Thu.Jul 25, 2019

article thumbnail

Multi-cloud use by healthcare providers puts patient data at risk

Thales Cloud Protection & Licensing

As a result of government mandates, the need for greater efficiency, and the desire to enable better patient care, U.S. healthcare organizations are nearly universal in the adoption of digital transformation technologies (cloud, SaaS applications, big data, IoT, digital payments, containers, and blockchain). But digital transformation also introduces the potential to put patients’ sensitive financial and healthcare data at risk by changing where and how data needs to be secured.

Cloud 66
article thumbnail

Why Hackers Abuse Active Directory

Data Breach Today

From Ransomware to APT Attacks, AD Can Make Connecting to Systems Easy Warning: Attackers are abusing poorly secured and managed implementations of Microsoft Windows Active Directory to hack organizations and distribute ransomware. Fewer old operating systems and greater Active Directory security knowledge are helping mitigate the threat. But experts say more must be done.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

The Unsexy Threat to Election Security

Krebs on Security

Much has been written about the need to further secure our elections, from ensuring the integrity of voting machines to combating fake news. But according to a report quietly issued by a California grand jury this week, more attention needs to be paid to securing social media and email accounts used by election officials at the state and local level.

Security 179
article thumbnail

ACT police admit they unlawfully accessed metadata more than 3,000 times

The Guardian Data Protection

Police seeking legal advice about two cases that resulted in information that ‘may have been used in a prosecution’ ACT Policing has admitted it unlawfully accessed citizens’ metadata a total of 3,365 times, not 116 as previously disclosed in an explosive commonwealth ombudsman’s report on Monday. The new disclosures include a total of 240 cases that resulted in information valuable to criminal investigations and two that “may have been used in a prosecution”.

Metadata 109
article thumbnail

Get Better Network Graphs & Save Analysts Time

Many organizations today are unlocking the power of their data by using graph databases to feed downstream analytics, enahance visualizations, and more. Yet, when different graph nodes represent the same entity, graphs get messy. Watch this essential video with Senzing CEO Jeff Jonas on how adding entity resolution to a graph database condenses network graphs to improve analytics and save your analysts time.

article thumbnail

German firms BASF, Siemens, Henkel hit by cyber attacks

Security Affairs

A new wave of cyber attacks carried out by a China-linked APT group hit German blue-chip companies BASF, Siemens, Henkel and others. On Wednesday, German blue-chip companies BASF, Siemens, Henkel along with a host of others confirmed they had been targeted by a wave of cyber attacks. German media reported that the cyber attacks were launched by China-linked cyberespionage group.

More Trending

article thumbnail

Imperva blocked the largest Layer 7 DDoS attack it has ever seen

Security Affairs

Researchers at Imperva revealed that an undisclosed streaming service was hit by a massive DDoS attack that stopped it for 13 days. An undisclosed streaming service was hit by a 13?day DDoS massive attack powered by a Mirai botnet composed of 402,000 IoT devices. Imperva confirmed that its systems were able to repel the attack and the service remained up and running during the DDoS attack. “Targeting the authentication component of your site, this DDoS attack was led by a coordinating 402,

IT 86
article thumbnail

Android Spyware Has Ties to Election Interference

Dark Reading

Recently revealed surveillance-ware comes from a consultant with close ties to Russia's GRU who was sanctioned by the US for election-tampering.

87
article thumbnail

Johannesburg residents left in the dark after a ransomware attack at City Power

Security Affairs

South African electric utility City Power that provides energy to the city of Johannesburg, has suffered serious disruptions after a ransomware attack. A ransomware infected systems at City Power, an electricity provider in the city of Johannesburg, South Africa, and some residents were left without power. The energy utility informed its customers via Twitter of the ransomware attack that encrypted its network, including all its databases and applications.

article thumbnail

Johannesburg Ransomware Attack Leaves Residents in the Dark

Dark Reading

The virus affected the network, applications, and databases at City Power, which delivers electricity to the South African financial hub.

article thumbnail

Peak Performance: Continuous Testing & Evaluation of LLM-Based Applications

Speaker: Aarushi Kansal, AI Leader & Author and Tony Karrer, Founder & CTO at Aggregage

