News
Managing IT and business issues
-
August 07, 2023
07
Aug'23
Microsoft fixes Azure flaw that was subject of researcher criticism
Microsoft has confirmed a potentially-dangerous flaw in the Azure platform has now been fully fixed, and moved to reassure customers that despite criticism it is committed to responsible disclosure and timely fixes
-
August 07, 2023
07
Aug'23
Rise in fraudsters spoofing the websites of leading UK banks
Despite safeguards to protect customers from scams, UK retail banks are still seeing high volumes of fake phishing websites exploiting their brands, and the problem seems to be increasing in scope and scale
-
August 04, 2023
04
Aug'23
SAP called out by German user group for Rise U-turn
German SAP user group Deutschsprachige SAP-Anwendergruppe calls on SAP for clarity around on-premise S/4Hana product enhancements
-
August 04, 2023
04
Aug'23
Log4Shell, ProxyShell still among most widely exploited flaws
Statistics released by the collective Five Eyes cyber agencies reveals insight into the most exploited vulnerabilities of 2022, and unsurprisingly there are some old ‘friends’ on the list
-
August 04, 2023
04
Aug'23
Biden’s SBOM mandate a ‘shot heard around the world’, report says
Two years and three months after Joe Biden mandated new standards in supply chain security, over 40% of UK respondents to a survey say they have implemented new SBOM policies in direct response
-
August 03, 2023
03
Aug'23
Scottish NHS trust ducks fine after staff shared patient data via WhatsApp
NHS Lanarkshire has been issued a formal reprimand by the ICO after staff members used WhatsApp to share patients’ personal data with one another
-
August 03, 2023
03
Aug'23
Microsoft attacked over ‘grossly irresponsible’ security practice
The CEO of Tenable has launched a scathing attack on Microsoft, asserting that the organisation is deliberately keeping its Azure cloud customers in the dark about dangerous vulnerabilities and accusing it of a culture of ‘toxic obfuscation’
-
August 02, 2023
02
Aug'23
Ivanti MDM users told to patch against two dangerous flaws
Users of Ivanti’s mobile device management platform have been warned to act now to patch two vulnerabilities that were chained by a threat actor in a series of cyber attacks on the Norwegian government
-
July 28, 2023
28
Jul'23
Lancaster Uni lends cyber support to nuclear decommissioning body
Lancaster University’s cyber team has joined with the Nuclear Decommissioning Authority to help support and protect its 300-year mission, while enhancing its own capabilities in the process
-
July 28, 2023
28
Jul'23
Scottish university hit by Rhysida ransomware gang
Data allegedly stolen from the University of Western Scotland has been put up for sale on the dark web by a ransomware gang going by the name Rhysida
-
July 28, 2023
28
Jul'23
ServiceNow Q2 2023: 23% year-on-year growth with GenAI to fore
ServiceNow has announced second-quarter 2023 revenue of $2.15bn, up 23% on the same quarter in 2022. The digital workflows automation supplier stressed GenAI developments and partnerships
-
July 27, 2023
27
Jul'23
Cyber criminals pivot away from ransomware encryption
Cyber breaches that saw data theft and extortion without an encryption or ransomware component account for more and more incidents, in a possible indication that ransomware gangs are changing up their business models
-
July 27, 2023
27
Jul'23
US cyber breach reporting rules to have global impact
Organisations that operate as Foreign Private Issuers in the US will have to get to grips with strict new cyber breach reporting regulations handed down by the SEC in Washington
-
July 27, 2023
27
Jul'23
Post Office tried to convince independent IT witness that he was wrong about Horizon
‘Delusional’ Post Office tried to influence an expert witness and get him to change his view about IT evidence which was detrimental to its case against a subpostmaster
-
July 26, 2023
26
Jul'23
Cyber attack on IT supplier hits two major ambulance trusts
Ambulance trusts serving millions across southern England have been hamstrung for the past week after a cyber attack took down their hosted patient records system
-
July 26, 2023
26
Jul'23
UK organisations lack confidence to carry out basic cyber tasks
