Sat.Feb 24, 2018 - Fri.Mar 02, 2018

article thumbnail

Leak of 23,000 Private Keys Triggers Security Scramble

Data Breach Today

Digital Certificate Revocation Blame Game: Trustico Swaps Blows With DigiCert Digital certificate vendor Trustico is sparring with DigiCert, which recently took over Symantec's digital certificate business, following a serious security incident. The private keys for at least 23,000 Trustico digital certificates have been compromised, prompting a scramble to protect affected websites.

Security 183
article thumbnail

E-Mail Leaves an Evidence Trail

Schneier on Security

If you're going to commit an illegal act, it's best not to discuss it in e-mail. It's also best to Google tech instructions rather than asking someone else to do it: One new detail from the indictment, however, points to just how unsophisticated Manafort seems to have been. Here's the relevant passage from the indictment. I've bolded the most important bits: Manafort and Gates made numerous false and fraudulent representations to secure the loans.

Paper 131
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

'Living laboratories': the Dutch cities amassing data on oblivious residents

The Guardian Data Protection

In Eindhoven and Utrecht smart tech is tackling traffic, noise and crime. But with privacy laws proving futile and commercial companies in on the act, are the plans as benign as they seem? Stratumseind in Eindhoven is one of the busiest nightlife streets in the Netherlands. On a Saturday night, bars are packed, music blares through the street, laughter and drunken shouting bounces off the walls.

Privacy 111
article thumbnail

Insights about the first three years of the Right To Be Forgotten requests at Google

Elie

The "Right To Be Forgotten" (RTBF) is the landmark European ruling that governs the delisting of personal information from search results. This ruling establishes a right to privacy, whereby individuals can request that search engines delist URLs from across the Internet that contain “inaccurate, inadequate, irrelevant or excessive” information surfaced by queries containing the name of the requester.

Privacy 107
article thumbnail

Get Better Network Graphs & Save Analysts Time

Many organizations today are unlocking the power of their data by using graph databases to feed downstream analytics, enahance visualizations, and more. Yet, when different graph nodes represent the same entity, graphs get messy. Watch this essential video with Senzing CEO Jeff Jonas on how adding entity resolution to a graph database condenses network graphs to improve analytics and save your analysts time.

article thumbnail

Darknet Vendors Sell Counterfeit TLS Certificates

Data Breach Today

Pro Tip: Change TLS Certificates Regularly For Better Data Security Certificate Authorities continue to be tricked into issuing bogus TLS certificates. A study by Recorded Future found that there are at least three underground vendors that can supply fraudulent TLS certificates, which pose serious risks to data security and privacy.

Privacy 183

More Trending

article thumbnail

How to fix the widening cyber security skills gap

IT Governance

The cyber security skills gap has been widening for years – there are simply not enough trained professionals to meet organisations’ growing cyber security needs. As a result, the value of those with the requisite skills is inflated, but they are left in charge of understaffed and poorly equipped defence teams. According to the latest figures, 68% of organisations acknowledge that demand for cyber security staff is high , and there is reportedly a 25 percentage point gap between availability and

article thumbnail

Facebook Doesn't Know How Many People Followed Russians on Instagram

WIRED Threat Level

By leaving Instagram followers off the public record, Columbia researcher Jonathan Albright says Facebook is making the Russian trolls' true audience appear artificially low.

article thumbnail

Equifax Discloses 2.4 Million More Mega-Breach Victims

Data Breach Today

Breach Costs Hit $114 Million, But Data Broker Still Sees Revenues Rise Equifax has identified 2.4 million U.S. consumers whose names and snippets of their driver's license numbers were stolen, adding to one of the worst breaches in history, which resulted in personal data for nearly every U.S. adult being exposed.

article thumbnail

Securing Containers for GDPR Compliance

Thales Cloud Protection & Licensing

Around the world, enterprises are anxious about May 25, 2018, the day enforcement begins for the European Union’s General Data Protection Regulation (GDPR). They have good reason. Perhaps the most comprehensive data privacy standard to date, the GDPR presents a significant challenge for organizations that process the personal data of EU citizens – regardless of where the organization is headquartered or processes the data.

