Mexican Tourist Tax Refund Firm Exposes 455K Customer Records

Tourists that visited Mexico in the past year, and applied for a tax refund on goods purchased while there, may have had their personal information exposed. According to security researchers, a database containing over 455,000 documents – including scanned passports, identification cards, credit cards, boarding passes and travel tickets – was left open to the […]… Read More

The post Mexican Tourist Tax Refund Firm Exposes 455K Customer Records appeared first on The State of Security.

Continue reading Mexican Tourist Tax Refund Firm Exposes 455K Customer Records

Half of Organizations Fail to Maintain PCI Compliance, Finds New Report

Nearly half of organizations that store, process or transmit card data are still failing to maintain PCI DSS compliance from year to year, reveal new statistics. According to the 2017 Verizon Payment Security Report, the number of enterprises becoming fully compliant is on an upward trend—growing almost five-fold since 2012. Last year, 55.4 percent of […]… Read More

The post Half of Organizations Fail to Maintain PCI Compliance, Finds New Report appeared first on The State of Security.

Continue reading Half of Organizations Fail to Maintain PCI Compliance, Finds New Report

US Government Cybersecurity Readiness Lags Behind Other Industries

According to a new report, the U.S. government’s overall cybersecurity ranked third to last compared to 17 other major industries, including transportation, finance, healthcare and more. The 2017 U.S. State and Federal Government Cybersecurity Report (PDF) by SecurityScorecard analyzed over 500 federal, state and local government agencies, and evaluated their security capabilities across 10 categories. The […]… Read More

The post US Government Cybersecurity Readiness Lags Behind Other Industries appeared first on The State of Security.

Continue reading US Government Cybersecurity Readiness Lags Behind Other Industries

New ‘Defray’ Ransomware Targeting Healthcare, Education, Manufacturing Sectors

A new strain of ransomware—dubbed Defray—has been found targeting a select group of industries, demanding $5,000 from infected victims. Security researchers at Proofpoint, who discovered the strain, warned they’ve observed two “small and selective targeted attacks” distributing the ransomware this month. According to Proofpoint’s analysis, one campaign aimed primarily at healthcare and education organizations, while […]… Read More

The post New ‘Defray’ Ransomware Targeting Healthcare, Education, Manufacturing Sectors appeared first on The State of Security.

Continue reading New ‘Defray’ Ransomware Targeting Healthcare, Education, Manufacturing Sectors

Posted in SBN

NHS Cyber Attack Allegedly Exposes Personal Data of 1.2 Million Patients

The UK’s National Health Service (NHS) has reportedly fallen victim to another massive cyber-attack, exposing the confidential records of up to 1.2 million patients. According to reports, an unknown hacker claimed to exploit a weakness in the NHS’ appointment booking system, SwiftQueue. The vendor is contracted by eight NHS trusts to manage booked appointments, as […]… Read More

The post NHS Cyber Attack Allegedly Exposes Personal Data of 1.2 Million Patients appeared first on The State of Security.

Continue reading NHS Cyber Attack Allegedly Exposes Personal Data of 1.2 Million Patients

Shipping Company Maersk Says NotPetya Cyberattack Could Cost Up to $300M

Container shipping company A.P. Moller-Maersk says a cyberattack that disrupted its operations will come with a hefty price tag of as much as $300 million in lost revenue. The Danish conglomerate, known as the largest container ship and vessel operator in the world, announced the estimated losses in its second quarter financial report. “In the […]… Read More

The post Shipping Company Maersk Says NotPetya Cyberattack Could Cost Up to $300M appeared first on The State of Security.

Continue reading Shipping Company Maersk Says NotPetya Cyberattack Could Cost Up to $300M

Posted in SBN

Nearly Half of Popular Consumer Websites Lack Basic Password Security Requirements

A new analysis of over 40 popular consumer and enterprise websites revealed that many fail to implement the most basic password security requirements. According to the Password Power Rankings study conducted by Dashlane, a surprising 46 percent of consumer sites have “dangerously lax” password policies, including widely used Dropbox, Netflix and Pandora. Of the enterprise […]… Read More

The post Nearly Half of Popular Consumer Websites Lack Basic Password Security Requirements appeared first on The State of Security.

Continue reading Nearly Half of Popular Consumer Websites Lack Basic Password Security Requirements

IRS Alerts of New Scam Stealing Tax Pros’ Credentials

The IRS issued an advisory last week, warning tax professionals of a new phishing scam impersonating tax software providers in an effort to steal their log-in credentials. In a press release, the Internal Revenue Service said the “sophisticated scam” underscores the need for accountants to take strong security measures to protect their clients and their […]… Read More

The post IRS Alerts of New Scam Stealing Tax Pros’ Credentials appeared first on The State of Security.

Continue reading IRS Alerts of New Scam Stealing Tax Pros’ Credentials

Svpeng Mobile Banking Trojan Now Equipped with Keylogger Capabilities

Security researchers have uncovered a new variant of the infamous Android mobile banking Trojan Svpeng, which now comes equipped with a keylogger feature. According to Kaspersky Lab, the latest update allows cybercriminals to steal entered text by exploiting a device’s accessibility services. Designed for users with disabilities or those temporarily unable to interact fully with […]… Read More

The post Svpeng Mobile Banking Trojan Now Equipped with Keylogger Capabilities appeared first on The State of Security.

Continue reading Svpeng Mobile Banking Trojan Now Equipped with Keylogger Capabilities

Virgin America Alerts Employees, Contractors of Personal Data Breach

Virgin America has alerted thousands of employees that the company’s systems were breached, leading to the compromise of their personal data. The American airline, which was acquired by Alaska Air in 2016, notified workers via letter, stating that the incident occurred earlier this year. “On March 13, 2017, during security monitoring activities, our data security […]… Read More

The post Virgin America Alerts Employees, Contractors of Personal Data Breach appeared first on The State of Security.

Continue reading Virgin America Alerts Employees, Contractors of Personal Data Breach