Wendy’s Reportedly Sued Over Collection of Employees’ Fingerprints

Two former employees of Wendy’s reportedly filed a lawsuit accusing the fast food restaurant chain of breaking the law in the way it collects and stores employees’ fingerprints. According to ZDNet, former Wendy’s employees Martinique … Continue reading Wendy’s Reportedly Sued Over Collection of Employees’ Fingerprints

5 Notable Security Incidents that Recently Affected Federal Entities

Digital attackers have a history of targeting public sector organizations. For its 2018 Data Breach Investigations Report (DBIR), Verizon Enterprise tracked 22,788 security incidents that affected the public sector. Data disclosure occurred in 304 of t… Continue reading 5 Notable Security Incidents that Recently Affected Federal Entities

Romanian Citizen Admits Guilt in Police Department Ransomware Attack

A Romanian citizen has pleaded guilty to federal charges resulting from a ransomware attack that targeted a police department. On 20 September, Eveline Cismaru, 28, pleaded guilty before the Honorable Dabney L. Friedrich in the District of Columbia to … Continue reading Romanian Citizen Admits Guilt in Police Department Ransomware Attack

ICO to Fine Equifax £500,000 for 2017 Data Breach

The Information Commissioner’s Office (ICO) of the United Kingdom announced it will fine Equifax £500,000 for a data breach that occurred in 2017. In a monetary penalty notice filed on 19 September, the ICO revealed its decision to impose th… Continue reading ICO to Fine Equifax £500,000 for 2017 Data Breach

State Department Says Some Employee Info Possibly Exposed in Security Incident

The U.S. State Department said that some employees’ information might have been exposed in a recent security incident. In a notice shared by Politico, the State Department disclosed that “activity of concern” on an email system might … Continue reading State Department Says Some Employee Info Possibly Exposed in Security Incident

A Quarter of Civilian Federal Agencies Have Adopted DMARC and SPF for All Domains

A quarter of civilian federal agencies have adopted DMARC and SPF email authentication protocols for all their domains in compliance with a mandate. Thirty-four percent of 133 agencies are now fully compliant with what is known as BOD 18-01. Issued by … Continue reading A Quarter of Civilian Federal Agencies Have Adopted DMARC and SPF for All Domains

Ransomware Attack Takes Down Airport’s Flight Information Screens

A ransomware attack prevented an English airport from using its flight information screens to assist passengers in their travels. On 13 September, Bristol Airport tweeted out that its flight information systems were experiencing technical difficulties…. Continue reading Ransomware Attack Takes Down Airport’s Flight Information Screens

ICO Receiving 500 Breach-Related Calls a Week Since GDPR Took Effect

The United Kingdom’s Information Commissioner’s Office (ICO) has been receiving 500 calls pertaining to data breaches since the European Union’s General Data Protection Regulation (GDPR) took effect. Speaking before hundreds of senior… Continue reading ICO Receiving 500 Breach-Related Calls a Week Since GDPR Took Effect

OilRig Launching Attack Campaigns With Updated BONDUPDATER Trojan

The OilRig group conducted at least one attack campaign containing an updated variant of the BONDUPDATER trojan as its final payload. In August 2018, Palo Alto Networks’ Unit 42 threat research team detected an OilRig campaign targeting a high-ra… Continue reading OilRig Launching Attack Campaigns With Updated BONDUPDATER Trojan

What is Vulnerability Management Anyway?

Vulnerability management (VM) programs are the meat and potatoes of every comprehensive information security program. They are not optional anymore. In fact, many information security compliance, audit and risk management frameworks require organizatio… Continue reading What is Vulnerability Management Anyway?