Infosecurity News

EFF Releases Millionth Free HTTPS Cert
'Let's Encrypt CA' helps build a more secure and better encrypted internet.

NatWest Vows to Improve Security After SIM Swap Fiasco
Investigation shows how easy it is to drain bank accounts

Google Open Sources Framework to Improve Third Party Security
Vendor Security Assessment Questionnaire should help firms and their suppliers

High-Seas Pirates Turn to Cyber-Espionage
Uncommonly wired sea-pirates hacked bills of lading for future shipments and vessel routes to plot out their attacks ahead of time.

Fresh APT Found Targeting Indian Military, Diplomats
The multi-vector campaign drops a remote access trojan (RAT) with data exfiltration, screen capture and keylogging capabilities.

Cox Communications Investigates Data Breach Affecting 40K Employees
Names, email addresses, phone numbers and phishing-ready info on employees has turned up on a Dark Web marketplace.

‘KeRanger’ Ransomware Hits OS X
Palo Alto Networks has unearthed a new piece of ransomware that is specifically targeting the OS X platform.

Fast Company, Inc. Magazine Publisher Hacked
Sources say hackers have already used stolen wage information and Social Security numbers to file fraudulent federal and state tax returns.

#RSAC: Accessibility Clickjacking Threatens 500Mn Android Devices
In a PoC unveiled at RSA, Skycure married mobile clickjacking and accessibility permissions for an insidious new attack vector.

Golem Android Trojan Remotely Controls Mobile Apps
Golem can control devices remotely and automatically launch and run applications without a user’s consent.

#RSAC: BT Partners with Identity and Security to Secure Cloud
BT has announced further partnerships with CA Technologies and Palo Alto Networks to offer cloud identity service and security.

#RSAC: Hackers Will Abuse Gov Data Access, Say Security Pros
Survey finds 88% of security professionals think access would have a negative impact on consumer and enterprise security and privacy

One Third of SMBs Have No Endpoint Security – Report
HEAT study also finds mobile management tools eschewed by many

Turkey Feels the DDoS Heat with Big Attack Spike
Likely motivated by geopolitical events, Turkish victims at the end of the year skyrocketed ten-fold to more than 30,000 events per day.

Just One Quarter of UK Directors Report Cybercrime
IoD report reveals worrying lack of cyber preparedness

POS Hackers Caught Scanning for Simple Passwords
Time for IT admins to improve password management

Turkish Hacker Pleads Guilty to $55m ATM Cyber Heist
Findikoglu faces over 57 years in the slammer

#RSAC: Cyberthreat Information Sharing and Privacy Concerns need not Conflict
“There are natural disincentives for companies to share"

#RSAC: Detect at Machine not Human Speed, Says HPE CTO
we need to build security into the data and make sure we can isolate and recover applications

#RSAC: Wearables Crack Open Enterprises for Cyber-Attack
69% of wearable device owners forego login credentials, such as PINs, passwords, fingerprint scanners and voice recognition.