Amid a shortfall of more than 10,000 cyber pros, UK businesses are still finding it difficult to fill their cyber security skills gaps, with even those in charge of security saying they lack confidence in themselves
-
July 25, 2023
25
Jul'23
Cisco, BT and others launch network security coalition
Network Resilience Coalition focuses on bringing together global expertise to improve data and network security
-
July 25, 2023
25
Jul'23
Tetra radio users’ comms may have been exposed for years
A number of flaws in the encryption algorithms used in the secure Tetra radio communications standard have potentially left users exposed to snooping
-
July 24, 2023
24
Jul'23
Citrix NetScaler users told to patch new zero-day urgently
A vulnerability disclosed and patched last week by Citrix appears to be being exploited by China-backed threat actors as a zero-day, prompting warnings from government cyber bodies
-
July 24, 2023
24
Jul'23
Bank of England’s project to replace ‘beating heart’ is foundation for continuous development
The Bank of England has reached a major milestone in its core system replacement programme, with next landmark in sight
-
July 24, 2023
24
Jul'23
Security AI and automation may reduce cost of data breaches
Organisations that go all in on security AI and automation tend to incur lower financial costs when they experience a data breach incident, according to an IBM report
-
July 20, 2023
20
Jul'23
Electronic Trade Documents Act receives royal assent
Digital trade documents are to be accorded the same status in law as paper ones under a law implemented to help reduce paper waste and speed up the UK’s foreign trade
-
July 20, 2023
20
Jul'23
Online Safety Bill screening measures amount to ‘prior restraint’
The Open Rights Group is calling on Parliament to reform the Online Safety Bill, on the basis that its content-screening measures would amount to “prior restraint” on freedom of expression
-
July 20, 2023
20
Jul'23
BBC outsources IT to India’s Tata Consultancy Services
TCS continues to build its UK public sector business, with the BBC its latest customer
-
July 20, 2023
20
Jul'23
Attention-seeking KillNet hacktivists becoming more dangerous
The KillNet DDoS gang seems to be becoming more dangerous, but its primary goal remains to create a lot of noise and draw media attention, according to latest analysis
-
July 19, 2023
19
Jul'23
Australia’s IaaS market surges 37.1% in 2022
IaaS remains the engine of growth in the Australian IT market and is showing no signs of slowing down, according to Gartner
-
July 19, 2023
19
Jul'23
BlackCat and Clop gangs both claim cyber attack on Estée Lauder
Cosmetics conglomerate Estée Lauder is experiencing operational disruption in the wake of a cyber attack that seems to involve two different cyber crime gangs
-
July 19, 2023
19
Jul'23
‘Significant gaps’ in UK AI regulation, says Ada Lovelace Institute
UK government’s plans to diffuse regulatory responsibility for AI among existing regulators will mean the tech is “only partially regulated”, while its data reforms will undercut already-limited existing protections, says Ada Lovelace Institute
-
July 19, 2023
19
Jul'23
Half of cyber pros engage in risky behaviour at work, report claims
Approximately 55% of security professionals say they have engaged in behaviours they would more usually advise against in the workplace, according to a report
-
July 19, 2023
19
Jul'23
Cyber criminal AI tool WormGPT produces ‘unsettling’ results
A newly discovered generative AI tool dubbed WormGPT is being sold to the cyber criminal underground via the dark web, and poses a significant danger, researchers warn
-
July 18, 2023
18
Jul'23
Critical Adobe ColdFusion flaws chained in ongoing cyber attacks
Two vulnerabilities in Adobe ColdFusion have been chained by threat actors to target victim systems, apparently after one of them was accidentally disclosed
-
July 18, 2023
18
Jul'23
Traditional IT outsourcing rockets as Europe’s businesses cut costs
Overall spending on IT services is up in European countries despite continued reduction in investments in cloud-based contracts
-
July 17, 2023
17
Jul'23
Police Scotland use cloud for biometric data despite clear risks
Police Scotland confirms it has stored significant volumes of biometric data on a cloud-based digital evidence sharing system despite major ongoing data protection concerns, bringing into question the effectiveness of the current regulatory approach...
