Posts

Showing posts with the label equifax

Reasons Why the Security Industry is Protecting the Wrong Thing

Image
Article by Paul German, CEO,  Certes Networks   Why is it that the security industry talks about network security, but data breaches? It’s clear that something needs to change, and according to Paul German, CEO, Certes Networks, the change is simple. For too long now, organisations have been focusing on protecting their network, when in fact they should have been protecting their data. Paul outlines three reasons why the security industry has been protecting the wrong thing and what they can do to secure their data as we move into 2021. They’re called data breaches, not network breaches, for a reason Looking back on some of the biggest data breaches the world has ever seen, it’s clear that cyber hackers always seem to be one step ahead of organisations that seemingly have sufficient protection and technology in place. From the  Adobe data breach  way back in 2013 that resulted in 153 million user records stolen, to the  Equifax data breach  in 2017 that exp...

Cyber Security Roundup for July 2019

July was a month of mega data privacy fines. The UK Information Commissioners Office (ICO) announced it intended to fine British Airways £183 million for last September's data breach , where half a million BA customer personal records were compromised. The ICO also announced a £100 million fine for US-based Marriot Hotels after the Hotel chain said 339 million guest personal data records had been compromised by hackers. Those fines were dwarfed on the other side of the pond, with  Facebook agreeing to pay a US Federal Trade Commission (FTC) fine of $5 billion dollars , to put the Cambridge Analytica privacy scandal to bed . And Equifax paid $700 million to FTC to settle their 2017 data breach, which involved the loss of at least 147 million personal records . Big numbers indeed, we are seeing the big stick of the GDPR kicking in within the UK, and the FTC flexing some serious privacy rights protection punishment muscles in the US. All 'food for thought' when performing cy...

Cyber Security Roundup for May 2019

May 2019 was the busiest month of the year for critical security vulnerabilities and patch announcements. The standout was a  Microsoft critical security update for Windows, rated with a CVSS score of 9.8 of 10 . This vulnerability fixes  CVE-2019-0708  aka 'BlueKeep', which if exploited could allow the rapid propagation of malware (i.e. worm) across networked devices, similar to the devastating WannaCry ransomware attacks of 2017 .  Such is the concern at Microsoft, they have released BlueKeep patches for their unsupported versions of Windows (i.e. XP, Visa, Server 2003) , a very rare occurrence. Researchers at Errata Security said they have found almost one million internet-connected systems which are vulnerable  to the BlueKeep bug. A zero-day Microsoft vulnerability was also reported by an individual called 'SandboxEscaper ', which I expect Microsoft will patch as part of their monthly patch cycle in June.  And a past Microsoft vulnerability, CVE-201...

Cyber Security Roundup for March 2019

Image
The potential threat posed by Huawei to the UK national infrastructure continues to be played out. GCHQ called for a ban on Huawei technology within UK critical networks , such as 5G networks, while Three said a Huawei ban would delay the UK 5G rollout , and the EU ignored the US calls to ban Huawei in 5G rollouts , while promoting the  EU Cybersecurity certification scheme to counter the Chinese IT threa t, which is all rather confusing.  Meanwhile,  Microsoft Researchers found an NSA-style Backdoor in Huawei Laptops , which was reported to Huawei by Microsoft, leading to the flaw being patched in January 2019. Is Huawei a Threat to UK National Security? Huawei: The company and the security risks   The assessment of the Chinese state as hostile towards Western nations is key in understanding why Huawei is considered a risk  Should we worry about Huawei?  Why has the UK not blocked Huawei? Why Huawei matters in five charts EU Cybersecurity ...

Cyber Security Roundup for April 2018

The fallout from the F acebook privacy scandal rumbled on throughout April and culminated with the closure of the company at the centre of the scandal, Cambridge Analytica . Overview of Facebook and Cambridge Analytica Facebook's Zuckerberg faces formal summons from MPs Facebook to contact 87 million users affected by data breach Canada data firm AIQ may face legal action in UK Facebook to vet UK political ads for May 2019 local elections Facebook to exclude billions from European privacy laws Ikea was forced to shut down its freelance labour marketplace app and website 'TaskRabbit'  following a 'security incident'. Ikea advised users of TaskRabbit   to change their credentials if they had used them on other sites, suggesting a significant database compromise. TSB bosses came under fire after a botch upgraded to their online banking system , which meant the Spanished owned bank had to shut down their online banking facility, preventing usage by over 5 mi...

Cyber Security Roundup for November 2017

One of the most notable data breaches disclosed this month was by Uber, given the company attempted to cover up the breach by paying off hackers. Over a year ago the transport tech firm was said to have paid £75,000 to two hackers to delete 57 million Uber account records which they had stolen . Uber revealed around 2.7 million of the stolen records were British riders and drivers . As a UK Uber rider, this could mean me, I haven't received any notification of the data breach from Uber as yet.  The stolen information included names, email addresses, and phone numbers. Uber can expect enforcement action from regulators on both sides of the pond, the UK Information Commissioner's Office (ICO) said it had " huge concerns " about the breach and was investigating. Jewson , Cash Converters , and Imgur all reported losing data due to hacks this month, while Equifax has reported suffering significant negative financial losses following their high profile hack of persona...