Kitchen Utensil Manufacturer Discloses Data Breach of E-commerce Site

A manufacturer of kitchen utensils, office supplies and housewares disclosed a data breach of customer information submitted to its e-commerce website. OXO International Ltd confirmed on 17 December 2018 that digital attackers might have compromised th… Continue reading Kitchen Utensil Manufacturer Discloses Data Breach of E-commerce Site

Alert Service Compromised to Send Out Spam Message

An unknown individual compromised an alert service and abused their access to send out a spam message to some of the service’s customers. The Queenland Early Warning Network (EWN) alert service disclosed first in a Facebook post and later on its … Continue reading Alert Service Compromised to Send Out Spam Message

The Top 20 Information Security Conferences of 2019

With 2018 in the rear-view mirror, the information security industry is now fully invested in 2019. The new year will no doubt present its fair share of challenging digital security threats. But so too will the year enable infosec professionals to disc… Continue reading The Top 20 Information Security Conferences of 2019

Phishers Bypassing 2FA to Compromise Google and Yahoo Accounts

Phishers are bypassing common forms of two-factor authentication (2FA) in a campaign targeting hundreds of Google and Yahoo accounts. In a new report, Amnesty International uses several attack emails sent to it by Human Rights Defenders (HRDs) spread a… Continue reading Phishers Bypassing 2FA to Compromise Google and Yahoo Accounts

NASA Notifies Employees of Potential Data Breach

The National Aeronautics and Space Administration (NASA) has warned its employees of a data breach that might have compromised their personal information. On 18 December, the agency’s Human Resources Messaging System (HRMES) sent out a message to… Continue reading NASA Notifies Employees of Potential Data Breach

Malware Using Memes Posted on Twitter as C&C Service

Researchers have observed a new threat using malicious memes posted on Twitter to receive command-and-control (C&C) instructions. Trend Micro observed that the malicious activity begins after a threat detected as “TROJAN.MSIL.BERBOMTHUM.AA&#8… Continue reading Malware Using Memes Posted on Twitter as C&C Service

Office 365 Phishing Attack Using Fake Non-Delivery Notifications

A new phishing attack is using fake non-delivery notifications in an attempt to steal users’ Microsoft Office 365 credentials. SANS ISC Handler Xavier Mertens discovered the attack while reviewing data captured by his honeypots. The attack begins… Continue reading Office 365 Phishing Attack Using Fake Non-Delivery Notifications

Save the Children Federation Tricked Into Sending $1 Million to Scammers

Scammers tricked Save the Children Federation, a well-known U.S. charity, into sending them approximately one million dollars. As reported by The Boston Globe, digital attackers compromised the email account of a Save the Children Federation employee s… Continue reading Save the Children Federation Tricked Into Sending $1 Million to Scammers

Saipem Identified a Digital Attack against Some of Its Servers

Italian oil and gas industry contractor Saipem has announced that it identified a digital attack against some of its servers. On 10 December, Saipem published a statement on its website in which it revealed the attack and said it was in the process of … Continue reading Saipem Identified a Digital Attack against Some of Its Servers

Bug Affected 52.5 Million Users in Connection with a Google+ API

A bug connected to a Google+ API potentially exposed the profile information belonging to 52.5 million users of Google’s social network. According to David Thacker, VP of Product Management for G Suite, a software update in November introduced th… Continue reading Bug Affected 52.5 Million Users in Connection with a Google+ API