Global Cyber News Digest

Daily News Digest

Stay current on the global cyber threat landscape and industry developments with CCOE’s daily digest and library of cybersecurity news and articles.

  • Martin Luther King Jr. Day: How America is honoring the civil-rights hero
    • All over the country, scores of people will gather to honor one of America's most prolific civil rights heroes, Dr. Martin Luther King Jr., on his birthday.
    • King was assassinated by James Earl Ray on April 4, 1968, in Memphis, Tenn.

      FOX News - Vandana Rambaran | January 19, 2020
    foxnews.comJanuary 19, 2020
  • PH wary of Chinese state-backed hackers
    • The Philippine government is mindful of the security risks brought about by increased Chinese control of its infrastructure and the reported Chinese state-backed hackers' cyber attacks and other threats around the world.
    • The Philippine military's deal with Dito Telecommunity, allowing the China-backed telco to build cell sites in its camps and bases, raises the risk of China mining Filipinos' data--independent experts said.

      Manila Standard | January 19, 2020
    manilastandard.netJanuary 19, 2020
  • Microsoft Warns of Unpatched IE Browser Zero-Day That's Under Active Attacks
    • Internet Explorer is dead, but not the mess it left behind.
    • A remote attacker can execute arbitrary code on targeted computers and take full control over them just by convincing victims into opening a maliciously crafted web page on the vulnerable Microsoft browser.

      The Hacker News - Mohit Kumar | January 18, 2020
    thehackernews.comJanuary 18, 2020
  • United Nations hit by major phishing attack
    • The United Nations has been hit by a targeted cyberattack that uses one of the world's most notorious malware strains.
    • Criminals used the Emotet malware in order to launch a phishing campaign aimed at stealing login details for UN staff and officials alike.

      TechRadar.pro - Mike Moore | January 15, 2020
    techradar.comJanuary 15, 2020
  • 49 Million User Records Leaked From US Data Broker LimeLeads · Experts Reactions
    • Data from an exposed LimeLeads Elasticsearch server has ended up on a hacking forum, being sold by a well-known individual on underground hacking forums named Omnichorus, who has build a reputation for sharing and selling hacked and stolen data.

      InformationSecurityBuzzNews -Security Experts | January 15, 2020
    informationsecuritybuzz.comJanuary 15, 2020
  • Study says Grindr, OkCupid, and Tinder breach GDPR
    • Dating apps Grindr, OkCupid, and Tinder are allegedly spreading user information like sexual preferences, behavioural data, and precise location to advertising companies in ways that may violate privacy laws, according to a study conducted by the Norwegian Consumer Council (NCC).
    • The study found that Grindr was among the apps with the most glaring privacy issues as it failed to do the following: Share clear information regarding the way it shares data with non-service provider third parties; share clear information about how user data is used for targeted ads; and provide in-app options to reduce data sharing with third parties.

      ZDNet - Campbell Kwan | January 15, 2020
    zdnet.comJanuary 15, 2020
  • How Should Companies Investigate Security Incidents
    • As of January 1, 2020, California became the first state to permit residents whose personal information is exposed in a data breach to seek statutory damages between $100-$750 per incident, even in the absence of any actual harm, with the passage of the California Consumer Privacy Act ("CCPA").
    • A successful defense will depend on the ability of the breached business to establish that it implemented and maintained reasonable security procedures and practices appropriate to the nature of the personal information held.

      Lexology - Jena M. Valdetero and Linda C. Hsu | January 14, 2020
    lexology.comJanuary 14, 2020
  • Patch Tuesday, January 2020 Edition
    • Microsoft today released updates to plug 50 security holes in various flavors of Windows and related software.
    • The patch batch includes a fix for a flaw in Windows 10 and server equivalents of this operating system that prompted an unprecedented public warning from the U.S. National Security Agency.
    • An advisory (PDF) released today by the NSA says the flaw may have far more wide-ranging security implications, noting that the "exploitation of the vulnerability allows attackers to defeat trusted network connections and deliver executable code while appearing as legitimately trusted entities."

      KrebsonSecurity | January 14, 2020
    krebsonsecurity.comJanuary 14, 2020
  • Make Data Safe Again: How to Tackle Dangerous Hackers
    • While protecting the integrity and security of our political system is undoubtedly extremely important, these incidents are interestingly few and far between; it is like worrying about a shark attack every time you dip your toe into water--in the real world, you are far likelier to be harmed in a car crash.
    • In the cybersecurity world, the equivalent of a car crash is an economic cyber intrusion.

      The National Interest - Caspian Tavallali | January 14, 2020
    nationalinterest.orgJanuary 14, 2020
  • 34% of data breaches are inside jobs
    • Who has the most access to a company's secure and sensitive data?
    • In most cases, it's not a teenage computer hacker from Russia but an employee on the payroll.
    • In 2019, Verizon's annual Data Breach Investigations Report found that more than one-third of all data breaches that occurred that year (34 percent) were the result of "insider threat actors."

      BetaNews - Michael Klazema | January 14, 2020
    betanews.comJanuary 14, 2020