Public data access will lead to breaches down the line – iTWire

Public data access will lead to breaches down the line
iTWire
Questions should, however, be raised about the crazy push to put public data on the Internet, especially in view of the increasing reports about data breaches, all at websites which were thought to be safe and secure beyond a doubt. Having data at one

and more »

data breach – Google News

Backdoor built in to widely used tax app seeded last week’s NotPetya outbreak

Enlarge (credit: National Police of Ukraine)

The third-party software updater used to seed last week’s NotPetya worm that shut down computers around the world was compromised more than a month before the outbreak. This is yet another sign the attack was carefully planned and executed.

Researchers from antivirus provider Eset, in a blog post published Tuesday, said the malware was spread through a legitimate update module of M.E.Doc, a tax-accounting application that’s widely used in Ukraine. The report echoed findings reported earlier by Microsoft, Kaspersky Lab, Cisco Systems, and Bitdefender. Eset said a “stealthy and cunning backdoor” used to spread the worm probably required access the M.E.Doc source code. What’s more, Eset said the underlying backdoored ZvitPublishedObjects.dll file was first pushed to M.E.Doc users on May 15, six weeks before the NotPetya outbreak.

“As our analysis shows, this is a thoroughly well-planned and well-executed operation,” Anton Cherepanov, senior malware researcher for Eset, wrote. “We assume that the attackers had access to the M.E.Doc application source code. They had time to learn the code and incorporate a very stealthy and cunning backdoor. The size of the full M.E.Doc installation is about 1.5GB, and we have no way at this time to verify that there are no other injected backdoors.”

Read 7 remaining paragraphs | Comments

Technology Lab – Ars Technica

Cybersecurity: The cold war online – Nature.com


Nature.com

Cybersecurity: The cold war online
Nature.com
It does not mention the hacking group The Shadow Brokers, which acquired stolen intelligence tools from the US National Security Agency (NSA) in 2016; the global WannaCry ransomware episode in May this year; or the new Chinese cybersecurity law that …

China hackers – read more

Medicare breach raises concerns about the Australian Government’s grip on personal data – Techly


Techly

Medicare breach raises concerns about the Australian Government's grip on personal data
Techly
A data breach allowing the Medicare number and associated personal deets of any Aussie to be purchased for about $ 30 worth of bitcoin raises serious concerns about the government's ability to protect public data. News of the breach broke on Tuesday, …
The Medicare machine: patient details of 'any Australian' for sale on darknetThe Guardian
What is the dark net, and how will it shape the future of the digital age? – ABC News (Australian Broadcasting …ABC

all 72 news articles »

data breach – Google News