GDPR 82
article thumbnail

Peak Performance: Continuous Testing & Evaluation of LLM-Based Applications

Speaker: Aarushi Kansal, AI Leader & Author and Tony Karrer, Founder & CTO at Aggregage

Software leaders who are building applications based on Large Language Models (LLMs) often find it a challenge to achieve reliability. It’s no surprise given the non-deterministic nature of LLMs. To effectively create reliable LLM-based (often with RAG) applications, extensive testing and evaluation processes are crucial. This often ends up involving meticulous adjustments to prompts.

article thumbnail

Color-coded filing systems: Reduce downtime and increase ROI – Part 1

TAB OnRecord

In 1967, TAB launched CompuColor® labeling products for application in computer punch cards. Forty-five years later, punch cards are computing history, but color-coded filing techniques are still an integral part of effective information management. What is it that allows color-coding to transcend its original purpose and remain popular four decades later?

article thumbnail

How Liberals Amped Up a Parkland Shooting Conspiracy Theory

WIRED Threat Level

A fake story about a Parkland student started on the right, but outrage-tweeting on the left propelled it into the mainstream.

IT 107
article thumbnail

SEC Reportedly Launches Cryptocurrency Probe

Data Breach Today

Report: Dozens of Firms and Advisers Behind Initial Coin Offerings Receive Subpoenas The U.S. Securities and Exchange Commission has reportedly issued dozens of subpoenas and requests for information to technology companies, executives and advisers involved in initial coin offerings. The regulator's new cyber unit investigates ICOs, which attempt to raise funds for cryptocurrency ventures.

Security 145
article thumbnail

Millions of Office 365 Accounts Hit with Password Stealers

Dark Reading

Phishing emails disguised as tax-related alerts aim to trick users into handing attackers their usernames and passwords.

Passwords 103
article thumbnail

How and Why Should You Be Tracking Geopolitical Risk?

Geopolitical risk is now at the top of the agenda for CEOs. But tracking it can be difficult. The world is more interconnected than ever, whether in terms of economics and supply chains or technology and communication. Geopolitically, however, it is becoming increasingly fragmented – threatening the operations, financial well-being, and security of globally connected companies.

article thumbnail

Weekly discussion podcast: Critical Information Infrastructure, Part 5

IT Governance

This week’s extract is taken from Toomas Viira’s book Lessons Learned – Critical Information Infrastructure Protection , which is a vital source of information and thought-provoking insights into potential issues within critical information infrastructure (CII). Episode 5 – Critical Infrastructure: “There is no universal model that suits all countries; there is no universal model that suits all sectors; there is no universal model that suits all service providers.

article thumbnail

How to Turn Off Facebook's Face Recognition Features

WIRED Threat Level

Facebook recently expanded its face recognition features—and you may have opted in without even realizing it.

IT 110
article thumbnail

Data Cache May Contain 2,800 Partly Undiscovered Breaches

Data Breach Today

Organizations Scramble After 80 Million Potentially Breached Records Surface An analysis of a massive 8.8 GB trove of files containing usernames and plaintext passwords suggests hundreds of services may have experienced unreported or undiscovered data breaches. Data breach expert Troy Hunt says the trove of 80 million records appears to contain fresh data.

article thumbnail

Tracking desktop ransomware payments end to end

Elie

Ransomware is a type of malware that encrypts the files of infected hosts and demands payment, often in a crypto-currency such as Bitcoin. In this paper, we create a measurement framework that we use to perform a large-scale, two-year, end-to-end measurement of ransomware payments, victims, and operators. By combining an array of data sources, including ransomware binaries, seed ransom payments, victim telemetry from infections, and a large database of Bitcoin addresses annotated with their owne

article thumbnail

7 Pitfalls for Apache Cassandra in Production

Apache Cassandra is an open-source distributed database that boasts an architecture that delivers high scalability, near 100% availability, and powerful read-and-write performance required for many data-heavy use cases. However, many developers and administrators who are new to this NoSQL database often encounter several challenges that can impact its performance.

article thumbnail

Immigration officials to continue to seek NHS England patient data

The Guardian Data Protection

Ministers reject calls to suspend practice amid fears it is stopping migrants seeking medical help Ministers have rejected a call from MPs to immediately suspend the disclosure of confidential NHS patient data to the Home Office to trace potential immigration offenders despite evidence it is deterring migrants in England from seeking medical help. A joint letter from Home Office and health ministers to the chair of the Commons health select committee discloses that 1,297 requests for non-clinica

IT 78
article thumbnail

A 1.3Tbs DDoS Hit GitHub, the Largest Yet Recorded

WIRED Threat Level

On Wednesday, a 1.3Tbps DDoS attack pummeled GitHub for 15-20 minutes. Here's how it stayed online.

