Infosecurity News

NCSC: Chinese Telecoms Firm ZTE is National Security Risk
GCHQ warns UK telcos to steer clear, although Huawei is still OK

#RSAC: Security Considerations Around Digital Business Transformation
Forrester VP Principal Analyst Julie A. Ask considered the key trends in digital business transformation and the impact they are having on security.

#BSidesSF: Managing Secrets in Your Cloud Environment
Common mistakes in secret management and solutions to the problem

#BSidesSF: How to Solve Infosec Problems with Creative Solutions
Managing individual and environmental factors to solve infosec problems

A Pair of Mobile Apps in Google Play Target Mideast Victims
ViperRAT 2.0 and Desert Scorpion represent a rare instance of a malicious APT in an official app marketplace.

Most Web Apps Contain High-Severity Vulnerabilities
High-severity vulnerabilities were found in 100% of tested banking and finance web applications.

University of Virginia Nabs Top Honors in Collegiate Cyber Contest
Ten cyber-defense teams faced off in Orlando, competing as white-hat hackers to protect a fictional biotech company called Volitech.

US and UK Cyber Agencies Issue Russian Attack Warning
Russian attackers have conducted a sustained campaign targeting routers, say the DHS, FBI and NCSC.

Developers Outnumber Security Pros 100:1 as Breaches Grow
Sonatype study urges greater use of DevSecOps

Telegram App Banned in Russia
Messaging app founder refused to hand encryption keys to FSB

Lords: UK Could be World Leader in "Ethical" AI
Report outlines opportunities for UK firms while experts claim it could address security challenges

Early Bird Code Injection Gets the Obfuscation Worm
Early Bird allows execution of malicious code before the entry point of a process, bypassing security products.

Scammers Bank on Cryptocurrency with Fake Apps
Fake cryptocurrency apps in the mobile app ecosystem exploit the names of well-known exchanges and mixers.

Cybercriminals Earn Millions, And Spend It Wildly
Some spend their money like legitimate earners typically do, but others tend to blow it on fast cars, hookers and drugs.

GWR Resets Passwords After Accounts Are Accessed
Around 1000 accounts affected, says UK train operator

Q1 Cyber-Attacks on UK Firms Jump 27%
ISP claims every firm experienced 600 attempts to infiltrate their network

Uber Hit with New FTC Breach Settlement
Firm will face civil penalties if it fails to disclose another breach

Nation-State Attacks Take 500% Longer to Find
In 50% of cases over the past 12 months, organizations had insufficient endpoint or network visibility to respond successfully.

Google Will Distrust Additional CAs, IT Pros Predict
Just 15% of respondents believe that Google's decision to distrust Symantec certificates is a one-time event.

UK Launches Offensive Cyber-Weapons Against Islamic State
This marks the first time the UK has systematically and persistently attacked an adversary’s online efforts as part of a wider military campaign.



