#cybersecurity

[ follow ]
Information security
Nextgov.com
4 hours ago
Information security

NASA doesn't know if its spacecraft have adequate cyber defenses, GAO warns

NASA needs mandatory cybersecurity guidelines for spacecraft acquisition policies. [ more ]
The Verge
3 hours ago
Information security

UnitedHealth CEO admits it paid $22 million ransom to BlackCat

CEO Andrew Witty confirmed paying a $22 million ransom to hackers for data breach, facing criticism and calls for better cybersecurity measures. [ more ]
Nextgov.com
9 hours ago
Information security

UnitedHealth CEO grilled over 'clear national security threat' from Change Healthcare hack

Senators questioned UnitedHealth CEO on recent ransomware cyberattack. [ more ]
Harvard Business Review
13 hours ago
Information security

Preventing the Next Big Cyberattack on U.S. Health Care

The cyberattack on Change Healthcare exposed vulnerabilities in the U.S. health care sector that require urgent action for improved cybersecurity. [ more ]
ITPro
14 hours ago
Information security

Human errors still a leading cause of cyber incidents, says Kaseya

Over two human-involved cyber incidents daily last year, majority not severe. Tool commoditization leads to more automated attacks. Government and IT sectors most targeted. [ more ]
ITPro
13 hours ago
Information security

Why remote desktop tools are facing an onslaught of cyber threats

Remote desktop tools are crucial for hybrid work but are often targeted by cybercriminals. [ more ]
moreInformation security
Ars Technica
8 hours ago
Tech industry

Rabbit R1 AI box revealed to just be an Android app

The Rabbit R1 is a smartphone replacement device running a limited Android OS without Google Play access, facing issues with functionality and battery life. [ more ]
cisa
CyberScoop
1 day ago
Information security

Easterly appeals to Congress on CISA funding, citing Chinese threats to critical infrastructure

More funding is crucial for CISA to enhance cybersecurity defense, particularly against Chinese hackers in critical infrastructure. [ more ]
WIRED
9 hours ago
Information security

The US Government Is Asking Big Tech to Promise Better Cybersecurity

The pledge offers flexibility to companies in meeting goals but emphasizes public progress and sharing techniques. [ more ]
CyberScoop
1 week ago
Information security

CISA ransomware warning program set to fully launch by end of 2024

CISA plans to launch automated vulnerability warning program to reduce ransomware attacks through patching vulnerabilities. [ more ]
morecisa
ComputerWeekly.com
8 hours ago
Information security

Better hygiene may mitigate the need to ban ransomware payments | Computer Weekly

Handling ransomware attacks requires weighing up asset value and determining the best recovery strategy. [ more ]
TechCrunch
13 hours ago
Information security

Citigroup's VC arm invests in API security startup Traceable | TechCrunch

API attacks are increasing, highlighting the need for improved API security measures. [ more ]
Privacy professionals
www.nytimes.com
1 day ago
Privacy professionals

N.S.A. Disclosure of U.S. Identities in Surveillance Reports Nearly Tripled in 2023

The number of unmaskings by the NSA from warrantless surveillance nearly tripled in 2022. [ more ]
ComputerWeekly.com
2 days ago
Privacy professionals

UK's long-awaited device security law kicks in | Computer Weekly

The PSTI Act of 2022 places legal duties on manufacturers to ensure basic security standards in electronic devices to protect consumers from data privacy violations and cyber attacks. [ more ]
www.theguardian.com
3 days ago
Privacy professionals

No more 12345: devices with weak passwords to be banned in UK

Tech with weak passwords banned in the UK under new law, enforcing minimum security standards for all smart devices. [ more ]
www.independent.co.uk
3 days ago
Privacy professionals

New laws to protect consumers from cyber attacks take effect

Manufacturers legally required to enhance security of smart devices by banning weak default passwords and ensuring transparency in security updates. [ more ]
BBC News
3 days ago
Privacy professionals

Smart gadgets: Tougher rules for sellers of internet-enabled devices in the UK

New UK law enforces stricter security rules for 'smart' gadgets to protect consumers from cyber-criminals. [ more ]
Los Angeles Times
5 days ago
Privacy professionals

