Amazon keeps tight-lipped about pre-Black Friday security incident

Amazon informed some customers about a security incident Wednesday that resulted in the exposure of their names and email addresses, a company spokesman confirmed to CyberScoop. Amazon “fixed the issue” and has emailed customers who may have been affected, though the company declined to say how many users’ information may have been involved. The incident was not a breach of Amazon.com, the company said. The news came just days before users from throughout the world will log onto the e-commerce site for Black Friday and Cyber Monday purchases. “It would seem Amazon has some…security issues to resolve,” one user on Amazon’s seller forum complained Wednesday. “With such a vague email from Amazon who knows how our information was leaked and to whom.” Amazon previously fired an employee who allegedly shared customer email addresses with a third-party seller, Gizmodo reported in October. But that issue does not appear to have been […]

The post Amazon keeps tight-lipped about pre-Black Friday security incident appeared first on Cyberscoop.

Continue reading Amazon keeps tight-lipped about pre-Black Friday security incident

What Wells Fargo’s cyber boss is doing to protect critical infrastructure

The National Infrastructure Advisory Council is picking up where it left off. Rich Baich, chief information security officer at Wells Fargo, will begin an indefinite term on the committee next month, more than one year since it NIAC released its most recent public report on cybersecurity. The executive group, charged with providing the president and Secretary of Homeland Security with advice on how to secure the U.S. critical infrastructure sectors and their information systems, largely has kept out of the public eye. In August 2017, eight members resigned from the council, citing President Donald Trump’s “insufficient attention” to growing threats and his reaction to a white nationalist rally Charlottesville, Va. in which a counter-demonstrator was killed. Little has happened since those resignations. Existing council members have met since 2017, though according to its website NIAC last submitted a report to the president and Department of Homeland Security in August 2017. […]

The post What Wells Fargo’s cyber boss is doing to protect critical infrastructure appeared first on Cyberscoop.

Continue reading What Wells Fargo’s cyber boss is doing to protect critical infrastructure

U.S. cybercrime-fighters enter agreements with Indonesia, Singapore

When U.S. officials return from international conferences this week they can be thankful for bolstered cybersecurity alliances with two Southeast Asian countries.   The government has struck separate deals with Indonesia and Singapore to strengthen bilateral cooperation on fighting international cybercrime. Deputy Attorney General Rod Rosenstein and Indonesia’s police chief on Monday reached an agreement to increase U.S. training of Indonesian law enforcement officials to combat cyberattacks such as ransomware and to better use digital forensics, according to Straits Times newspaper. The State Department meanwhile signed a declaration of intent with Singapore’s Cybersecurity Agency to increase training and the sharing of technical information, ZDNet reported. Both Singapore and Indonesia are members of the Association of Southeast Asian Nations (ASEAN), an intergovernmental organization made up of members that increasingly have been targeted by hackers, researchers warned this year. Singapore in July said it had been victimized in its largest-ever cyberattack, in which suspected nation-state […]

The post U.S. cybercrime-fighters enter agreements with Indonesia, Singapore appeared first on Cyberscoop.

Continue reading U.S. cybercrime-fighters enter agreements with Indonesia, Singapore

Facebook’s former security boss embarks on apology tour

In the wake of another bad news cycle for Facebook, the company has found an unlikely ally: the former chief information security officer whose exit was responsible for a previous round of controversy. Alex Stamos has been defending the social media giant following a Nov. 14 report in the New York Times which revealed that Facebook CEO Mark Zuckerberg and chief operating officer Sheryl Sandberg sought to ignore systemic problems within the social media platform. Zuckerberg and Sandberg “ignored warning signs” that foreign operatives could exploit Facebook’s reach to disrupt elections, disseminate propaganda and inspire “campaigns of hate,” the Times reported. Both Zuckerberg and Sandberg have defended the company since the report’s publication. Stamos largely has stood alongside them, despite a reportedly acrimonious departure in which he wrote a note to colleagues blaming Facebook’s current woes on “tens of thousands of small decisions made over the last decade.” In an […]

The post Facebook’s former security boss embarks on apology tour appeared first on Cyberscoop.

Continue reading Facebook’s former security boss embarks on apology tour

Suspected Russian cybercriminal arrested in Bulgaria at U.S. request, lawyer says

Bulgarian authorities last week arrested an accused Russian cybercriminal based on an Interpol warrant that originated with prosecutors from the Eastern District of New York, a lawyer familiar with the case told CyberScoop. Alexander Zhukov, a Russian national, was apprehended by police after he was indicted in absentia by U.S. prosecutors, according to Arkady Bukh, a New York-based attorney with a history of representing suspected hackers from Eastern Europe. Bukh now is in negotiations to represent Zhukov, he said Wednesday. Prosecutors accused Zhukov of affiliate fraud, Bukh said. Affiliate fraud typically involves artificially inflating internet traffic to defraud marketers, charging advertisers for access to website visitors who don’t exist. “There is widespread fraud from huge amounts of traffic getting directed through botnets,” said Bukh, describing the rise of ad fraud in general. “Before, it was boys and girls in Russia sitting in boiler rooms clicking manual clicks in order to get […]

The post Suspected Russian cybercriminal arrested in Bulgaria at U.S. request, lawyer says appeared first on Cyberscoop.

Continue reading Suspected Russian cybercriminal arrested in Bulgaria at U.S. request, lawyer says

Consolidation is coming for the cybersecurity industry

It’s starting to happen. Amid a flurry of mergers and acquisitions, the cybersecurity industry is embarking on a path of consolidation that analysts predict will result in the existence of far fewer companies within just a few years. Thousands of cybersecurity vendors are in the marketplace, offering services ranging from anti-phishing and malicious software analysis to threat detection that relies on artificial intelligence technology. The number of companies will reduce by half within five to seven years, as many existing firms are acquired by larger players, and others simply go out of business, said Bill Crowell, a partner at the venture capital firm Alsop Louie Partners. “Cyber defense is about having an integrated set of tools that work together to prevent attacks,” said Crowell, a former deputy director of the U.S. National Security Agency. “But the industry now has a thousand points of light and no illumination. It’s as if […]

The post Consolidation is coming for the cybersecurity industry appeared first on Cyberscoop.

Continue reading Consolidation is coming for the cybersecurity industry