What to do when receiving unprompted MFA OTP codes.

Receiving an unprompted one-time passcode (OTP) sent as an email or text should be a cause for concern as it likely means your credentials have been stolen. One of the initial components of a cyberattack is the theft of legitimate credentials to corporate networks and online services. These credentials can be stolen in phishing attacks,Continue reading “What to do when receiving unprompted MFA OTP codes.”

New DHS guidance for faith-based communities advises online protection for physical security

DHS Secretary Alejandro N. Mayorkas says the country is in a “heightened threat environment” and that the agency was acting accordingly to protect houses of worship. Many faith-based institutions across the country are preparing for a busy holiday season, and the Department of Homeland Security has issued guidance intended to help with security—and no, leavingContinue reading “New DHS guidance for faith-based communities advises online protection for physical security”

CIA urges ‘secure by design’ elimination of factory-default passwords.

The agency recommended physical access requirements for initial setup and time-limited credentials. CISA says default passwords like “1111” need at least a few more special characters. In an advisory issued December 15, the agency offered “secure by design” recommendations for tech manufacturers, especially those making programmable logic controllers (PLCs)—devices that cyber attackers have targeted to compromise wasteContinue reading “CIA urges ‘secure by design’ elimination of factory-default passwords.”

Cloud engineer wreaks havoc on bank network after getting fired.

Now he’s got two years behind bars to think about his bad choices. An ex-First Republic Bank cloud engineer was sentenced to two years in prison for causing more than $220,000 in damage to his former employer’s computer network after allegedly using his company-issued laptop to watch pornography. Miklos Daniel Brody, 38, of San Francisco,Continue reading “Cloud engineer wreaks havoc on bank network after getting fired.”

FBI Issues Guidance for Delaying SEC-Required Data Breach Disclosure.

The FBI has issued guidance for SEC data breach reporting requirements and how disclosures can be delayed. The FBI has issued guidance regarding the data breach reporting requirements of the Securities and Exchange Commission (SEC), providing useful information on how disclosures can be delayed. The SEC announced in late July that it had adopted new cybersecurityContinue reading “FBI Issues Guidance for Delaying SEC-Required Data Breach Disclosure.”

BazarCall attacks abuse Google Forms to legitimize phishing emails.

A new wave of BazarCall attacks uses Google Forms to generate and send payment receipts to victims, attempting to make the phishing attempt appear more legitimate. BazarCall, first documented in 2021, is a phishing attack utilizing an email resembling a payment notification or subscription confirmation to security software, computer support, streaming platforms, and other well-known brands. TheseContinue reading “BazarCall attacks abuse Google Forms to legitimize phishing emails.”

Apache has warned customers of a critical remote code execution (RCE) vulnerability in its popular Struts 2 framework.

Apache Struts 2 is an open-source web application framework for developing Java EE web applications. The new vulnerability, CVE-2023-50164, has been given a maximum severity rating and affects Struts 2.0.0-2.3.37 (EOL), Struts 2.5.0-2.5.32, and Struts 6.0.0-6.3.0. “An attacker can manipulate file upload parameters to enable path traversal and under some circumstances this can lead toContinue reading “Apache has warned customers of a critical remote code execution (RCE) vulnerability in its popular Struts 2 framework.”

10,000 people’s data stolen in genetic testing company Asper Biogene leak.

Personal and health data belonging to approximately 10,000 people has been illegally downloaded from the Tartu-based genetic testing company Asper Biogene’s database, the State Prosecutor’s Office said on Thursday. Those affected are in the process of being notified. A criminal investigation has been launched by the Southern Prefectural Criminal Bureau which is in the processContinue reading “10,000 people’s data stolen in genetic testing company Asper Biogene leak.”

Nissan Restoring Systems After Cyberattack.

Nissan Oceania says it has been working on restoring its systems after falling victim to a cyberattack. Japanese car manufacturer Nissan has disclosed a cyberattack impacting the internal systems at Nissan Oceania. A regional division of the multinational carmaker, Nissan Oceania is responsible for the company’s operations in Australia and New Zealand. Nissan Oceania disclosedContinue reading “Nissan Restoring Systems After Cyberattack.”

Report: 2.6 billion personal records compromised by data breaches in past two years — underscoring need for end‑to‑end encryption.

An Apple study shows that threats to consumer data stored in the cloud have grown dramatically since the last report was published in December 2022. Earlier this week Apple published an independent study conducted by Massachusetts Institute of Technology professor Dr. Stuart Madnick that found clear and compelling proof that data breaches have become anContinue reading “Report: 2.6 billion personal records compromised by data breaches in past two years — underscoring need for end‑to‑end encryption.”