Infosecurity News

Walmart Jewelry Partner Exposes Millions in Latest Cloud Storage Misconfig
MBM/Limogés Jewelry exposed data that can be used to carry out targeted fraud or phishing attempts.

DHS, FBI Warn on Russian State Actors Targeting Critical Infrastructure
The US is warning that Russian state-sponsored cyber-attackers are targeting critical infrastructure – including nuclear sites.

Vulnerability Discovered in MikroTik RouterOS
Software sold across the globe found to have vulnerability by security researchers

Cybercrime Profits: Up to $200Bn Laundered Each Year
Cybercriminals turning to virtual currencies, video game currency and digital payment systems like PayPal to convert illegal revenue into clean cash

Sofacy Targets Government Agency with New Spear-Phishing Campaign
Espionage group with ties to Russia targets European government organization with updated phishing techniques

US Treasury Department Sanctions Russians Over NotPetya, Election Meddling
The NotPetya campaign, it noted, was the “most destructive and costly cyber-attack in history."

WhatsApp Agrees to Stop Sharing User Data with Facebook
After a ban from the ICO, WhatsApp will no longer share personal data until the GDPR rules can be met.

Minority Cyber-Pros Are Better Educated but Paid Less
Minority representation is higher than in the broader workforce, but these pros are disproportionately found in non-management roles.

Cybersecurity Incident Response Still Major Issue
Half of incident response plans are either informal, ad-hoc or completely non-existent

Rush to the Cloud Risks Security Breaches
Companies across Europe feel the pressure to move to the cloud, but neglect cybersecurity

Google Moves to Ban Ads for Bitcoin, Cryptocurrency
The ban follows a similar no-quarter approach taken by Facebook earlier this year.

Playboy Develops Virtual Currency Wallet
Online visitors will be able to pay and earn tokens to view Playboy.TV’s original content.

BlackTDS Emerges as an As-a-Service Drive-By Kit for Malware Distribution
BlackTDS hosts components for sophisticated drive-by attacks, like social engineering and redirection to exploit kits.

Euro Firms Lagging on AWS CloudTrail Adoption
Missed opportunity to use native security and compliance tools, says Sumo Logic

Fortnite Gamers Warned Over Account Hacking
Players apparently faced with large credit card charges from fraudulent purchases

Microsoft Releases More Spectre/Meltdown Patches
Patch Tuesday covers over 70 vulnerabilities this month

Police Force Investigated for Possible Breach Cover-Up
Gwent Police failed to inform ICO after discovering security issue

Chinese APT Takes Aim at Pharma
The infamous PlugX malware is targeting pharmaceutical organizations in Vietnam, aimed at stealing drug formulas.

Thousands of Florida Virtual School Students Hit by Two-Year Data Breach
The leaked information includes student and parent names, dates of birth, email addresses, school account numbers and credentials.

Trojans Reign Supreme in 2017
Geopolitics, meanwhile, seemed to guide major malware campaigns during the year.



