Posts

Showing posts with the label Apache

Cyber Security Roundup for November 2018

One of the largest data breaches in history was announced by Marriott Hotels at the end of November. A hack was said to have compromised up to a mind-blowing "half a Billion" hotel guests' personal information over a four year period.  See my post,  Marriott Hotels 4 Year Hack Impacts Half a Billion Guests  for the full details.  The Radisson Hotel Group also disclosed its Rewards programme suffer a data compromise . Radisson said hackers had gained access to a database holding member's name, address, email address, and in some cases, company name, phone number, and Radisson Rewards member number. Vision Direct reported a website compromise , which impacted users of their website between 3rd and 8th November, some 16,300 people were said to be at risk  A   fake Google Analytics script  was placed within its website code by hackers.  Eurostar customers were notified by email to reset their passwords following presumably successful a utom...

Cyber Security Roundup for October 2017

State-orchestrated cyber attacks have dominated the media headlines in October, with rogue state North Korea and its alleged 6,800 strong cyber force blamed for several cyber attacks. International intelligence scholars believe the North Korean leadership are using cyber warfare to up the political ante with their ongoing dispute with the United States. The North Koreans, as well as terrible security practices, were directly blamed by the UK National Audit Office for the recent  NHS WannaCry attack  ( despite North Korea denying it ). North Korea was also reported to be implicated in the  stealing US War Plans from South Korea , and for a spear phishing campaign against the US Power Grid . The possible Russian manipulation of the US election with cyber attacks and rogue social media campaigns is still a story not going away, while the Chinese are alleged to be behind the data theft of  Australian F-35 fighter jet, in what is described as an 'extensive' Cyberattack ....

Cyber Security Roundup for September 2017

A massive data breach at Equifax dominated the UK media finance headlines this month, after 143 million customer records were compromised by a cyber-attack, 400,000 of which were UK customer accounts. Hackers took advantage of Equifax’s negligence in not applying security updates to servers. The data breach has already cost the CEO, CIO and CISO their jobs. In the UK Equifax faces investigations and the prospect of significant fines by both the Financial Conduct Authority and the Information Commissioner's Office over the loss of UK customer financial and personal data respectively. Hackers stole a quarter of a million Deloitte client emails , follow the breach Deloitte was criticised by security professional for not adopting two-factor authentication to protect the email data which they hosted in Microsoft’s Azure cloud service. September was an extremely busy month for security updates, with major patches releases by Microsoft , Adobe , Apache , Cisco and Apple to fix a...

Cyber Security Roundup for March 2017

Security researchers found there were able to find numerous sensitive documents by searching Microsoft’s Office 365 documents made publically accessible through the Docs.com website. Documents found included business confidential information, passwords and personal data. The issue was not caused by any security vulnerability in O365, but by its use rs misconfiguring or not understand the access permissions on their Microsoft O365 file storage, inadvertently permitting public access to t heir confidential data.  Businesses and users need to meet cloud services halfway when it comes to security, that starts obtaining a clear understanding of what security the cloud service does and does not do, so ensure your security homework is done before adopting the cloud. A patch for a critical vulnerability in Apache (Server) Struts was released this month, the vulnerability, which is being actively exploited by cyber criminals in ransomware attacks, allows the remote execution of comma...