Infosecurity News

Brits Want More Visible Multi-Factor Authentication
Equifax poll suggests less than three log-in steps is no good for consumers

Google Offers $20,000 Rewards to Drive OSS-Fuzz Initiative
Aim is to improve the security and stability of open source software

FBI: Whaling and BEC Scams Rack Up $5bn in Ill-Gotten Gains
Losses have increased a whopping 2,370% in three years.

SMBs Admit They're Compromising on Security
More than 70% of SMB IT managers say budgets have forced them to compromise on security features.

Manchester Police in the Dock After Losing Interview Footage
ICO fines GMP £150,000 after unencrypted DVDs were lost in the post

Mobile Hackers Intercept Bank 2FA to Drain Accounts
Known bug in global SS7 protocol is to blame

Android Apps with Ultrasonic Beacons Track People's Daily Habits
These apps embed ultrasonic beacons into audio, and track them using the microphone of mobile devices.

Bondnet Botnet Mines Cryptocurrency Worldwide
It’s also ready to be weaponized immediately for other purposes, such as mounting Mirai-style DDoS attacks.

NYPD: Fraud Ring Recruited Mules Via Social Media
Sophisticated operation resulted in $2.5m counterfeit check deposits

KONNI RAT Eyes North Korea
A previously unknown remote administration tool has been uncovered after evading detection by the security community for more than three years.

Cuts Like a Knife: Sabre Breach Potentially Impacts 32K Hotel Properties
The hospitality giant is investigating a compromise of its widely-used reservations software.

Gannett Phishing Attack Affects 18K Employees
A hacker was able to compromise the Office 365 credentials of some HR employees.

Clinton: FBI Letter and “Russian WikiLeaks” Cost Me Election
Former frontrunner in no doubt about impact of last minute “events”

India’s Aadhaar ID Card Scheme: 135 Million Records Exposed and Counting
Field day for fraudsters after government's epic privacy snafu

UK Office Workers 'Too Trusting' of Email Attachments
UK businesses expose themselves to hackers and zero-day attacks by failing to implement good email security practices

Fuze Fixes Recordings Privacy Bug
A vulnerability in the Fuze communications platform did not have sufficient controls to ensure that the recordings were kept private

ICO Fines E-Commerce Firm After SQLi Flaw
Building supplies vendor slapped with £55,000 fine

NSA Ends Upstream “About” Data Collection
Agency claims failure to comply with FISC rules was “inadvertent”

Intel Fixes Critical Nine-Year-Old Bug
Vulnerability affects AMT, SBT and ISM firmware

UK Plans to Scan All Attendees at the Champions League Final
Police in Britain will use facial recognition to run real-time comparisons with the mugshots of 500,000 “persons of interest."



