News
IT risk management
- 
				June 12, 2020
				
					12
					Jun'20
				
NHS email service users ensnared in phishing attack
More than 100 accounts on the NHSmail service were affected by attack, but health service says no patient data was accessed
 - 
				June 12, 2020
				
					12
					Jun'20
				
100,000 cheap wireless cameras vulnerable to hacking
Active devices built by Chinese firm HiChip have been sold in the UK as webcams and connected baby monitors
 - 
				June 11, 2020
				
					11
					Jun'20
				
CISOs buying into unified security proposition
The time is right for all-in-one security solutions, according to a report
 - 
				June 10, 2020
				
					10
					Jun'20
				
Decade-old vulnerability among 129 Patch Tuesday fixes
A 10 year-old bug in Windows Group Policies could easily enable attackers to gain highly privileged user status on target systems, opening the doors to a wave of cyber attacks
 
- 
			June 10, 2020
			
				10
				Jun'20
			
Nasty surprises lurking in furloughed employees’ inboxes
Research conducted by KnowBe4 points to a looming email security problem as furloughed employees head back to work
 - 
			June 10, 2020
			
				10
				Jun'20
			
How Australian firms can defend against supply chain attacks
Supply chain security risks can wreak havoc if measures are not taken to deter cyber attackers from exploiting a supplier’s security gaps to target another firm
 - 
			June 09, 2020
			
				09
				Jun'20
			
Honda investigates suspected Snake ransomware attack
Attack disrupts global operations at carmaker, with assembly lines falling silent and sales suspended
 - 
			June 09, 2020
			
				09
				Jun'20
			
Poorly-secured AWS buckets used to launch Magecart attacks
Cyber criminals are exploiting misconfigured AWS S3 buckets to run credit card fraud and malvertising campaigns, according to new data
 - 
			June 08, 2020
			
				08
				Jun'20
			
What it takes to get DevSecOps right
DevSecOps will drive at least 50% of new applications in Asia-Pacific by 2024, but getting it right will require change management, a collaborative mindset and the right automation tools
 - 
			June 05, 2020
			
				05
				Jun'20
			
Police chiefs working with Public Health England on contact-tracing security
Police force representatives are in talks with Public Health England over operational security concerns arising from the NHS Test and Trace coronavirus contact-tracing scheme
 
- 
			June 05, 2020
			
				05
				Jun'20
			
Ministry of Defence forms new cyber security regiment
The 13th Signal Regiment brings together personnel from across the armed forces to provide specialist security services
 - 
			June 04, 2020
			
				04
				Jun'20
			
Dutch organisations invest heavily in compliance – but in vain
Despite the fact that companies in the Netherlands have invested heavily to comply with GDPR legislation introduced two years ago, 90% of them are still discovering fundamental weaknesses in their IT environment
 - 
			June 04, 2020
			
				04
				Jun'20
			
Small businesses failing on remote worker protection
Only one-third of people working for small businesses have received any guidance from their employers on how to secure their remote working set-up
 - 
			June 04, 2020
			
				04
				Jun'20
			
Data privacy groups pile in on UK contact-tracing app
UK-based digital privacy and free speech campaigning organisation files complaint with the Information Commissioner’s Office about contact-tracing app
 - 
			June 04, 2020
			
				04
				Jun'20
			
The Security Interviews: How the BSI protects the IoT from itself
David Mudd of the BSI reveals how a pragmatic and realistic approach to security vulnerabilities underpins its internet of things kitemark, helping give users the confidence to buy smart devices safely
 - 
			June 04, 2020
			
				04
				Jun'20
			
Coronavirus: Cyber criminals target laid-off workers
Malicious actors are targeting workers laid-off or furloughed during the coronavirus pandemic
 - 
			June 03, 2020
			
				03
				Jun'20
			
Sodinokibi data auctions highlight changing criminal tactics
The operators of the Sodinokibi ransomware strain are auctioning off swathes of stolen data in an apparent bid to raise cash. What is motivating this new tactic?
 - 
			June 03, 2020
			
				03
				Jun'20
			
Security procurement framework goes live for NHS and public sector
Cyber Security Services Framework, developed by NHS Shared Business Services, has formally launched
 - 
			June 03, 2020
			
				03
				Jun'20
			
Infosec 2020: Covid-19 an opportunity to change security thinking
The annual Infosecurity Europe is being held virtually this year, and speakers at an online panel session have been considering the impact of the pandemic on security awareness
 - 
			June 03, 2020
			
				03
				Jun'20
			
Aston Martin swaps out legacy antivirus for AI-driven service
Luxury car manufacturer says the advent of artificial intelligence-powered services will revolutionise its security posture
 - 
			June 02, 2020
			
				02
				Jun'20
			
NIS security regulations proving effective, but more work to do
The UK’s NIS cyber security and risk regulations are proving somewhat effective, according to a government report
 - 
			June 01, 2020
			
				01
				Jun'20
			
How managed threat hunting helps bust malicious insiders
Managed threat hunting services can help take some of the pressure off security operations centres and help ensure potential breaches don’t escalate into something far worse. We explore one such case with a happy ending
 - 
			May 29, 2020
			
				29
				May'20
			
Government launches IoT security funding round
A £400,000 funding pot is on offer for innovators to design schemes that boost internet-of-things security
 - 
			May 29, 2020
			
				29
				May'20
			
Test and Trace has not passed data protection impact assessment
Public Health England failed to complete the required impact assessment before launching the Covid-19 Test and Trace programme
 - 
			May 29, 2020
			
