#security-practices

[ follow ]
Theregister
3 days ago
Information security

CISA expects devs to squash old directory traversal bugs

CISA urges software industry to address directory traversal vulnerabilities. [ more ]
The Verge
3 weeks ago
Privacy professionals

Telehealth firm Cerebral fined $7 million over "careless" privacy violations

FTC proposes $7 million fine against Cerebral for mishandling patient data and sharing with third parties without consent. [ more ]
The Verge
4 weeks ago
Privacy professionals

Microsoft left internal passwords exposed in latest security blunder

Microsoft exposed sensitive data on an Azure server due to lacking password protection.
Reports indicate the potential for extensive data leaks and services compromise due to the exposed credentials. [ more ]
Therecord
3 months ago
Privacy professionals

FTC settles with Blackbaud over poor data practices leading to massive hack

Blackbaud will be required to delete unnecessary personal data as part of an FTC settlement.
The breach was a result of the company's weak security practices and poor encryption practices. [ more ]
Ars Technica
5 months ago
Privacy professionals

Prison phone company leaked 600K users' data and didn't notify them, FTC says

Prison phone company Global Tel*Link leaked the personal information of nearly 650,000 users and failed to notify most of the users that their personal data was exposed.
The company agreed to a settlement that requires it to change its security practices and offer free credit monitoring and identity protection to affected users, but the settlement doesn't include a fine.
Global Tel*Link reconfigured the test environment to cut off public access after being notified by a security researcher, but the data was later found on the dark web. [ more ]
Ars Technica
5 months ago
Privacy professionals

Prison phone company leaked 600K users' data and didn't notify them, FTC says

Prison phone company Global Tel*Link leaked the personal information of nearly 650,000 users and failed to notify most of the users that their personal data was exposed.
The company agreed to a settlement that requires it to change its security practices and offer free credit monitoring and identity protection to affected users, but the settlement doesn't include a fine.
Global Tel*Link reconfigured the test environment to cut off public access after being notified by a security researcher, but the data was later found on the dark web. [ more ]
Theregister
5 months ago
Privacy professionals

Google, Amazon, Microsoft make the Mozilla naughty list

Mozilla has labeled several products from Google, Amazon, and Microsoft as 'Privacy Not Included' due to concerns about data collection and security practices.
The report covers over 100 connected products and highlights the worsening state of privacy and security practices by tech giants.
Amazon, in particular, has been criticized for its privacy indiscretions, including retaining voice recordings of children and allegations of employees spying on customers. [ more ]
Amazic
3 months ago
DevOps

What's more to explore besides DevOps? - Amazic

DevOps initiatives are essential for IT organizations, with most organizations recognizing its importance in software development.
DevSecOps is a popular variant of DevOps, focusing on integrating security practices throughout the software development lifecycle. [ more ]
[ Load more ]