Software leaders who are building applications based on Large Language Models (LLMs) often find it a challenge to achieve reliability. It’s no surprise given the non-deterministic nature of LLMs. To effectively create reliable LLM-based (often with RAG) applications, extensive testing and evaluation processes are crucial. This often ends up involving meticulous adjustments to prompts.

article thumbnail

Android Spyware Monokle, developed by Russian defense contractor, used in targeted attacks

Security Affairs

Researchers at Lookout discovered a new mobile spyware dubbed Monokle that was developed by a Russian defense contractor. Experts at Lookout discovered a new Android mobile spyware in the wild, dubbed Monokle, that was developed by a Russian defense contractor named Special Technology Centre Ltd. ( STC). “Lookout has discovered a highly targeted mobile malware threat that uses a new and sophisticated set of custom Android surveillanceware tools called Monokle that has possible connection

Cleanup 79
article thumbnail

Advancements in streaming data storage, real-time analysis and machine learning

IBM Big Data Hub

It’s no surprise: most companies working with stream data today say they are planning to make changes to drive greater value. Advancements in machine learning (ML) and very-high-speed data persistence for real-time analytics are reshaping strategies and architectures.

article thumbnail

New variant of Linux Botnet WatchBog adds BlueKeep scanner

Security Affairs

Experts at Intezer researchers have spotted a strain of the Linux mining that also scans the Internet for Windows RDP servers vulnerable to the Bluekeep. Researchers at Intezer have discovered a new variant of WatchBog, a Linux-based cryptocurrency mining botnet, that also includes a module to scan the Internet for Windows RDP servers vulnerable to the Bluekeep vulnerability (CVE-2019-0708). “We have discovered a new version of WatchBog—a cryptocurrency-mining botnet operational since la

Mining 75
article thumbnail

Russian Threat Group May Have Devised a 'Man-on-the-Side' Attack

Dark Reading

Data from an intrusion last year suggests Iron Liberty group may have a new trick up its sleeve, Secureworks says.

IT 90
article thumbnail

How and Why Should You Be Tracking Geopolitical Risk?

Geopolitical risk is now at the top of the agenda for CEOs. But tracking it can be difficult. The world is more interconnected than ever, whether in terms of economics and supply chains or technology and communication. Geopolitically, however, it is becoming increasingly fragmented – threatening the operations, financial well-being, and security of globally connected companies.

article thumbnail

Three things to consider about medical storage

TAB OnRecord

It’s an important time to re-examine your medical equipment storage. Amidst a need for additional patient rooms and beds are rising real estate costs (hospitals account for over $1 trillion1 in owned property), an increased need for secure storage and storage requests that are unique to the healthcare industry. We’ll take you through three things [.

article thumbnail

How to Create Smarter Risk Assessments

Dark Reading

Executives and directors need quantitative measurements - such as likelihood of loss and hard-dollar financial impact - to make more informed decisions about security risks.

Risk 71
article thumbnail

FTC fines Facebook $5B and obliges it to adopt a new privacy framework

Security Affairs

The Federal Trade Commission fined Facebook $5 billion for privacy violations and is instituting new oversight and restrictions on its business. The Federal Trade Commission fined Facebook $5 billion for privacy violations over the Cambridge Analytica scandal. The authorities are also instituting new oversight and restrictions on its business. In April 2018, Facebook revealed that 87 million users have been affected by the Cambridge Analytica case, much more than 50 million users initially tho

Privacy 69
article thumbnail

Answer These 9 Questions to Determine if Your Data Is Safe

Dark Reading

Data protection regulations are only going to grow tighter. Make sure you're keeping the customer's best interests in mind.

