Infosecurity News

Idaho Inmates Hack Tablets for Extra Credits
Vulnerability exploit nets prisoners $225K

US Warns of Supply Chain Attacks
Software wide open to abuse by China, Russia and Iran

Exobot Android Malware Targets Banking Apps
Source code for a new version of Exobot dubbed "Trump Edition" has been leaked online.

LifeLock Flaw Highlights Weak Web App Security
A web application design flaw results in a LifeLock data breach.

Imperva Acquires Prevoty, Enhances App Security
Prevoty's LA office will become newest location for Imperva.

Two-Fifths of IT Leaders regard IoT Security as Afterthought
Trend Micro research uncovers worrying lack of investment in protection

XSS Flaws Most Common Over Past Nine Years
NCC Group says it’s still uncovering decades-old flaw in its research

Smart Home Security Camera Bug Exposed
Flaw could let hackers view users’ feeds

DevSecOps Sees Slow Adoption but Wider Incident Handling
More than three-quarters of DevOps pros do not practise 'DevSecOps', or are still in the process of implementation

COSCO Hit by Suspected Ransomware
Chinese shipper’s US website and operations affected

Senator Urges Government to Kill Off Flash Now
Wyden wants to mitigate security risk well before software’s end-of-life in 2020

ERP Apps Under Attack Warns US-CERT
Digital Shadows/Onapsis report lifts lid on a worrying trend

Virginian Bank Robbed Twice in Eight Months
Hackers made off with over $2m following phishing success

Twitter Looks to Tighten Control Over Developers
Social media platform wants to reduce spam and policy abuse

Trend Micro’s ZDI Bug Bounty Goes Server Side
WordPress, Drupal et al come under the microscope in $1.5m scheme

Russian Hacking Campaign Targeted US Utilities
Hacking of US utility control rooms raises concerns over foreign adversaries.

Email-Based Attacks a Growing Risk
Whether it's phishing campaigns or impersonation tactics, attackers are preying on victims through email.

Pen Testers Abuse Configuration, Capture Creds
Rapid7 published a report on successful exploits from a season of pen testing.

City of London Police Begins Cryptocurrency Training
Officers get new courses to improve their cyber-skills

Endpoint Concerns Blight IIoT Security
SANS Institute report reveals patching problems



