Infosecurity News

Dyreza Banking Threat Back to Target North America
Microsoft said that the busy Dyreza RAT has a fresh attack vector using a wire transfer phish.

Cameron Calls in the Spies to Deal With Child Abuse Online
GCHQ and NCA to co-operate, but critics say it’s simply electioneering

China Responsible for 85% of Global Phishing Domains – APWG
Cyber-criminals targeting victims inside Great Firewall are blamed for malicious domain registrations

ICS-CERT: BlackEnergy Attacks on Critical Infrastructure Target Known Vulnerabilities
In a new wrinkle in an ongoing attack, the BlackEnergy malware is targeting internet-connected human-machine interfaces (HMIs).

Charge Anywhere Admits Breach May Have Given Hackers Access for Five Years
Mobile payments processor only partially encrypted data travelling across its network

Ukraine Attacks Rained Down on Cyber Monday – Report
Imperva spots attackers using shopping period as cover to steal data and break systems

Serious Flaw Found in Alibaba's English e-Commerce Site
An attacker could alter product prices, delete goods or close a merchant’s shop on the site.

RedOctober Rises Again with Cloud Atlas APT
Cloud Atlas uses an unusual set of tactics that are not very common in the APT world, including using cloud accounts for C&C communications.

Advanced Inception APT Malware Likely State-Sponsored
The highly sophisticated malware targets wireless and PC users in high-value positions.

(ISC)2 Panel Debate Calls for “Change of Culture” to Mitigate Cyber Threat
Panel also urges greater government transparency

Minister Warns of Cyber Hacking Threat to Driverless Cars
Claire Perry claims attacks on driver-assisted cars and smart motorways could create barrier to adoption

Mobile Banking: A New Vector for Check-Cashing Scams
The Better Business Bureau is warning that mobile apps are being pressed into service in a high-tech twist on an old scam.

TD Bank Ordered to Pay Damages Over Data Breach
The bank lost two unencrypted files with personal information for more than 90,000 Massachusetts customers, but didn't tell anyone for seven months.

Poodle returns to torment 10% of Global Sites
Repurposed attack easier than last time as it targets TLS

UK Police Lack Skills and Resources to Fight Cybercrime – Report
Only around a third are adequately tooled up

Target Ruled Negligent in Massive Holiday Data Breach
Banks and other financial institutions now have the go-ahead to pursue compensation from the retail giant via class-action lawsuits.

(ISC)² Appoints COO David Shearer as Next Executive Director
Shearer will succeed executive director Hord Tipton at the end of 2014.

IoT, Mobility to Drive Fresh Identity Management Ideas
With IoT apps such as remote control of household appliances, health monitoring devices and hotel room keys, the need to verify the identities of mobile device users will become even more urgent.

bebe Suffers First PoS Hack of the Holiday Season
The bebe breach bucks the trend of cyber-criminals going for larger retailers; the attackers targeted customers with higher spending limits.

SpoofedMe Social Login Vulnerability Threatens Web
IBM has uncovered a vulnerability in the social log-in services provided by Amazon and LinkedIn that allow consumer impersonation.



