Infosecurity News
Orbitz Attack Impacts Hundreds of Thousands of Consumers
Hackers likely accessed the popular travel-booking site, exposing payment card info, during two periods.
Android Banking Trojan Fakebank Adds Vishing Dimension
The malware will intercept mobile calls and direct victims to a scammer impersonating a bank agent.
FIDO Alliance Expands Authenticator Certifications
The FIDO Alliance has expanded its certification program to include multi-level security certifications.
Email Fraud is a Top Business Risk for 2018
Businesses across the globe are concerned about email phishing campaigns
UK Police Spend £1.3m on Cybersecurity Training
UK Police forces spent around £1.3m over three years according to new report
Cambridge Analytica: ICO Seeks Warrant to Search London Office
Information Commissioner urgently seeks a court warrant to enter the company’s London HQ
Twitter Users Bilked out of Big Money by Elon Musk Clones
When a verified celebrity account posts a tweet, a fraud account using the same image and display name responds with a scam offer.
Microsoft Debuts Bug Bounty for Spectre/Meltdown-Style Flaws
Microsoft has launched the limited-time bounty, while Intel launches a “virtual fences” hardware redesign.
Dragonfly Compromises Core Router to Attack Critical Infrastructure
A core Cisco router relied on by one of Vietnam’s largest oil rig manufacturers was the jumping-off point for attacks on UK energy companies.
Firefox Bug Goes Unfixed for Nine Years
Software developer discovers flaw in Firefox and Thunderbird’s password manager
Cambridge Analytica Under Fire for Data Harvesting
Data analytics firm accused of harvesting millions of Facebook profiles of US voters
Researchers Discover Security Issue on Chrome RDP
Bug discovered that allows a guest user full access to an administer’s machine using Chrome Remote Desktop
GandCrab Ransomware Finds a New Shell
This well-known malware has gotten around a free decryption tool meant to dull its claws by building a new version in just days.
Walmart Jewelry Partner Exposes Millions in Latest Cloud Storage Misconfig
MBM/Limogés Jewelry exposed data that can be used to carry out targeted fraud or phishing attempts.
DHS, FBI Warn on Russian State Actors Targeting Critical Infrastructure
The US is warning that Russian state-sponsored cyber-attackers are targeting critical infrastructure – including nuclear sites.
Vulnerability Discovered in MikroTik RouterOS
Software sold across the globe found to have vulnerability by security researchers
Cybercrime Profits: Up to $200Bn Laundered Each Year
Cybercriminals turning to virtual currencies, video game currency and digital payment systems like PayPal to convert illegal revenue into clean cash
Sofacy Targets Government Agency with New Spear-Phishing Campaign
Espionage group with ties to Russia targets European government organization with updated phishing techniques
US Treasury Department Sanctions Russians Over NotPetya, Election Meddling
The NotPetya campaign, it noted, was the “most destructive and costly cyber-attack in history."
WhatsApp Agrees to Stop Sharing User Data with Facebook
After a ban from the ICO, WhatsApp will no longer share personal data until the GDPR rules can be met.