SEC fines Morgan Stanley Smith Barney $35 million over failure to secure customer data

The financial giant hired a moving company with no experience in data destruction to dispose of hard drives with the personal data of around 15 million customers, said the SEC.
The post SEC fines Morgan Stanley Smith Barney $35 million over failure to … Continue reading SEC fines Morgan Stanley Smith Barney $35 million over failure to secure customer data→

Uber exposes Lapsus$ extortion group for security breach

In last week’s security breach against Uber, the attackers downloaded internal messages from Slack as well as information from a tool used to manage invoices.
The post Uber exposes Lapsus$ extortion group for security breach appeared first on TechRepub… Continue reading Uber exposes Lapsus$ extortion group for security breach→

How to protect your organization’s single sign-on credentials from compromise

Half of the top 20 most valuable public U.S. companies had at least one single sign-on credential up for sale on the Dark Web in 2022, says BitSight.
The post How to protect your organization’s single sign-on credentials from compromise appeared first … Continue reading How to protect your organization’s single sign-on credentials from compromise→

Cosmetics giant Sephora first to be fined for violating California’s Consumer Privacy Act

Sephora will have to pay $1.2 million in penalties, inform California customers it sells their personal data and offer them ways to opt out.
The post Cosmetics giant Sephora first to be fined for violating California’s Consumer Privacy Act appeared fir… Continue reading Cosmetics giant Sephora first to be fined for violating California’s Consumer Privacy Act→

How a business email compromise attack exploited Microsoft’s multi-factor authentication

Mitiga says that MFA, even if improperly configured, is no panacea for preventing attackers from abusing compromised credentials.
The post How a business email compromise attack exploited Microsoft’s multi-factor authentication appeared first on TechRe… Continue reading How a business email compromise attack exploited Microsoft’s multi-factor authentication→

How a business email compromise scam spoofed the CFO of a major corporation

In a scam analyzed by Avanan, the victim received an email claiming to be from the CFO directing them to make a payment to their insurance company.
The post How a business email compromise scam spoofed the CFO of a major corporation appeared first on T… Continue reading How a business email compromise scam spoofed the CFO of a major corporation→

How ransomware attacks target specific industries

Analyzing over 100 prominent ransomware incidents, Barracuda found the top targeted sectors to be education, municipalities, healthcare, infrastructure and financial.
The post How ransomware attacks target specific industries appeared first on TechRepu… Continue reading How ransomware attacks target specific industries→