DataCamp Implements Partial Password Reset After Data Security Incident

Online data science learning platform DataCamp implemented a password reset for some of its users potentially affected by a data security incident. According to a statement published on its website, DataCamp discovered on 11 February 2019 that a third … Continue reading DataCamp Implements Partial Password Reset After Data Security Incident

Dunkin’ Says Credential Stuffing Attacks Targeted DD Perks Accounts

Dunkin’ Brands Inc. (“Dunkin’”) said that bad actors recently used credential stuffing attacks to target some DD Perks accounts. Kari McHugh, senior director of customer relations at Dunkin’, wrote in a sample letter sent to the… Continue reading Dunkin’ Says Credential Stuffing Attacks Targeted DD Perks Accounts

U.S. Senators Concerned by Government Employees’ Use of Foreign VPNs

Two U.S. Senators expressed their concern that federal government employees could be undermining the United States’ national security by using VPNs made by foreign companies. In a letter dated 7 February 2019, U.S. Senators Marco Rubio (R-FL) and… Continue reading U.S. Senators Concerned by Government Employees’ Use of Foreign VPNs

Australia Investigating Digital Attack Attempt against Federal Parliament

Australia’s security agencies have launched an investigation into a digital attack attempt against the country’s Federal Parliament. Sources told the Australian Broadcasting Company that security personnel caught digital attackers in the ea… Continue reading Australia Investigating Digital Attack Attempt against Federal Parliament

Phishers Leveraging Google Translate to Target Google and Facebook Users

Phishers are leveraging Google Translate in their attempts to steal the login credentials for users’ Google and Facebook accounts. Larry Cashdollar, a member of Akamai’s Security Intelligence Response Team (SIRT), received an email in early… Continue reading Phishers Leveraging Google Translate to Target Google and Facebook Users

Software Vulnerabilities Used by 200 VT Towns Left Employees’ SSNs Exposed

Vulnerabilities in software used by 200 Vermont municipalities left town employees’ Social Security Numbers and other information exposed. Brett Johnson, owner of IT company simpleroute, discovered the flaws after two Vermont towns hired him to d… Continue reading Software Vulnerabilities Used by 200 VT Towns Left Employees’ SSNs Exposed

14 Essential Bug Bounty Programs of 2019

In 2017, The State of Security published its most recent list of essential bug bounty frameworks. Numerous organizations and government entities have launched their own vulnerability reward programs (VRPs) since then. With that in mind, I think it&#821… Continue reading 14 Essential Bug Bounty Programs of 2019

Why Security Is Needed to Keep the CI/CD Pipeline Flowing Smoothly

Technology has advanced to a state where clients now expect a constant stream of updates for their software and applications. To fulfill this demand, developers commonly turn to what’s known as a CI/CD pipeline. As noted by Synopsys, this practic… Continue reading Why Security Is Needed to Keep the CI/CD Pipeline Flowing Smoothly

Scammers Threatening YouTube Content Creators with Channel Suspension

Scammers are now using the threat of channel suspension to coerce YouTube content creators into meeting their demands and sending over money. These digital attackers are specifically targeting YouTube’s policy infringement system through which us… Continue reading Scammers Threatening YouTube Content Creators with Channel Suspension