Glendale teachers surprised to find their taxes already filed -- fraudulently

The Glendale Unified School District experienced a ransomware attack resulting in the fraudulent filing of taxes for hundreds of employees. [ more ]
morePrivacy professionals
Ars Technica
1 day ago
Information security

Change Healthcare hacked through stolen password for account with no MFA

Cyberattack on Change Healthcare due to lack of multifactor authentication led to prescription market disruption. [ more ]
Theregister
1 day ago
Information security

UnitedHealth CEO: 'Decision to pay ransom was mine'

Cybercriminals used stolen credentials to access Change Healthcare's systems, prompting CEO Andrew Witty to pay a $22 million ransom, emphasizing the importance of cybersecurity measures. [ more ]
ABA Journal
1 day ago
Law

Clark Hill was 'duped by an obvious scam,' costing its client $1.1M, suit alleges

Clark Hill fell victim to a sophisticated email scam, transferring $1.1M to wrong account, emphasizing the importance of verifying financial requests. [ more ]
Artificial intelligence
FedScoop
2 days ago
Artificial intelligence

CISA unveils guidelines for AI and critical infrastructure

The Cybersecurity and Infrastructure Security Agency released safety guidelines for critical infrastructure, addressing AI risks and obligations under the Biden administration's executive order. [ more ]
Above the Law
2 days ago
Artificial intelligence

Today At ILTA EVOLVE: AI Icebreakers, Cybersecurity Challenges, Live Entertainment

Exciting educational sessions and networking opportunities at ILTA EVOLVE event in Charlotte, focusing on cybersecurity, generative AI, and top security actions for law firms. [ more ]
DevOps.com
1 week ago
Artificial intelligence

The Role of AI in Securing Software and Data Supply Chains - DevOps.com

Open source software supply-chain attacks are increasing, impacting businesses and necessitating new security strategies like AI integration. [ more ]
Nextgov.com
1 week ago
Artificial intelligence

Foreign adversaries using AI to push disinformation, crumble election process, US warns

Foreign actors are using generative AI tools to conduct propaganda campaigns aimed at influencing U.S. elections and exacerbating partisan tensions. [ more ]
Theregister
2 weeks ago
Artificial intelligence

NSA offers AI security advice mainly to defense tech world

The NSA released guidance on protecting AI systems for the defense industry. [ more ]
moreArtificial intelligence
CyberScoop
1 day ago
Information security

US spy agencies to share intelligence on critical infrastructure in policy revamp

The U.S. intelligence community will share threat information with critical infrastructure operators under the revised policy directive. [ more ]
www.cbc.ca
1 day ago
London

All London Drugs stores remain closed after 'cybersecurity incident' | CBC News

London Drugs stores closed due to a cybersecurity incident in Western Canada, prioritizing customer care and data security. [ more ]
WIRED
1 day ago
Information security

The White House Reveals New Master Plan to Stop Everything From Cyberattacks to Terrorism

The Biden administration is updating the US government's infrastructure protection blueprint with a focus on cybersecurity and partnerships with the private sector. [ more ]
TechCrunch
1 day ago
Information security

Exclusive: SafeBase taps AI to automate software security reviews

SafeBase utilizes AI to automate security questionnaires, saving time and improving accuracy for customers. [ more ]
TechCrunch
1 day ago
Information security

Change Healthcare hackers broke in using stolen credentials - and no MFA, says UHG CEO | TechCrunch

Hackers exploited stolen credentials without multi-factor authentication to breach Change Healthcare's systems, leading to massive health data exfiltration in a ransomware attack. [ more ]
JavaScript
Bloomberg
1 day ago
JavaScript

Bloomberg

To prevent unusual activity prompts, ensure browser supports JavaScript/cookies and isn't blocking them. [ more ]
InfoQ
1 week ago
JavaScript

SSH Backdoor from Compromised XZ Utils Library

A backdoor was discovered in xz utils affecting Linux distributions like Debian Sid and Fedora, emphasizing the importance of cybersecurity diligence. [ more ]
Bloomberg
6 days ago
JavaScript

Bloomberg

To prevent being flagged as unusual activity, ensure your browser supports JavaScript and cookies, and that they are not blocked. [ more ]
moreJavaScript
ComputerWeekly.com
1 day ago
Information security

