Infosecurity News
Fake Cryptocurrency Trading Apps Harvest Credentials and Steal Cash
The apps steal Poloniex login credentials, and trick victims into making their Gmail accounts accessible.
US Government Warns CNI Firms of Dragonfly Attacks
New campaign focused on stealing ICS and SCADA data
Reaper Botnet Has Come for the Internet
Reaper is much bigger and more sophisticated than Mirai—and it's still just a baby.
US Consumers Willing to Trade eCommerce Convenience for Security
Survey contradicts the widely-held belief that consumers value convenience and experience over security.
FBI Seeks DDoS Attack Evidence from Victims
The FBI has requested that US victims of DDoS attacks share the details of the experience
25% of Mail Claiming to Be from Federal Agencies is Fraudulent
As mandate comes down, 82% of federal domains lack DMARC for email security, and have 90 days to implement it.
Domino’s Australia Blames Former Supplier for Info Leak
Customers complain of personalised spam from company
UK Cybercrime Falls but Stats Are Still Shaky
ONS figures show 1.6 million incidents of computer misuse
GCHQ Collects Mass Social Media Data on Millions in UK—Report
The spy agency allegedly has collected info for decades, sharing it with foreign intelligence and law enforcement.
Employee Snooping is Widespread, with Most Looking for Sensitive Info They Don't Need
Nearly two in three IT security pros admit they've specifically sought out company information they didn’t need.
Third of IoD Members Have Never Heard of GDPR
Institute calls on government and regulator to step up outreach efforts
ROCA Crypto Bug Compromises RSA Keys
Organizations urged to hunt down vulnerable Infineon chips
Report: 88% of Java Apps Vulnerable to Attacks from Known Security Defects
New Veracode report exposes the risks companies face from vulnerable open source components
Google Rolls Out Advanced Protection for High-Risk Users
Users include journalists who need to protect the confidentiality of their sources, or people in abusive relationships.
DHS Mandates DMARC, HTTPS for All US Federal Agencies
Agencies will have 90 days to implement DMARC and 120 days to upgrade to HTTPS.
Poorly Secured SSH Keys Exposing Firms to Breaches
Venafi finds 90% of organizations don’t even know what they have
Microsoft Kept Quiet About 2013 Bug Database Hack: Report
Five former employees reveal lack of transparency at tech giant
FT30 Firms at Risk from Equifax-Style Breach
RiskIQ report reveals vulnerable web infrastructure is commonplace
Pizza Hut Serves Up a Slice of Data Breach
Affected customers placed orders on the company's mobile app or website on October 1 and 2.
Fresh Adobe Zero-Day Spotted in the Wild
BlackOasis is using it to deliver the FinSpy commercial malware.