Reddit Says Some User Data Accessed in Security Incident

Reddit said that a digital attacker infiltrated some of its systems and accessed user data during a recent security incident. On 1 August, the social news aggregation website revealed that an attacker had compromised a few of its employees’ accou… Continue reading Reddit Says Some User Data Accessed in Security Incident

Disruption: The True Cost of an Industrial Cyber Security Incident

Industrial control systems are essential to the smooth operation of various national critical infrastructure. While once segmented from the web, these systems are now becoming increasingly more networked and remotely accessible as organizations transfo… Continue reading Disruption: The True Cost of an Industrial Cyber Security Incident

Breach at Electronics Retailer Might Have Exposed 10M Data Records

A 2017 breach at one of the largest consumer electronics retailers in Europe might have exposed 10 million records containing personal data. On 31 July, Dixon’s Carphone issued an “Update on Investigation into Unauthorized Data Access.&#822… Continue reading Breach at Electronics Retailer Might Have Exposed 10M Data Records

Data Security Incident at Pediatric Hospital Affects 100K Individuals

A data security incident at a pediatric hospital affected more than 100,000 individuals including patients and employees. On 20 July, the Boys Town National Research Hospital published a “Notice of Data Security Incident” on its website. Ac… Continue reading Data Security Incident at Pediatric Hospital Affects 100K Individuals

Shipping Company Struck by Ransomware Attack

A shipping company suffered a ransomware attack that affected certain network systems in one of its regions of operation. On 25 July, COSCO Shipping Lines disclosed on Facebook that it had suffered a “local network breakdown” in the America… Continue reading Shipping Company Struck by Ransomware Attack

25% of Federal Agencies Have Yet to Start Compulsory DMARC Compliance Journey, Researchers Find

There is a saying that “security is a process, not a destination.” It means organizations can’t fulfill their information security responsibilities with just a checklist. Instead enterprises must continuously adapt their defenses to t… Continue reading 25% of Federal Agencies Have Yet to Start Compulsory DMARC Compliance Journey, Researchers Find

Kronos Malware Returns With New Attack Campaigns, Updates

The Kronos banking trojan has returned with several new attack campaigns as well as a few updates. In April 2018, researchers at Proofpoint detected a new variant of the malware. It’s the first time Kronos surfaced after largely disappearing from… Continue reading Kronos Malware Returns With New Attack Campaigns, Updates

Russian Hacking Campaign Targeting U.S. Electric Utilities

Homeland security officials said that individuals working for Russia are currently targeting electric utilities located in the United States. The Department of Homeland Security told The Wall Street Journal that persons working for a state-sponsored ha… Continue reading Russian Hacking Campaign Targeting U.S. Electric Utilities

Exobot Android Banking Trojan’s Source Code Leaked Online

Someone leaked the source code for the Exobot Android banking trojan online, leading the malware to circulate widely on the underground web. Bleeping Computer said it received a copy of the source code from an unknown individual in June. In response, i… Continue reading Exobot Android Banking Trojan’s Source Code Leaked Online