Keeper to help Williams F1 keep up with cyber challenges | Computer Weekly

Keeper Security partners with Williams Racing, enhancing data protection and password hygiene in the team. [ more ]
ComputerWeekly.com
2 days ago
Information security

Ransomware payment bans need universal buy-in | Computer Weekly

Banning ransomware payments is crucial to disrupt cyber criminals and protect organizations from repeated attacks. [ more ]
Ars Technica
2 days ago
Information security

Everyday devices are used to hide ongoing account compromise campaign

Okta warns about widespread authentication attack using devices of everyday users to hide fraudulent login attempts. [ more ]
ITPro
2 days ago
Information security

Windows 11 Pro and CDW - Overcoming today's escalating cyberthreats

Security concerns should not impede business growth. Windows 11 Pro devices help mitigate cybersecurity risks. [ more ]
Theregister
2 days ago
Information security

UK finally bans '12345' passwords on connected devices

Smart device manufacturers in the UK must adhere to new laws like the PSTI Act, focusing on minimum security standards and crackable default passwords. [ more ]
Theregister
2 days ago
Information security

Discord snoop site Spy.pet is offline, banned from platform

Data harvesting site Spy.pet was dismantled after public exposure, highlighting the importance of transparency and scrutiny in cybersecurity. [ more ]
euronews
4 days ago
Europe politics

Can social media swing the EU election?

More EU platform rules in place for 2024 election. [ more ]
Fast Company
5 days ago
Information security

Be careful where you upload files: Cybersecurity researchers highlight a new ransomware threat to browsers

Uploading files online can also lead to ransomware attacks due to modern browsers' capabilities to interact with local file systems. [ more ]
Nextgov.com
5 days ago
Information security

VA is warning veterans about Change Healthcare cyberattack, secretary says

The Department of Veterans Affairs notified over 15 million veterans of a cybersecurity breach but found no adverse impacts on patient care. [ more ]
Above the Law
5 days ago
Information security

Using Employee Engagement And Technical Controls To Reduce Insider Risk

Insider risk, posed by employees, is a significant cybersecurity concern in organizations despite traditional defense mechanisms. [ more ]
data-breaches
InfoQ
6 days ago
Data science

Rachael Greaves at QCon London: Ethical AI Can Decrease the Impact of Data Breaches

Data minimisation helps decrease the impact of data breaches by limiting the amount of information organizations hold. [ more ]
channelpro
1 week ago
Privacy professionals

Do you know your data's worth?

Data is rapidly growing, with its value increasing significantly; protecting data is crucial for businesses to prevent cyberattacks and financial loss. [ more ]
eLearning Industry
1 week ago
Privacy professionals

Ensuring eLearning Security: Safeguarding Your Online Education Venture Against Cyber Threats

eLearning security is crucial due to rising cybercrime costs and the increasing reliance on technology in education. [ more ]
Harvard Business Review
2 weeks ago
Business intelligence

How to Stay Ahead of a Cybersecurity Breach with the Right Resilience Strategy - SPONSOR CONTENT FROM COMMVAULT

Cybercriminals are advancing their tactics, causing widespread ransomware attacks across organizations of all sizes. [ more ]
moredata-breaches
ITPro
5 days ago
Information security

Flawed Cisco firewalls used to target government networks

A state-affiliated cyber espionage campaign, ArceneDoor, exploited two Cisco zero-day vulnerabilities to infiltrate government networks. [ more ]
TechCrunch
6 days ago
Startup companies

Rubrik's shares climb 20% in its public debut | TechCrunch

Rubrik debuts on NYSE at $38 a share, exceeding its target range, with a fully diluted valuation of $6.6 billion. [ more ]
TechCrunch
6 days ago
Information security

Health insurance giant Kaiser notifies millions of a data breach | TechCrunch

Kaiser Foundation Health Plan notified 13.4 million residents of a data breach involving unauthorized access to a network server. [ more ]
Tripwire
6 days ago
Information security

"Junk gun" ransomware: the cheap new threat to small businesses

Cheap, unsophisticated ransomware like 'junk gun' poses a serious threat to organizations, despite not making headlines like other advanced variants. [ more ]
The Verge
6 days ago
Information security

