Lagging Legacy Systems: How Federal Agencies Are Tackling Old IT

If you’re a U.S. taxpayer, you’ve likely heard how Tax Day 2018 was uniquely rocky for the Internal Revenue Service (IRS). A series of technical problems prevented the IRS from processing tax returns filed electronically on 17 April. The ag… Continue reading Lagging Legacy Systems: How Federal Agencies Are Tackling Old IT

Dozens of Vulnerabilities Found Under Hack the DTS Bug Bounty Program

The Hack the DTS bug bounty program uncovered dozens of vulnerabilities in the Defense Travel System serving the Department of Defense. On 30 May, vulnerability coordination platform HackerOne revealed the results of Hack the DTS. Nineteen trusted secu… Continue reading Dozens of Vulnerabilities Found Under Hack the DTS Bug Bounty Program

Insurance Software Provider Exposed Clients’ Data Stored on S3 Bucket

An insurance software provider exposed clients’ sensitive data that it had stored on an Amazon Simple Storage Solution (S3) bucket. Andrew Lech, founder of AgentRun, confirmed the breach in an email sent out to the insurance agency management sof… Continue reading Insurance Software Provider Exposed Clients’ Data Stored on S3 Bucket

Two Canadian Banks Contacted by Fraudsters About Potential Data Theft

Fraudsters contacted two Canadian banks claiming they stole tens of thousands of customers’ personal and account information. Simplii Financial, the direct banking brand for the Canadian Imperial Bank of Commerce (CIBC), disclosed on 28 May that … Continue reading Two Canadian Banks Contacted by Fraudsters About Potential Data Theft

Mozilla Rolls Out Two-Step Verification for Firefox Accounts

Mozilla announced the rollout of two-step verification (2SV) as an optional security feature for all Firefox user accounts. The engineers at Mozilla Foundation designed the feature without support for SMS-based codes. They likely did so for the same re… Continue reading Mozilla Rolls Out Two-Step Verification for Firefox Accounts

Understanding the Primary Threats and Security Concerns to Container Environments

Regular readers of The State of Security should now have a general understanding of why organizations need security for their containers. But they still might be a bit fuzzy on the specifics. In particular, they might still be unclear on the types of t… Continue reading Understanding the Primary Threats and Security Concerns to Container Environments

Greenwich University Fined £120,000 by ICO for “Serious” Security Breach

The Information Commissioner’s Office (ICO) fined the University of Greenwich £120,000 for a “serious” security breach of personal data. On 21 May, the United Kingdom’s Information Commissioner announced the fine. It’… Continue reading Greenwich University Fined £120,000 by ICO for “Serious” Security Breach

PCI DSS Version 3.2.1 Published by PCI Security Standards Council

The Payment Card Industry Security Standards Council (PCI SSC) published a minor revision to version 3.2 of its Data Security Standard (PCI DSS). On 17 May, PCI SSC published PCI DSS version 3.2.1. The purpose of the update was to clarify organizations… Continue reading PCI DSS Version 3.2.1 Published by PCI Security Standards Council

Malware Actors Targeting North Korean Defectors Using Facebook and Google Play

Security researchers found that hackers are using both Google Play and Facebook to actively target North Korean defectors with malware capable of stealing their information. McAfee Mobile Research Team discovered that the Sun Team hacking group is usin… Continue reading Malware Actors Targeting North Korean Defectors Using Facebook and Google Play