Infosecurity News

Employee Snooping is Widespread, with Most Looking for Sensitive Info They Don't Need
Nearly two in three IT security pros admit they've specifically sought out company information they didn’t need.

Third of IoD Members Have Never Heard of GDPR
Institute calls on government and regulator to step up outreach efforts

ROCA Crypto Bug Compromises RSA Keys
Organizations urged to hunt down vulnerable Infineon chips

Report: 88% of Java Apps Vulnerable to Attacks from Known Security Defects
New Veracode report exposes the risks companies face from vulnerable open source components

Google Rolls Out Advanced Protection for High-Risk Users
Users include journalists who need to protect the confidentiality of their sources, or people in abusive relationships.

DHS Mandates DMARC, HTTPS for All US Federal Agencies
Agencies will have 90 days to implement DMARC and 120 days to upgrade to HTTPS.

Poorly Secured SSH Keys Exposing Firms to Breaches
Venafi finds 90% of organizations don’t even know what they have

Microsoft Kept Quiet About 2013 Bug Database Hack: Report
Five former employees reveal lack of transparency at tech giant

FT30 Firms at Risk from Equifax-Style Breach
RiskIQ report reveals vulnerable web infrastructure is commonplace

Pizza Hut Serves Up a Slice of Data Breach
Affected customers placed orders on the company's mobile app or website on October 1 and 2.

Fresh Adobe Zero-Day Spotted in the Wild
BlackOasis is using it to deliver the FinSpy commercial malware.

New Scam Impersonates VAT Form to Deliver Malware
Phishing attack disguised as HMRC doc contains links to the infamous JRAT malware

Iran Blamed for June Parliament Cyber-Attack
Hackers brute forced scores of accounts

DoubleLocker Ransomware Changes PIN and Encrypts Data
Double trouble for Android users, says ESET

Hundreds of Fake iPhone Accounts Spread Social Scams
ZoneFOX spots fraudsters newsjacking the iPhone 8/X launch

Hyatt Suffers Second Card Data Breach in Two Years
Hotel giant caught out yet again

Netflix Phish Presses Play on Corporate Dangers
Phishing a consumer service like Netflix could lead to illicit access to an enterprise email account.

Accenture Leaked Data Via Another AWS Misconfig
Consulting giant is latest firm guilty of serious security failings

North Korea Targets US Power Grid
Meanwhile, hackers stole a cache of military documents from South Korea including a plan to assassinate Kim Jong-un.

In-Depth Med Records for 150K Americans Leaked in Latest Amazon S3 Issue
Each file includes patient names, home addresses, phone numbers and details on the tests themselves.