Microsoft needs to win back trust

Microsoft is facing serious security challenges, requiring a complete overhaul of its security culture to prevent further breaches and restore trust. [ more ]
Ars Technica
2 weeks ago
Privacy professionals

Why the US government's overreliance on Microsoft is a big problem

Microsoft's untouchable position due to critical government partnerships. [ more ]
Theregister
2 weeks ago
Deliverability

Microsoft breach allowed Russia to steal Feds' emails

CISA warns Russian spies stole sensitive data from Microsoft's email system; agencies need immediate remedial action. [ more ]
TechCrunch
2 weeks ago
Privacy professionals

US says Russian hackers stole federal government emails during Microsoft cyberattack | TechCrunch

Russian government-backed hackers stole U.S. federal agency emails via a Microsoft cyberattack.
CISA issued an emergency directive for civilian government agencies to secure email accounts from Russian hackers. [ more ]
The Verge
3 weeks ago
Privacy professionals

Microsoft left internal passwords exposed in latest security blunder

Microsoft exposed sensitive data on an Azure server due to lacking password protection.
Reports indicate the potential for extensive data leaks and services compromise due to the exposed credentials. [ more ]
Hot for Security
6 days ago
Information security

Hacker posts fake story about Ukrainians trying to kill Slovak President

The importance of cybersecurity measures and vigilance in protecting IT systems from malicious hackers. [ more ]
Graham Cluley
1 week ago
Information security

Smashing Security podcast #369: Keeping the lights on after a ransomware attack

Podcast discusses Leicester City Council ransomware attack, data breach, Indian election deepfakery. [ more ]
Inside Higher Ed | Higher Education News, Events and Jobs
6 days ago
Information security

Colleges spending more than ever on cybersecurity efforts

Higher education institutions are increasing cybersecurity budgets, but still lag behind other sectors in spending levels. [ more ]
ITPro
6 days ago
Information security

Hackers have been abusing a popular antivirus solution to crack corporate networks for five years

A malware campaign has been using a popular antivirus solution to distribute backdoors on networks since at least 2018. [ more ]
Theregister
1 week ago
Information security

'Sophisticated' nation-state crew exploiting Cisco firewalls

A sophisticated nation-state group compromised Cisco firewalls for espionage, targeting VPN services globally. [ more ]
Hindustan Times
1 week ago
Privacy professionals

Nothing data leak: Company confirms 'vulnerability' affecting community member data

Data breach at UK-based smartphone company Nothing led to leaked email addresses of community members. [ more ]
ComputerWeekly.com
1 week ago
DevOps

Questions for IT and cyber leaders from the CSRB Microsoft report | Computer Weekly

Organizations should consider assessing their security and risk profile in relation to Microsoft's Global Hyperscale Cloud in light of recent hacking incidents. [ more ]
thenewstack.io
2 weeks ago
DevOps

Attack (or Penetrate Test) Cloud Native the Easy Way

Weak cloud native infrastructure security defenses leave distributed networks vulnerable to attacks via simple tools or unpatched security holes, including easy access through dark web purchases. [ more ]
TechRepublic
1 week ago
Privacy technologies

Can a VPN Be Hacked?

VPNs encrypt online traffic to protect user data from prying eyes, providing an additional layer of security for both businesses and consumers. [ more ]
PCMAG
2 weeks ago
Privacy technologies

Pay $199 Once, Get DPN and Firewall Protection for Life

Deeper Connect Pico offers an all-in-one security solution for home offices at a one-time cost of less than $200. [ more ]
Forbes
1 week ago
Marketing

Malvertising Slips Through: Boosting Digital PR And Ad Safety Is Vital

Digital ad tools by mar-tech startups are crucial, but malvertising poses significant threats exploiting trust and mimicking legitimate brands. [ more ]
TechCrunch
1 week ago
Privacy professionals

European police chiefs target E2EE in latest demand for 'lawful access' | TechCrunch

The UK's National Crime Agency director general urges Meta to reconsider end-to-end encryption for better law enforcement access. [ more ]
www.nytimes.com
1 week ago
Germany news

