Microsoft uncovered the SolarWinds crooks using mass-mail service Constant Contact and posing as a U.S.-based development organization to deliver malicious URLs to more than 150 organizations.
Threatpost
Security
Biden’s Cybersecurity Executive Order Puts Emphasis on the Wrong Issues
David Wolpoff, CTO at Randori, argues that the call for rapid cloud transition Is a dangerous proposition: “Mistakes will be made, creating opportunities for our adversaries.
Threatpost
Making The Business Case For Cyber Security
Gone are the halcyon days of the cyber security vision being to simply fix technical problems. Enabling the business is now the mission. Benchmarking against your peers is a great way to understand ho…
Is Data Privacy Evolving Into Data Rights? Checking-In On Data Rights Management…
As a result of data laws such as GDPR, processing data subject access requests (DSAR) have surged. In fact, in the year following the implementation of GDPR, customer data solutions provider Segment e…
Threat Actor ‘Agrius’ Emerges to Launch Wiper Attacks Against Israeli Targets
The group is using ransomware intended to make its espionage and destruction efforts appear financially motivated.
Threatpost
What The Cyber Security Executive Order Means for CISOs
One of the Order’s goals is to modernize federal government cybersecurity by unifying intelligence among various agencies through information sharing. The Order also directs the federal government to…
100M Android Users Hit By Rampant Cloud Leaks
Several mobile apps, some with 10 million downloads, have opened up personal data of users to the public internet – and most aren’t fixed.
Threatpost
Email Campaign Spreads StrRAT Fake-Ransomware RAT
Microsoft Security discovered malicious PDFs that download Java-based StrRAT, which can steal credentials and change file names but doesn’t actually encrypt.
Threatpost
WP Statistics Bug Allows Attackers to Lift Data from WordPress Sites
The plugin, installed on hundreds of thousands of sites, allows anyone to filch database info without having to be logged in.
Threatpost

