Tag Archive for: ‘Bad

How bad is the hack that targeted U.S. agencies? | Business News


Its apparent monthslong timeline gave the hackers ample time to extract information from a lot of different targets. Buchanan compared its magnitude to the 2015 Chinese hack of the U.S. Office of Personnel Management, in which the records of 22 million federal employees and government job applicants were stolen.

FireEye executive Charles Carmakal said the company was aware of “dozens of incredibly high-value targets” compromised” by the hackers and was helping “a number of organizations respond to their intrusions.” He would not name any, and said he expected many more to learn in coming days that they, too, were infiltrated.

SolarWinds, of Austin, Texas, provides network-monitoring and other technical services to hundreds of thousands of organizations around the world, including most Fortune 500 companies and government agencies in North America, Europe, Asia and the Middle East.

Its compromised product, called Orion, accounts for nearly half SolarWinds’ annual revenue. Its centralized monitoring looks for problems in an organization’s computer networks, which means that breaking in gave the attackers a “God-view” of those networks.

SolarWinds said in a financial filing that it sent an advisory to about 33,000 of its Orion customers that might have been affected, though it estimated a smaller number of customers — fewer than 18,000 — had actually installed the compromised product update earlier this year.

Source…

Update iOS Right Now to Fix Some Bad Security Bugs


Congratulations, the week that somehow lasted four months is finally over. At the time of writing this post, the Associated Press still hadn’t called a winner in the United States presidential election. (Donald Trump tried to declare victory early Wednesday morning, but it doesn’t work like that. At all.) While you wait, let’s get you caught up some security news you might have missed while you were watching maps change color on cable news.

Earlier this week, the cryptocurrency had a mystery on its hands when someone emptied a billion dollars from a bitcoin wallet that had sat untouched for years. (Yes, billion.) The sleuthing was short-lived; it turned out that the IRS had tracked down the wallet’s owner after establishing that so-called Individual X had amassed the trove in the first place by hacking the Silk Road seven years ago. It’s the biggest cryptocurrency seizure in US history, and it’s not even close. Law enforcement also shut down a West Virginia man who was allegedly selling 3D-printed machine gun components—barely disguised as wall hangers—to so-called Boogaloo Boys extremists.

Some privacy strides were made this week in various corners. Zoom has finally added real end-to-end encryption, so we walked through how to turn it on and what you have to give up to do so. WhatsApp added disappearing messages, although with less flexibility than other encrypted platforms give you. And while the presidential race remains in doubt, privacy-friendly ballot initiatives comfortably passed in both Michigan and California.

To round out the election news, we took a look at how smoothly Election Day itself went, and how you can thank years of overdue investment and smart decisions for it. We also enjoyed this livestream of ballot-counting in Philadelphia—and explained how every step of the process works.

And there’s more! Every Saturday we round up the security and privacy stories that we didn’t break or report on in depth but think you should know about. Click on the headlines to read them, and stay safe out there.

Apple released its latest iOS update this week, and while the new emojis it comes with are exciting, you’ll also want it to fix a raft of security issues for iPhone and…

Source…

‘Bad Policy and Bad Politics’: Kamala Harris Accused of Hijacking Medicare for All Label to Push More Industry-Friendly Plan – Common Dreams

‘Bad Policy and Bad Politics’: Kamala Harris Accused of Hijacking Medicare for All Label to Push More Industry-Friendly Plan  Common Dreams

Single-payer advocates on Monday accused Sen. Kamala Harris of hijacking the Medicare for All label to push an alternative that would fail to fundamentally …

“HTTPS hijacking” – read more

Top UK Official: Huawei Is ‘Bad Security’

A top UK government cyber-official has called out the telecom supplier, long suspected to use its infrastructure sales as a base for industrial espionage.
Mobile Security – Threatpost