Germany Arrests 3 Suspected of Passing Secrets to China

German citizens arrested for gathering naval data for Chinese security services show delicate relationship dynamics between the two countries. [ more ]
www.nytimes.com
1 week ago
Deliverability

Welcome to Scam World

In a world inundated with digital communication channels, it's crucial to be vigilant and discerning about the information and opportunities that come our way. [ more ]
Nextgov.com
2 weeks ago
Deliverability

Russian hackers accessed U.S. government emails in Microsoft breach, CISA says

Kremlin-backed hackers breached Microsoft systems in January, exfiltrating email communication from federal agencies, raising cybersecurity concerns. [ more ]
english.elpais.com
1 week ago
Women in technology

Yemeni women become mobile phone technicians to curb sextortion

Women in Yemen face challenges fixing mobile phones due to gender norms and risks of extortion, impacting their daily lives and work opportunities. [ more ]
Iapp
1 week ago
Data science

UN agency suffers ransomware attack

UN Development Programme data stolen in ransomware attack. [ more ]
WIRED
2 weeks ago
Data science

Change Healthcare's New Ransomware Nightmare Goes From Bad to Worse

Change Healthcare faces cyberattack with stolen medical and financial data being sold by ransomware group. [ more ]
TechCrunch
2 weeks ago
Data science

A ransomware gang is leaking Change Healthcare's stolen patient data | TechCrunch

Cybercriminals published stolen medical records to extort payment from Change Healthcare. [ more ]
Gadgets 360
3 weeks ago
Data science

Boat Launches Probe Into Data Breach That Impacted 7.5 Million Customers

Boat is investigating a potential data breach that exposed PII of over 7.5 million customers.
The leaked data was available for purchase online, making customers vulnerable to phishing and scams. [ more ]
TechCrunch
1 week ago
Privacy professionals

Cape dials up $61M from A16Z + more for mobile service that doesn't use personal data | TechCrunch

Cape aims to provide a more secure approach by minimizing the collection of personal data, enhancing privacy protection. [ more ]
Forbes
2 weeks ago
Privacy professionals

Council Post: How SMEs Can Build An Optimal Tech Stack For A Secure Hybrid Workplace

Implementing a robust cybersecurity strategy is crucial for businesses of all sizes.
Zero trust security measures are essential to protect data in organizations. [ more ]
TechCrunch
3 weeks ago
Data science

AI data security startup Cyera confirms $300M raise at a $1.4B valuation | TechCrunch

AI-based Cyera platform secures sensitive data movement, funding $300M at $1.4B valuation.
Cyera's rapid valuation growth reflects strong user traction and market demand for data security solutions. [ more ]
Nextgov.com
3 weeks ago
Privacy professionals

Congress tries again for comprehensive data privacy bill

The American Privacy Rights Act aims to establish nationwide data security practices and hold companies accountable for protecting personal data.
The bill empowers the Federal Trade Commission to enforce legislation and requires large data holders to conduct privacy impact assessments regularly. [ more ]
Nextgov.com
3 weeks ago
Privacy professionals

Wyden bill requires new cyber standards in federal tech procurement

New bill by Sen. Ron Wyden requires cybersecurity standards for federal government collaboration tools.
Measure focuses on preventing hacks like the Chinese cyberattack on Microsoft email accounts of government officials. [ more ]
TechRepublic
1 week ago
Privacy professionals

Devices Infected With Data-Stealing Malware Increased by 7 Times Since 2020

The number of devices infected with data-stealing malware in 2023 was 9.8 million, with an expected rise to 16 million; infostealers are on the rise due to ease of access. [ more ]
Data Matters Privacy Blog
2 weeks ago
EU data protection

EU Formally Adopts Cyber Law for Connected Products | Data Matters Privacy Blog

The EU Parliament passed the EU Cyber Resilience Act (CRA) to ensure connected products are resilient against cyber threats and comply with essential cybersecurity requirements. [ more ]
Iapp
3 weeks ago
EU data protection

Netherlands' DPA reminds entities to report data breaches

The Autoriteit Persoonsgegevens handled over 25,000 data breach reports impacting 20 million individuals in 2023.
Institutions are mandated to notify individuals if their data is potentially compromised in a cyberattack. [ more ]
Kotaku
2 weeks ago
Video games

