Houzz Says Security Incident Might Have Exposed User Data

Home design website and community Houzz revealed that a security incident might have exposed some users’ personal and account data. On 1 February, Houzz published a security update explaining that it detected the security event in late December 2… Continue reading Houzz Says Security Incident Might Have Exposed User Data

Airbus Reveals It Suffered a Digital Security Incident

European aerospace corporation Airbus SE has revealed that a digital security incident recently affected some of its computer systems. In a press release published on 30 January, Airbus confirmed that its “Commercial Aircraft business” info… Continue reading Airbus Reveals It Suffered a Digital Security Incident

Judge Denies Approval of $50M Settlement to Yahoo Data Breach Lawsuit

A federal judge has denied the approval of a proposed $50 million settlement to a class action lawsuit over a data breach at Yahoo. On 28 January, Judge Lucy Koh rejected the settlement in a order submitted to the San Jose division of the U.S. District… Continue reading Judge Denies Approval of $50M Settlement to Yahoo Data Breach Lawsuit

Untold Number of Discover Card Account Holders Notified of Data Breach

An undisclosed number of Discover card account holders have learned of a data breach that might have compromised their account information. According to Bleeping Computer, Discover Financial Services first learned of the security incident on 13 August … Continue reading Untold Number of Discover Card Account Holders Notified of Data Breach

Video-Sharing Platform Targeted by Credential Stuffing Attacks

Bad actors have targeted a video-sharing technology platform with credential stuffing attacks in order to hijack users’ accounts. On 25 January, Dailymotion published a statement on its website in which it announced that it had been the subject o… Continue reading Video-Sharing Platform Targeted by Credential Stuffing Attacks

Malspam Campaign Targeting Russian Speakers with Redaman Malware

An ongoing malicious spam campaign is currently targeting Russian-speaking users with samples of the Redaman banking malware. Since at least September 2018, the malspam campaign has been sending out malicious spam emails written in Russian to users who… Continue reading Malspam Campaign Targeting Russian Speakers with Redaman Malware

Malvertising Campaign Used Steganography to Distribute Shlayer Trojan

A short-lived malvertising campaign leveraged a steganography-based payload to target Mac users with the Shlayer trojan. Named for its use of veryield-malyst[dot]com as one of its ad-serving domains, the “VeryMal” threat actor conducted its… Continue reading Malvertising Campaign Used Steganography to Distribute Shlayer Trojan

DHS Issues Emergency Directive on DNS Infrastructure Tampering

The Department of Homeland Security (DHS) has issued an emergency directive that requires federal agencies to mitigate the threat of Domain Name System (DNS) infrastructure tampering. In “Emergency Directive 19-01,” DHS explains that it&#82… Continue reading DHS Issues Emergency Directive on DNS Infrastructure Tampering

Adware Installers Disguised as Cracks Installing STOP Ransomware

STOP ransomware is using adware installers disguised as cracks as a new method of distributing itself to unsuspecting users. According to Bleeping Computer creator and owner Lawrence Abrams, websites known for distributing software cracks, or software … Continue reading Adware Installers Disguised as Cracks Installing STOP Ransomware

How the Federal Shutdown Could Do Long-Term Digital Security Damage

Most people have at least heard of the partial shutdown plaguing the U.S. federal government. Now over three weeks old, the stoppage owes its existence to a conflict over border security funding. President Donald Trump wants $5.7 billion to build a new… Continue reading How the Federal Shutdown Could Do Long-Term Digital Security Damage