IT 112
article thumbnail

Cryptocurrency Theft: Hackers Repurpose Old Tricks

Data Breach Today

Web Injects, Malware, Phishing and Fake Advertising Used in Attack Arsenal Criminals continue their quest for acquiring cryptocurrencies without having to buy and manage their own mining equipment. They're resorting to attacks aimed at stealing the cryptocurrencies via hacking, phishing, fake advertising and web injection attacks via repurposed banking Trojans.

Mining 133
article thumbnail

The UK and Australian Governments Are Now Monitoring Their Gov Domains on Have I Been Pwned

Troy Hunt

If I'm honest, I'm constantly surprised by the extent of how far Have I Been Pwned (HIBP) is reaching these days. This is a little project I started whilst killing time in a hotel room in late 2013 after thinking "I wonder if people actually know where their data has been exposed?" I built it in part to help people answer that question and in part because my inner geek wanted to build an interesting project on Microsoft's Azure.

article thumbnail

Entity Resolution Checklist: What to Consider When Evaluating Options

Are you trying to decide which entity resolution capabilities you need? It can be confusing to determine which features are most important for your project. And sometimes key features are overlooked. Get the Entity Resolution Evaluation Checklist to make sure you’ve thought of everything to make your project a success! The list was created by Senzing’s team of leading entity resolution experts, based on their real-world experience.

article thumbnail

Combat the increasing ransomware threat by educating employees

IT Governance

A recent Sophos survey of 2,700 IT managers in organisations with 100-5,000 employees around the world, revealed that many businesses are not prepared for ransomware attacks. 54% of those surveyed had experienced an attack within the past year. A further 31% are expected to fall victim in the future. Key findings. 45% of UK organisations experienced a ransomware attack within the past 12 months.

article thumbnail

Chrome's WebUSB Feature Leaves Some Yubikeys Vulnerable to Attack

WIRED Threat Level

While still the best protection against phishing attacks, some Yubikey models are vulnerable after a recent update to Google Chrome.

article thumbnail

IoT Devices: Reducing the Risks

Data Breach Today

Attorney Steven Teppler, who recently wrote a report that addresses risks related to the internet of things, offers insights on risk management steps organizations in all sectors must take as IoT devices proliferate in the enterprise.

IoT 126
article thumbnail

How & Why the Cybersecurity Landscape Is Changing

Dark Reading

A comprehensive new report from Cisco should "scare the pants off" enterprise security leaders.

article thumbnail

Reimagined: Building Products with Generative AI

“Reimagined: Building Products with Generative AI” is an extensive guide for integrating generative AI into product strategy and careers featuring over 150 real-world examples, 30 case studies, and 20+ frameworks, and endorsed by over 20 leading AI and product executives, inventors, entrepreneurs, and researchers.

article thumbnail

ISO 27001 training in Birmingham

IT Governance

Achieving certification to ISO 27001 demonstrates to existing and potential customers that your organisation has defined and put in place best-practice information security processes. ISO 27001 is the only auditable international standard that defines the requirements of an information security management system (ISMS). Implementing an ISO 27001-certified ISMS can help your organisation avoid the penalties and losses associated with data breaches, and comply with legal and regulatory requirement

article thumbnail

Russia's Olympics Hack Was the Country's Latest False Flag Attack

WIRED Threat Level

The Kremlin's hacking misdirection is evolving. And even when those attempts to confuse forensics fail, they still succeed at sowing future doubt.

article thumbnail

Sizing Up the Role of Deception Technology in Healthcare

Data Breach Today

The new generation of deception technology can play an important role in helping healthcare organizations detect malware, including ransomware, but it requires careful implementation to get the most value, says Mitch Parker, CISO at Indiana University Health System.