86
article thumbnail

7 Pitfalls for Apache Cassandra in Production

Apache Cassandra is an open-source distributed database that boasts an architecture that delivers high scalability, near 100% availability, and powerful read-and-write performance required for many data-heavy use cases. However, many developers and administrators who are new to this NoSQL database often encounter several challenges that can impact its performance.

article thumbnail

NSA Announces New Cybersecurity Directorate

Adam Levin

The U.S. National Security Agency announced the formation of a new Cybersecurity Directorate earlier this week. Effective October 1, the directorate’a mission is will be the creation of a “major organization that unifies NSA’s foreign intelligence and cyber defense missions,” according to the agency’s website. It will be led by Anne Neuberger, the former NSA deputy director of operations and lead of the Russia Small Group.

article thumbnail

Stock trading service Robinhood stored passwords in plaintext for some users

Security Affairs

Stock trading service Robinhood announced that the passwords of a number of users were stored in plaintext, the company is informing impacted ones. Stock trading service Robinhood admitted to have stored passwords of a number of users in plain text, the company is informing impacted ones via emai l. “When you set a password for your Robinhood account, we use an industry-standard process that prevents anyone at our company from reading it.

article thumbnail

Location intelligence – an auto industry game changer

DXC Technology

With technology advances over the last decade, automotive businesses can now easily obtain enhanced location-based data – from within a facility and across the globe – that helps them make better-informed critical business decisions. When used well, location-based data is a game changer. Location intelligence can enhance visibility at all levels of the business – […].

article thumbnail

UPDATE: FTC Announces Record-Breaking Facebook Settlement Order

Hunton Privacy

As previously reported on July 12, 2019, Facebook will pay a $5 billion penalty to the Federal Trade Commission to resolve a privacy probe into whether Facebook violated a prior FTC consent decree requiring the company to better protect user privacy. The $5 billion penalty is the largest imposed on any company for violating consumers’ privacy – nearly 20 times the largest privacy or data security penalty to date.

Privacy 60
article thumbnail

Reimagined: Building Products with Generative AI

“Reimagined: Building Products with Generative AI” is an extensive guide for integrating generative AI into product strategy and careers featuring over 150 real-world examples, 30 case studies, and 20+ frameworks, and endorsed by over 20 leading AI and product executives, inventors, entrepreneurs, and researchers.

article thumbnail

An introduction to 360 degree threat detection

OpenText Information Management

According to Accenture, the cost of cybercrime to US Financial Services companies rose 40% between 2014 and 2017, on average costing companies over $18 million per year. Add to this much tighter data protection regulations – such as those in the US and Europe – and the need for endpoint security becomes clear. In this … The post An introduction to 360 degree threat detection appeared first on OpenText Blogs.

article thumbnail

Security Training That Keeps Up with Modern Development

Dark Reading

Black Hat USA speakers to discuss what it will take to 'shift knowledge left' to build up a corps of security-savvy software engineers.

article thumbnail

4 steps to becoming a more data-driven organization

Information Management Resources

Organizations must implement effective intelligent data management strategies that help them being able to access the right data at the right time and recover it when it’s lost or damaged.

Access 61
article thumbnail

Senate Report: US Election Security 'Sorely Lacking' in 2016

Dark Reading

Senate Intelligence Committee report released today cites weaknesses, but finds no evidence of vote-tampering.

article thumbnail

How to Migrate From DataStax Enterprise to Instaclustr Managed Apache Cassandra

If you’re considering migrating from DataStax Enterprise (DSE) to open source Apache Cassandra®, our comprehensive guide is tailored for architects, engineers, and IT directors. Whether you’re motivated by cost savings, avoiding vendor lock-in, or embracing the vibrant open-source community, Apache Cassandra offers robust value. Transition seamlessly to Instaclustr Managed Cassandra with our expert insights, ensuring zero downtime during migration.

article thumbnail

Facebook's Ex-Security Chief Details His 'Observatory' for Internet Abuse

WIRED Threat Level

Alex Stamos' Stanford-based project will try to persuade tech firms to offer academics access to massive troves of user data.

article thumbnail

Android Malware 'Triada' Most Active on Telco Networks

Dark Reading

Google in May disclosed that several Android devices had been shipped pre-installed with the RAT.

71
article thumbnail

Facebook to Settle with SEC for $100 Million

Hunton Privacy

In addition to Facebook’s record-breaking Federal Trade Commission penalty and settlement order , on July 24, 2019, the Securities and Exchange Commission announced charges against Facebook for inadequate and misleading disclosures over its privacy practices. Facebook, without admitting or denying the SEC’s allegations, has agreed to the entry of a final judgment ordering a fine of $100 million.

Privacy 50