Source Serverless Apps Have Critical Vulnerabilities
According to PureSec's audit, most vulnerabilities and weaknesses were caused by human error.

Sears/Delta Card Breach Widens to Include Best Buy
The culprit is a cybersecurity breach at third-party software provider, [24]7.ai, which provides online automated chat.

Echoes of Mirai: New IoT Botnet Targets Financial Firms
Recorded Future warns of likely IoTroop activity in January

Hospitals Exposed by Connected Devices
Trend Micro warns of growing attack surface and supply chain risk

Breached Records Fall 25% as Cloud Misconfigurations Soar
Cyber-criminals focused on ransomware in 2017, says IBM

Sears, Kmart and Delta Hit with Payment-Card Breach
The breach was at a third-party firm that provides online customer support services to all three companies.

Rampant Misconfigurations Expose 1.5 Billion Sensitive Corporate Files
The volume of exposed data in the study totaled 12 petabytes, 4,000 times the size of the Panama Papers leak.

100% of Web Apps Contain Vulnerabilities
All apps tested by Trustwave displayed at least 1 vulnerability, with 11 as the median number detected per application.

Intel Halts Spectre Patching for Some Chips
Chip giant to focus on newer models, as research highlights growing update challenges

Pyongyang Hackers Could be Major Future Threat: Parliament
China pegged for supporting North Korea hacking efforts
Cambridge Analytica Scandal: Facebook Says 87m Users Affected
Social network on charm offensive with new privacy features

Half of Cyber-Pros Believe They're Losing the Fight
They believe that in the next year they will struggle to deal with cyber-threats or be unable to defend against them.

2.7 Million UK Businesses Wide Open to IoT Hacks
Half of UK businesses don't update default passwords on IoT devices when they are added to corporate networks.

DHS Detects Cell-Phone Spy Gear in DC
The Department of Homeland Security doesn’t know who’s behind the eavesdropping equipment.

EMEA Attack Dwell Time Hits 175 Days
FireEye report reveals worrying trend

Flexera: 20,000 New Software Flaws Found in 2017
Intelligence and processes must improve, warns vendor

US Gas Pipelines Hit by Cyber-Attack
Third-party provider is targeted as firms scramble for workarounds

Americans Resigned to ID Theft, But Taking Steps
Many Americans are taking steps to change their behavior in order to be more protected.



