Infosecurity News

Poorly Secured SSH Keys Exposing Firms to Breaches
Venafi finds 90% of organizations don’t even know what they have

Microsoft Kept Quiet About 2013 Bug Database Hack: Report
Five former employees reveal lack of transparency at tech giant

FT30 Firms at Risk from Equifax-Style Breach
RiskIQ report reveals vulnerable web infrastructure is commonplace

Pizza Hut Serves Up a Slice of Data Breach
Affected customers placed orders on the company's mobile app or website on October 1 and 2.

Fresh Adobe Zero-Day Spotted in the Wild
BlackOasis is using it to deliver the FinSpy commercial malware.

New Scam Impersonates VAT Form to Deliver Malware
Phishing attack disguised as HMRC doc contains links to the infamous JRAT malware

Iran Blamed for June Parliament Cyber-Attack
Hackers brute forced scores of accounts

DoubleLocker Ransomware Changes PIN and Encrypts Data
Double trouble for Android users, says ESET

Hundreds of Fake iPhone Accounts Spread Social Scams
ZoneFOX spots fraudsters newsjacking the iPhone 8/X launch

Hyatt Suffers Second Card Data Breach in Two Years
Hotel giant caught out yet again

Netflix Phish Presses Play on Corporate Dangers
Phishing a consumer service like Netflix could lead to illicit access to an enterprise email account.

Accenture Leaked Data Via Another AWS Misconfig
Consulting giant is latest firm guilty of serious security failings

North Korea Targets US Power Grid
Meanwhile, hackers stole a cache of military documents from South Korea including a plan to assassinate Kim Jong-un.

In-Depth Med Records for 150K Americans Leaked in Latest Amazon S3 Issue
Each file includes patient names, home addresses, phone numbers and details on the tests themselves.

Data Breach Notification Most Clicked Subject in Phishing Tests
The most common subject line to get an employee’s attention relates to data breaches

Light Patch Tuesday this Month with No Adobe Fixes
Admins should focus on three publicly disclosed flaws

Latest ATM Malware is Lightweight and Simple
The malware consists of two parts - an injector module, which targets ATM software, and the module to be injected.

All for One, One for All: MENA Cyber-criminals Have a Spirit of Sharing Mindset
Investigation shows the regional cybercrime marketplace is defined by a feeling of brotherhood and religious alliance.

VTech Asks Court to Drop Lawsuit Over Breach Affecting Millions of Kids and Parents
The litigation is a consolidation of five separate lawsuits, all arising out of the November 2015 data breach.

Facebook CSO: Spotting Fake News is Harder Than You Think
Stamos hits back at critics



