Tag: data
-
Columbus says ransomware gang stole personal data of 500,000 Ohio residents
First seen on techcrunch.com Jump to article: techcrunch.com/2024/11/04/columbus-says-ransomware-gang-stole-personal-data-of-500000-ohio-residents/
-
Keyboard robbers steal 171K customers’ data from AnnieMac mortgage house
Names and social security numbers of folks looking for the biggest loan of their lives exposed First seen on theregister.com Jump to article: www.theregister.com/2024/11/15/anniemac_data_breach/
-
Daniel Stori’s Turnoff.US: ‘I Love Windows Powershell’
via the inimitable Daniel Stori at Turnoff.US! Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2024/11/daniel-storis-turnoff-us-i-love-windows-powershell/
-
8.8 Rated PostgreSQL Vulnerability Puts Databases at Risk
Cybersecurity researchers at Varonis have identified a serious security vulnerability in PostgreSQL that could lead to data breaches… First seen on hackread.com Jump to article: hackread.com/postgresql-vulnerability-puts-databases-at-risk/
-
Microsoft Power Pages Misconfigurations Expose Millions of Records Globally
SaaS Security firm AppOmni has identified misconfigurations in Microsoft Power Pages that can lead to severe data breaches…. First seen on hackread.com Jump to article: hackread.com/microsoft-power-pages-misconfigurations-data-leak/
-
Good Essay on the History of Bad Password Policies
Stuart Schechter makes some good points on the history of bad password policies: Morris and Thompson’s work brought much-needed data to highlight a problem that lots of people suspected was bad, but that had not been studied scientifically. Their work was a big step forward, if not for two mistakes that would impede future progress…
-
How to Mask Sensitive Data in Files, from CSV to JSON
Tags: dataTonic’s file connector is a quick and easy way to get de-identified data to power your development. Simply upload data in files (such as CSV) to detect and mask sensitive data, and then generate new output files for safe, fast use. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/11/how-to-mask-sensitive-data-in-files-from-csv-to-json/
-
Generating High Quality Test Data for MySQL Through De-identification and Synthesis
As one of the most popular open-source databases, widely used for web applications, MySQL is no stranger to PII and sensitive data. At the same time, its users need production-like data for effective development and testing. Here are the challenges involved in anonymizing MySQL databases and solutions for tackling them. First seen on securityboulevard.com Jump…
-
The Ultimate Guide to Data Masking in SQL Server
If you’re exploring data masking in SQL Server, how can you decide which SQL masking method is right for you? Learn all about your options here. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/11/the-ultimate-guide-to-data-masking-in-sql-server/
-
Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia
A Vietnamese-speaking threat actor has been linked to an information-stealing campaign targeting government and education entities in Europe and Asia with a new Python-based malware called PXA Stealer.The malware “targets victims’ sensitive information, including credentials for various online accounts, VPN and FTP clients, financial information, browser cookies, and data from gaming software,” First seen on…
-
South Korea Fines Meta $15.67M for Illegally Sharing Sensitive User Data with Advertisers
Meta has been fined 21.62 billion won ($15.67 million) by South Korea’s data privacy watchdog for illegally collecting sensitive personal information … First seen on thehackernews.com Jump to article: thehackernews.com/2024/11/south-korea-fines-meta-1567m-for.html
-
Chinese SilkSpecter Hackers Attacking Black Friday Shoppers
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers in Europe and the USA during the Black Friday shopping season. The campaign leveraged the legitimate payment processor Stripe to steal victims’ Cardholder Data (CHD) and Sensitive Authentication Data (SAD) while allowing legitimate transactions to proceed. The threat actor used…
-
Research Highlights SHA256 Password Security Strengths and Risks
A new study by Specops Software explores the resilience of SHA256, a commonly used cryptographic hashing algorithm, against modern password-cracking techniques. The findings emphasize the algorithm’s effectiveness in protecting data, especially when combined with strong, complex passwords. However, the research also highlights vulnerabilities when using short or simple passwords, even with this robust technology. SHA256,…
