Infosecurity News

39% of Companies Use Password-Only Authentication
62% view employees as their biggest threat.

FBI Skills Gaps Leave Field Offices Understaffed with Cyber Experts
Next Generation Cyber Initiative has problems, says OGI

Fresh Attack Vectors Found for Stagefright Android Flaw
In addition to MMS, devices can be infected using malicious video files that auto-play when opening a website, or via malicious apps or MP4 files.

1.5Mn Affected In Medical Information Engineering Hack
Several healthcare providers were affected by the attack, including local companies and national outlets, and the federal government.

SANS Announces Recruitment Fair for Top Infosec Candidates
Institute will train up 40 applicants ready to step into a job

Potao Trojan Served Up by Russian TrueCrypt Site
ESET report reveals five-year targeted attack campaign

Russian Cyber Underground Goes From Strength to Strength
Trend Micro report highlights increasing sophistication and professionalism

Russian APT Group Tosses a Hammer Around
Ingenious Hammertoss uses social media and steganography to hide Russian state-sponsored attackers' activities.

Anthem Breach: Symantec Points Finger at ‘Black Vine’ Group
Cyber-espionage group likely operates from China

Researchers Jump the Security Air Gap With a Feature Phone
Hack requires just a lightweight piece of malware

Google Debuts 'Bring Your Own Encryption'
Users can create and hold keys and prevent anyone, including Google, from accessing their at-rest data within the Google Cloud Platform.

ING, USAA Join Up with FIDO Alliance
Financial services has been an engine for the group's strong authentication standards ever since PayPal joined.

Fujitsu: UK Employees Fail to Grasp Importance of Corporate Data
Research highlights need for improved awareness

SSL Redirect Malvertising Campaign Exposes 10 Million to Angler EK
Cyphort Labs warns users global attack is ongoing

Planned Parenthood Hacked Over Videos
The group obtained data such as employees' email addresses, and plans to show Planned Parenthood "stripped naked."

Zerodium Launches to Buy and Sell Zero-Days
The start-up is backed by Vupen, the French vulnerability dealer that has often drawn controversy for brokering exploits to the highest bidder.

Pakistan to Ban BlackBerry Enterprise Service Over Security Fears
Authorities can’t monitor encrypted comms platform

Three Sentenced for $14m Fraud Scheme
Estonian men masterminded global campaign affecting four million PCs

IoT Security, Privacy Concerns Weigh on Consumers
The convenience that smartwatches and other devices bring is also accompanied by security and privacy issues.

Anonymous Hacks US Census Bureau
Online collective exposes employee data in protest at trade agreements



