Cobalt/Carbanak Malware Group Leader Arrested in Spain

The Spanish National Police has arrested the leader of a criminal group responsible for developing sophisticated banking malware including Cobalt and Carbanak. On 26 March, EUROPOL announced the arrest of the yet-unnamed computer criminal mastermind in… Continue reading Cobalt/Carbanak Malware Group Leader Arrested in Spain

19% of Ohio State University Students Clicked on Links in Phishing Simulation

Nearly one in five students at Ohio State University clicked on unverified links in emails sent to them as part of a phishing simulation. On 31 January, the IT risk management office at Ohio State University (OSU) initiated a phishing exercise against … Continue reading 19% of Ohio State University Students Clicked on Links in Phishing Simulation

Researchers Can Earn up to $15K in Netflix’s New Public Bug Bounty Program

Netflix has launched a public bug bounty program through which security researchers can receive rewards of up to $15,000. Announced on 21 March, the streaming service’s new vulnerability responsible disclosure framework will award researchers upw… Continue reading Researchers Can Earn up to $15K in Netflix’s New Public Bug Bounty Program

Frost Bank Detects Unauthorized Access that Could Have Exposed Check Images

Texas-chartered Frost Bank has detected an instance of unauthorized access that might have exposed the images of some electronically stored checks. Frost, which is one of the largest banks in Texas at 139 branches across the state, detected the securit… Continue reading Frost Bank Detects Unauthorized Access that Could Have Exposed Check Images

How to Use NIST’s Cybersecurity Framework to Protect against Integrity-Themed Threats

When it comes to the CIA triad, confidentiality generally commands most of the attention. Organizations are worried about the unauthorized disclosure of their data, so they concentrate on reducing the risks of that type of an incident. In so doing, how… Continue reading How to Use NIST’s Cybersecurity Framework to Protect against Integrity-Themed Threats

Microsoft Launches Limited-Time Bug Bounty Program for Bugs Like Spectre and Meltdown

Microsoft has launched a limited-time bug bounty program to help discover and address vulnerabilities similar to Spectre and Meltdown. On 14 March, the Redmond-based tech giant announced a framework for speculative execution side channel vulnerabilitie… Continue reading Microsoft Launches Limited-Time Bug Bounty Program for Bugs Like Spectre and Meltdown

For the First Time, DHS and FBI Accuse Russia of Hacking U.S. Energy Organizations

For the first time on record, the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) publicly blamed Russia for attempting to hack U.S. energy infrastructure. On 15 March, DHS and FBI published a joint Technical Alert (… Continue reading For the First Time, DHS and FBI Accuse Russia of Hacking U.S. Energy Organizations

Unique Data Exfiltration Method Makes PinkKite POS Malware Stand Out

A new family of point-of-sale malware called “PinkKite” uses a unique method to exfiltrate consumers’ stolen payment card information. Kroll Inc. researchers Matt Bromiley and Courtney Dayter presented on the threat during Kaspersky&#… Continue reading Unique Data Exfiltration Method Makes PinkKite POS Malware Stand Out

The FBI’s 10 Most Wanted Black-Hat Hackers – #10

Hackers all have different intentions. Some work to making computer networks more secure, while others develop malware and exploit software vulnerabilities. Of the latter group, there is a special subclass of criminals: those who make the FBI’s C… Continue reading The FBI’s 10 Most Wanted Black-Hat Hackers – #10

Hacking Attack Might Have Breached 135K Patients’ Records at NY Outpatient Center

A hacking attack at a New York-based outpatient center might have breached the medical records of approximately 135,000 patients. The incident occurred on 8 January 2018 when St. Peter’s Surgery & Endoscopy Center (the “Center”) d… Continue reading Hacking Attack Might Have Breached 135K Patients’ Records at NY Outpatient Center