-
Ransomware Groups Use Cloud Services For Data Exfiltration
SentinelOne described some of ransomware groups’ favorite techniques for targeting cloud services First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-groups-cloud-services/
-
Microsoft Power Pages misconfigurations exposing sensitive data
NHS supplier that leaked employee info fell victim to fiddly access controls that can leave databases dangling online First seen on theregister.com Jump to article: www.theregister.com/2024/11/15/microsoft_power_pages_misconfigurations/
-
Why Open-Source CIAM Solutions Are Essential for Data Security and Privacy
Businesses face mounting cyber threats and data breaches from third-party vendors. Open-source CIAM solutions offer a secure, transparent alternative for customer identity management. Discover how these solutions provide enhanced security, complete data control, and cost-effective scalability. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/11/why-open-source-ciam-solutions-are-essential-for-data-security-and-privacy/
-
Data aggregator breach exposes 122M individuals’ info
First seen on scworld.com Jump to article: www.scworld.com/brief/data-aggregator-breach-exposes-122m-individuals-info
-
Chinese targeting of US telecoms involved extensive data compromise
First seen on scworld.com Jump to article: www.scworld.com/brief/chinese-targeting-of-us-telecoms-involved-extensive-data-compromise
-
Blinded by Silence
Tags: access, antivirus, attack, backdoor, breach, control, credentials, crowdstrike, cybersecurity, data, defense, detection, edr, endpoint, exploit, extortion, firewall, github, malicious, malware, microsoft, mitre, monitoring, network, open-source, phone, ransomware, risk, service, siem, sophos, threat, tool, update, vulnerability, windowsBlinded by Silence: How Attackers Disable EDR Overview Endpoint Detection and Response systems (EDRs) are an essential part of modern cybersecurity strategies. EDR solutions gather and analyze data from endpoints to identify suspicious activities and provide real-time threat visibility. This allows security teams to respond quickly to incidents, investigate threats thoroughly, and mitigate the impact of…
-
Major cyber attacks and data breaches of 2024
As 2024 draws to a close, the cybersecurity landscape continues to evolve, marked by both familiar adversaries and emerging threats with newer technologies and improved tactics. Rather than merely cataloguing breaches, we look into the anatomy of significant cyber attacks, associated vulnerabilities that led to such events, and relevant controls. We’ve chronicled key developments month……
-
Microsoft Power Pages: Data Exposure Reviewed
Learn about a data exposure risk in Microsoft Power Pages due to misconfigured access controls, highlighting the need for better security and monitoring. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/11/microsoft-power-pages-data-exposure-reviewed/
-
NISRichtlinie: G DATA sieht Fehleinschätzung bei Mehrheit der Angestellten in Deutschland
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/nis-2-richtlinie-g-data-warnung-fehleinschaetzung-mehrheit-angestellte-deutschland
-
Does the GDPR Apply to American Organizations?
GDPR scope, applicability, and key requirements Does the EU GDPR (General Data Protection Regulation) apply in the US? Yes, if your organization offers goods or services to, or monitors the behavior of, EU residents, irrespective of their citizenship. Equally, the EU GDPR doesn’t apply to US residents or customers, even if they’re EU citizens. The…
-
Hacker gets 10 years in prison for extorting US healthcare provider
Robert Purbeck, a 45-year-old man from Idaho, has been sentenced to ten years in prison for hacking at least 19 organizations in the United States, stealing the personal data of more than 132,000 people, and multiple extortion attempts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/legal/hacker-gets-10-years-in-prison-for-extorting-us-healthcare-provider/
-
Cloud Ransomware Flexes Fresh Scripts Against Web Apps
Cloud service providers are getting better at protecting data, pushing adversaries to develop new cloud ransomware scripts to target PHP applications, a new report says. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/cloud-ransomware-scripts-web-applications

