Infosecurity News

Firefox Bug Goes Unfixed for Nine Years
Software developer discovers flaw in Firefox and Thunderbird’s password manager

Cambridge Analytica Under Fire for Data Harvesting
Data analytics firm accused of harvesting millions of Facebook profiles of US voters

Researchers Discover Security Issue on Chrome RDP
Bug discovered that allows a guest user full access to an administer’s machine using Chrome Remote Desktop

GandCrab Ransomware Finds a New Shell
This well-known malware has gotten around a free decryption tool meant to dull its claws by building a new version in just days.

Walmart Jewelry Partner Exposes Millions in Latest Cloud Storage Misconfig
MBM/Limogés Jewelry exposed data that can be used to carry out targeted fraud or phishing attempts.

DHS, FBI Warn on Russian State Actors Targeting Critical Infrastructure
The US is warning that Russian state-sponsored cyber-attackers are targeting critical infrastructure – including nuclear sites.

Vulnerability Discovered in MikroTik RouterOS
Software sold across the globe found to have vulnerability by security researchers

Cybercrime Profits: Up to $200Bn Laundered Each Year
Cybercriminals turning to virtual currencies, video game currency and digital payment systems like PayPal to convert illegal revenue into clean cash

Sofacy Targets Government Agency with New Spear-Phishing Campaign
Espionage group with ties to Russia targets European government organization with updated phishing techniques

US Treasury Department Sanctions Russians Over NotPetya, Election Meddling
The NotPetya campaign, it noted, was the “most destructive and costly cyber-attack in history."

WhatsApp Agrees to Stop Sharing User Data with Facebook
After a ban from the ICO, WhatsApp will no longer share personal data until the GDPR rules can be met.

Minority Cyber-Pros Are Better Educated but Paid Less
Minority representation is higher than in the broader workforce, but these pros are disproportionately found in non-management roles.

Cybersecurity Incident Response Still Major Issue
Half of incident response plans are either informal, ad-hoc or completely non-existent

Rush to the Cloud Risks Security Breaches
Companies across Europe feel the pressure to move to the cloud, but neglect cybersecurity

Google Moves to Ban Ads for Bitcoin, Cryptocurrency
The ban follows a similar no-quarter approach taken by Facebook earlier this year.

Playboy Develops Virtual Currency Wallet
Online visitors will be able to pay and earn tokens to view Playboy.TV’s original content.

BlackTDS Emerges as an As-a-Service Drive-By Kit for Malware Distribution
BlackTDS hosts components for sophisticated drive-by attacks, like social engineering and redirection to exploit kits.

Euro Firms Lagging on AWS CloudTrail Adoption
Missed opportunity to use native security and compliance tools, says Sumo Logic

Fortnite Gamers Warned Over Account Hacking
Players apparently faced with large credit card charges from fraudulent purchases

Microsoft Releases More Spectre/Meltdown Patches
Patch Tuesday covers over 70 vulnerabilities this month



