Airlines and Personal Data: A Flight of Fancy

When you purchase a ticket for a flight, be it domestic or international, most are thinking of the purpose of that ticket: to travel from point A to point B. Those invested in the privacy and compliance discussion have since the dawn of the internet n… Continue reading Airlines and Personal Data: A Flight of Fancy

Cyber Security Roundup for October 2018

Aside from Brexit, Cyber Threats and Cyber Attack accusations against Russia are very much on the centre stage of UK government’s international political agenda at the moment. The government publically accused Russia’s military ‘GRU’ intelligence … Continue reading Cyber Security Roundup for October 2018

Here’s how to defend your enterprise from Magecart

Magecart, a tool used by a broad set of hackers to steal online payment data, has been rampant in recent months. The group has allegedly breached popular websites like those of British Airways and Ticketmaster UK by injecting malicious scripts directly or through third-parties to siphon off customer data en masse. With the body of forensic evidence tied to Magecart growing, researchers with analytics company Securonix have released recommendations for defending against the groups. The goal is keep online vendors from being Magecart’s next high-profile scalp. The threat data can “increase the chances of early detection of this, and potentially other future variants of the Magecart malicious threat actor activity on your network,” Securonix’s Oleg Kolesnikov and Harshvardhan Parashar wrote in a research paper. There are at least three data channels that organizations need to monitor to boost their chances of detecting Magecart, according to Kolesnikov and Parashar: web server […]

The post Here’s how to defend your enterprise from Magecart appeared first on Cyberscoop.

Continue reading Here’s how to defend your enterprise from Magecart

Most GandCrab Ransomware Victims Can Now Recover Their Files for Free

Businesses and home users affected by the latest versions of GandCrab ransomware can now recover their locked files for free, thanks to a new decryption tool developed by researchers from antivirus vendor Bitdefender in collaboration with the Romanian… Continue reading Most GandCrab Ransomware Victims Can Now Recover Their Files for Free

British Airways has some good news and bad news about its payment breach

British Airways has made significant revisions to its account of how many payments may have been compromised in a card-skimming breach the airline reported last month. Additional incidents have been discovered, but the original reported exposure was smaller than announced, the company said. The company said on Thursday that it identified an additional window of time when payments were exposed by hackers, and is freshly notifying about 185,000 affected accounts. Of the new number, the airline says that 77,000 card holders had basic billing information as well as card number, expiration date and CVV (the security code usually on the back of the card) exposed. The other 108,000 did not have the CVV exposed. The airline says the newly identified incidents involve rewards bookings between April 21 and July 28. Those dates are separate from British Airways’ initial disclosure last month. British Airways said at the initial disclosure in September that it notified 380,000 customers of the […]

The post British Airways has some good news and bad news about its payment breach appeared first on Cyberscoop.

Continue reading British Airways has some good news and bad news about its payment breach

Magecart Cybergang Targets 0days in Third-Party Magento Extensions

Over two dozen third-party ecommerce plugins contain zero-day vulnerabilities being exploited in a recent Magecart campaign. Continue reading Magecart Cybergang Targets 0days in Third-Party Magento Extensions

Cyber Security Roundup for September 2018

September 2018 started with a data breach bang, with British Airways disclosing a significant hack and data loss. 380,000 of the airlines’ website and mobile app customers had their debit and credit card details lifted via a maliciously injected s… Continue reading Cyber Security Roundup for September 2018