-
July 13, 2023
13
Jul'23
Civil society groups call on EU to put human rights at centre of AI Act
Dozens of civil society groups are calling on EU institutions to prioritise people and human rights in AI legislation as secretive negotiations begin
-
July 13, 2023
13
Jul'23
Microsoft issues new warning over Chinese cyber espionage
A newly uncovered Chinese espionage campaign exploited forged authentication tokens to access its victims’ email accounts, says Microsoft
-
July 13, 2023
13
Jul'23
One month after MOVEit: New vulnerabilities found as more victims are named
Five weeks after the mass MOVEit breach, new vulnerabilities in the file transfer tool are coming to light as the Clop cyber crime group continues to terrorise victims. But has the gang bitten off more than it can chew?
-
July 12, 2023
12
Jul'23
Digital public services ‘riddled’ with problems, says TUC
The UK’s increasingly digitised public services are plagued by design, governance and workplace issues that are undermining the government’s stated goal of improving efficiency, but can be alleviated by giving public sector workers a greater say in ...
-
July 12, 2023
12
Jul'23
Ofcom’s online safety preparedness efforts hobbled by government
Despite Ofcom’s progress so far, UK government changes to the scope and timetable of the Online Safety Bill are hobbling the ability of the regulator to successfully prepare for the new regime
-
July 12, 2023
12
Jul'23
Cozy Bear lures victims with used BMW 5 Series
A recent Cozy Bear campaign saw the Russian APT group pivot to exploiting an advert for a used car as it targeted diplomatic missions in Kyiv
-
July 12, 2023
12
Jul'23
Hackers: We won’t let artificial intelligence get the better of us
AI is changing how ethical hackers go about their work, and will continue to do so, but the community is convinced the technology will never be able to replicate the creativity of a flesh-and-blood hacker
-
July 12, 2023
12
Jul'23
Microsoft users on high alert over dangerous RCE zero-day
A serious RCE vulnerability in Microsoft Office and Windows is among several zero-days disclosed in Redmond’s July Patch Tuesday update, but this one does not have a patch yet
-
July 11, 2023
11
Jul'23
EU formally grants data adequacy to US
The European Commission has formally granted the US data adequacy, allowing companies and organisations to freely transfer personal data across the Atlantic via the EU-US Data Privacy Framework. But privacy activist Max Schrems has already committed...
-
July 11, 2023
11
Jul'23
Malicious URL volumes soar as cyber criminals pull on Threads
Malicious actors have been quick to exploit the buzz around Meta’s newly launched Threads platform, with thousands of new suspicious domains registered exploiting its branding
-
July 11, 2023
11
Jul'23
Finland’s VTT partners Nokia on data market
Finish state’s involvement in Nokia project will add weight and capital to work on creating a market for data
-
July 11, 2023
11
Jul'23
Apple pushes Rapid Response patch to fix WebKit zero-day
Apple deployed an emergency patch under its Rapid Security Response update programme, but had to temporarily suspend delivery after it caused problems for users of the Safari browser
-
July 11, 2023
11
Jul'23
Peer calls for every Post Office prosecution to be reviewed
Post Office prosecutions should be reviewed in light of damning evidence laid bare by statutory public inquiry into Horizon scandal, says peer James Arbuthnot
-
July 10, 2023
10
Jul'23
Post Office inquiry must examine rule on IT evidence if miscarriages of justice are to be avoided
Public inquiry must examine role of court rules around use of computer evidence that enabled Post Office to prosecute innocent people
-
July 07, 2023
07
Jul'23
Suspicious email reported every five seconds in UK
National Cyber Security Centre report reveals a suspicious email was reported by UK citizens and organisations every five seconds last year
-
July 06, 2023
06
Jul'23
Biometrics watchdog calls for public space surveillance review
The biometrics and surveillance camera commissioner is calling for a review of public space surveillance to gain a clearer picture about the proliferation of Chinese surveillance technology across the public sector, but warns against applying double...
-
July 06, 2023
06
Jul'23
Privacy campaigners call for UK data adequacy to be revoked
The European Commission should revoke the UK’s data adequacy if its Data Protection and Digital Information Bill passes, which campaigners argue ‘flies in the face’ of the decision