Global Cyber News Digest

Daily News Digest

Stay current on the global cyber threat landscape and industry developments with CCOE’s daily digest and library of cybersecurity news and articles.

  • Hackers Exploit Known VA Cybersecurity Weaknesses In Massive Data Breach

    • The Department of Veterans Affairs admitted by press release that 46,000 veterans were victims of an agency data breach while withholding details that fired up some in Congress.
    • The news preceded a curiously timed GAO report reminding everyone and their mom that VA still has not addressed “persistent” IT problems exposing veterans to risk.
    • There is no significant penalty for data breaches by US government agencies right now.
    | September 21, 2020
    hak-iq.us20.list-manage.comSeptember 21, 2020
  • The Real Cost of a Data Breach for Your Brand (and How to Best Protect Yourself)

    • A data breach can be a backbreaker for any brand. There’s the immediate scramble to stop the bleeding, but well past the initial clean-up, the ripple effects can cripple a company for years.
    • Being proactive against this threat is pivotal to any brand’s survival in the 21st century.
    • Data has become a valuable currency in itself, and just like the money it represents, it requires its own version of an alarm system before would-be robbers reach the vault.
    • By being aware of the risks and fortifying your brand’s defenses well before they are tested, you can avoid or endure a data breach without it being the end of your brand.
    - Tom Popomaronis | September 21, 2020
    hak-iq.us20.list-manage.comSeptember 21, 2020
  • Activision Accounts Hacked? 500,000 Call Of Duty Players Could Be Affected

    • According to reports, more than 500,000 Activision accounts may have been hacked with login data being compromised.
    • The credentials to access these accounts are, Dexerto said, being leaked publicly, and account details changed to prevent easy recovery by the rightful owners.
    • Activision accounts are mostly used by players of the hugely popular Call of Duty franchise.
    • You should also activate two-factor authentication (2FA) if you hadn't before. However, it appears that this isn't an option on Activision accounts.
    - Davey Winder | September 21, 2020
    hak-iq.us20.list-manage.comSeptember 21, 2020
  • University of Tasmania IT bungle leads to mass student data breach

    • Nearly 20,000 University of Tasmania (UTAS) students have had their personal information exposed to the entire campus after a major IT bungle.
    • The mistake was blamed on security settings on shared files which were "unintentionally configured incorrectly" which had "made the information visible and accessible to unauthorised users".
    • UTAS said the data that was breached "is used to inform the ways the university supports students in their studies".
    - Mark Saunokonoko | September 21, 2020
    hak-iq.us20.list-manage.comSeptember 21, 2020
  • Iranian Hackers Can Now Beat Encrypted Apps, Researchers Say

    • Iranian hackers, most likely employees or affiliates of the government, have been running a vast cyberespionage operation equipped with surveillance tools that can outsmart encrypted messaging systems — a capability Iran was not previously known to possess.
    • The hackers have successfully infiltrated what were thought to be secure mobile phones and computers belonging to the targets, overcoming obstacles created by encrypted applications such as Telegram and even gaining access to information on WhatsApp.
    - Ronen Bergman and Farnzaz Fassihi | September 18, 2020
    hak-iq.us20.list-manage.comSeptember 18, 2020
  • Dunkin' Data Breach Settlement Paves the Way for More Suits

    • Under the New York settlement with Dunkin' Brands, which is the franchiser of 12,900 Dunkin' outlets and 8,000 Baskin-Robbins stores worldwide, the company must refund money to about 20,000 New York customers affected by a 2015 data breach and also pay $650,000 in fines.
    • The settlement requires Dunkin' to reset the password on any New York customer cards registered during the affected period and notify customers who are eligible for a refund for any fraudulent activity on their card resulting from the data breach.
    • Dunkin' must also maintain reasonable safeguards to protect against credential stuffing attacks.
    - Doug Olenick | September 17, 2020
    hak-iq.us20.list-manage.comSeptember 17, 2020
  • Chinese Antivirus Firm Was Part of APT41 ‘Supply Chain’ Attack

    • The U.S. Justice Department this week indicted seven Chinese nationals for a decade-long hacking spree that targeted more than 100 high-tech and online gaming companies.
    • The government alleges the men used malware-laced phishing emails and “supply chain” attacks to steal data from companies and their customers.
    • One of the alleged hackers was first profiled here in 2012 as the owner of a Chinese antivirus firm.
    • After the indictments were filed prosecutors said they obtained warrants to seize websites, domains and servers associated with the group’s operations, effectively shutting them down and hindering their operations.
    - Brian Krebs | September 17, 2020
    hak-iq.us20.list-manage.comSeptember 17, 2020
  • Cyber attacks threaten universities restarting in the UK

    • The UK’s cybersecurity agency NCSC has issued a warning to universities over the likelihood of cyberattacks as a new term starts
    • The alert follows a speight of ransomware attacks on top universities in the UK, US, and Canada
    • Attackers could leverage phishing scams, impersonating university officials
    - Mark Jones | September 17, 2020
    hak-iq.us20.list-manage.comSeptember 17, 2020
  • You’re not as smart as you think you are: Phishing with Covid-19 as bait

    • Targeting people, instead of systems, is the fastest and most results-driven method of hacking. The reason for this is due to the Dunning-Kruger effect, a cognitive bias where people overestimate their knowledge or ability in a certain area.
    • In the case of network security, people overestimate their ability to gauge risky behavior online.
    • COVID-19 is a top-of-mind concern that sets the stage for an emotional response. It depends on the individual, but the odds of an emotional response are quite high.
    - Phil Trainor | September 16, 2020
    hak-iq.us20.list-manage.comSeptember 16, 2020
  • Two Russians Charged in $17M Cryptocurrency Phishing Spree

    • The Justice Department unsealed indictments against Russian nationals Danil Potekhin and Dmitirii Karasavidi, alleging the duo was responsible for a sophisticated phishing and money laundering campaign that resulted in the theft of $16.8 million in cryptocurrencies and fiat money from victims.
    • Separately, the U.S. Treasury Department announced economic sanctions against Potekhin and Karasavidi, effectively freezing all property and interests of these persons (subject to U.S. jurisdiction) and making it a crime to transact with them.
    | September 16, 2020
    hak-iq.us20.list-manage.comSeptember 16, 2020