Steam Hit Ready Or Not Source Code Stolen In Massive Hack

Hackers stole millions of files, including Ready or Not game source code and console builds, highlighting cybersecurity risks in the gaming industry. [ more ]
TechCrunch
2 weeks ago
Venture

Evolution Equity Partners raises $1.1B for new cybersecurity and AI fund | TechCrunch

Investment in cybersecurity dropped 40% but is showing signs of recovery. Evolution Equity Partners launched a $1.1 billion cybersecurity and AI fund. [ more ]
eLearning Industry
2 weeks ago
Web design

Balancing SEO And Cybersecurity: Ensuring Safe Web Experiences For Your Users

SEO and cybersecurity are interconnected priorities for all website owners, affecting search rankings and brand reputation. [ more ]
Theregister
3 weeks ago
Web design

Notepad++ dev slams notepad.plus 'parasite' website

Beware of the notepad.plus scam site with malicious ads targeting Notepad++ users.
Reporting unscrupulous sites can help remove them from search results and protect users. [ more ]
TechRepublic
2 weeks ago
Information security

Sophos Study: 94% of Ransomware Victims Have Their Backups Targeted

Backups do not guarantee safety from ransomware attacks; compromised backups significantly increase the likelihood of paying ransom and recovery costs. [ more ]
TechRepublic
2 weeks ago
Information security

Apple Alerts iPhone Users to Mercenary Spyware Attacks

Apple warned iPhone users of targeted mercenary spyware attacks, advising expert help for affected users. [ more ]
GSMArena.com
2 weeks ago
Apple

Apple warns users in over 90 countries on mercenary spyware attacks

Apple warned users in 92 countries of potential spyware attacks, specifically targeting individuals with a high level of sophistication and resources. [ more ]
New York Post
2 weeks ago
Apple

Apple hit with 'mercenary spyware attacks' - iPhone users warned worldwide of 'most advanced digital threats'

High-profile individuals targeted in advanced cyberattacks
Mercenary spyware attacks are highly sophisticated and well-funded [ more ]
Engadget
2 weeks ago
Apple

iPhone users in 92 countries received a spyware attack warning from Apple

Apple warned users of potential mercenary spyware attacks on their iPhones.
Apple's alert emphasized the personalized nature of the attack and urged users to take it seriously. [ more ]
New Relic
2 weeks ago
Information security

Identify vulnerabilities across application environments

Securing application environments is essential for operational security, compliance, and customer trust, requiring identification and mitigation of vulnerabilities through detailed understanding and effective strategies. [ more ]
Theregister
2 weeks ago
France politics

French cities knocked offline by 'large-scale cyber attack'

French municipal services offline due to cyber attack. [ more ]
New York Post
2 weeks ago
New York City

NYC start-up founder Sophia D'Antoine, 30, dies after being mowed down crossing UES street

Sophia D'Antoine, a young cybersecurity research firm founder, tragically passed away after being struck by a speeding SUV.
The incident involved a 2017 Land Rover hitting D'Antoine, subsequently causing a head-on collision with a taxi and another parked SUV. [ more ]
Nextgov.com
2 weeks ago
Business intelligence

CISA alerts Sisense breach that possibly exposed customer data

Sisense may have experienced a data breach affecting customer data.
The incident is suspected to be part of a broader supply chain attack with potential impacts on critical infrastructure. [ more ]
siliconvalleyjournals.com
3 weeks ago
Business intelligence

Onum Raised $28M in Series A Funding for Data Observability and Orchestration Platform

Onum secured $28 million in Series A funding for expansion and growth.
Pedro Castillo, CEO, aims to empower businesses with advanced data management capabilities. [ more ]
TechCrunch
3 weeks ago
Business intelligence

Google injects generative AI into its cloud security tools | TechCrunch

Google introduced cloud-based security products at Cloud Next conference for corporate networks.
Gemini AI models were central in the new security products and services introduced by Google. [ more ]
TechRepublic
3 weeks ago
Information security

Cyber Insurance Policy | TechRepublic

Cyber threats are increasing, leading to financial losses that companies need to mitigate.
The policy covers various cyber-related incidents, such as unauthorized access to bank accounts and fraudulent transactions. [ more ]
[ Load more ]