				29
				May'20
			
How Sega Europe slashed incident response times using cloud SIEM
Gaming company’s SOC radically improves its operational efficiency with Sumo Logic’s cloud SIEM service
 - 
			May 28, 2020
			
				28
				May'20
			
Public Health England to keep contact-tracing data for 20 years
PHE will retain the data it collects via the NHS Test and Trace programme for 20 years
 - 
			May 28, 2020
			
				28
				May'20
			
IoT buyers eye private network deployments for added security
Fully private, segregated networks for IoT deployments are becoming increasingly attractive to many organisations, according to a report
 - 
			May 27, 2020
			
				27
				May'20
			
Enterprise clouds hammered by cyber attacks during pandemic
Remote workers logging onto enterprise cloud service accounts are an easy access point for attackers, says McAfee
 - 
			May 27, 2020
			
				27
				May'20
			
Fears contact-tracing app will open the floodgates for cyber criminals
Study of UK consumers reveals worries over an uptick in cyber crime and a lack of trust in government
 - 
			May 26, 2020
			
				26
				May'20
			
StrandHogg mobile vulnerability has evil twin
Variant of the dangerous StrandHogg vulnerability affecting Android phones could allow hackers to access almost all apps on a target device
 - 
			May 26, 2020
			
				26
				May'20
			
The Security Interviews: Temper tantrums ahead as GDPR enters its terrible twos?
On the General Data Protection Regulation’s second birthday, Tim Hickman, a data protection lawyer and partner at White & Case LLP, discusses the regulation’s teething troubles and assesses how best to maintain optimum compliance
 - 
			May 25, 2020
			
				25
				May'20
			
Coronavirus: Australia calls for stronger defences amid cyber attacks
The Australian Cyber Security Centre offers guidance for critical infrastructure operators to guard against cyber attacks which have already hit the healthcare sector
 - 
			May 22, 2020
			
				22
				May'20
			
EasyJet to be sued over customer data breach
If successful, airline’s potential liability for the loss of millions of customer records could be as high as £18bn
 - 
			May 22, 2020
			
				22
				May'20
			
Covid-19 will leave organisations exposed to higher cyber risks
Hacking attacks and phishing emails could become the new norm, according to research by the World Economic Forum
 - 
			May 22, 2020
			
				22
				May'20
			
Hancock to Harman: No contact-tracing privacy law
Health secretary claims existing data protection law is good enough to guarantee the security of contact-tracing data
 - 
			May 22, 2020
			
				22
				May'20
			
Coronavirus: How MyIX is keeping Malaysians connected
Malaysia’s MyIX internet exchange has been classed as critical national infrastructure, with member telcos adding more capacity to meet the surge in demand for internet services
 - 
			May 20, 2020
			
				20
				May'20
			
NCSC discloses multiple vulnerabilities in contact-tracing app
National Cyber Security Centre has received mountains of feedback on the security of the government’s Covid-19 contact-tracing app, and has now taken the step of making multiple disclosures
 - 
			May 20, 2020
			
				20
				May'20
			
Serco exposes contact tracers’ data in email error
Error saw almost 300 coronavirus contact tracers’ email addresses made visible to other recipients of the message
 - 
			May 20, 2020
			
				20
				May'20
			
Personal devices putting Singapore employers at risk
More than half of Singapore respondents to a CrowdStrike-commissioned survey believe their devices are only somewhat secure against advanced cyber threats
 - 
			May 20, 2020
			
				20
				May'20
			
Responsible Cyber acquires Secucial in S$7m deal
Singapore startup Responsible Cyber plans to bolster its Immune platform with access control management capabilities, and sets out to expand its global footprint
 - 
			May 19, 2020
			
				19
				May'20
			
Cancelled NCSC CyberUK event gets green light for 2021
The NCSC’s popular CyberUK event has been rescheduled to next year, and will again take place in Newport in south Wales
 - 
			May 19, 2020
			
				19
				May'20
			
Nine million EasyJet customer details lost in data breach
Cyber attack on EasyJet’s systems originated from a highly sophisticated source, says the airline
 - 
			May 19, 2020
			
				19
				May'20
			
Vast majority of cyber attacks are easy to stop, says Verizon
Almost 90% of data breaches are motivated by the prospect of financial gain, but cyber criminals have clearly defined breach pathways, giving the good guys an advantage if they care to use it
 - 
			May 18, 2020
			
				18
				May'20
			
Why a pandemic-specific BCP matters
Many organisations still do not have scenario-specific business continuity plans, which are helpful when the situation requires a customised response, such as a pandemic, according to Forrester
 - 
			May 14, 2020
			
				14
				May'20
			
China targeting Covid-19 researchers through IT suppliers, claims US
The US CISA says it is seeing targeting and attempted network compromise of Covid-19 research centres by China
 - 
			May 13, 2020
			
				13
				May'20
			
Report reveals inadequate cyber security at Schiphol Airport
A report has revealed problems with critical security systems in Amsterdam’s Schiphol Airport
 - 
			May 13, 2020
			
				13
				May'20
			
Nation state APT groups prefer old, unpatched vulnerabilities
The Cybersecurity and Infrastructure Security Agency and the FBI have published details of the most commonly exploited vulnerabilities of recent years, and there are some “classics” on the list
 - 
			May 13, 2020
			
				13
				May'20
			
Microsoft fixes 16 critical vulnerabilities on Patch Tuesday
The trend towards mammoth Patch Tuesdays continues as Microsoft fixes 111 vulnerabilities
 - 
			May 12, 2020
			
				12
				May'20
			
Draft Covid-19 contact tracing legislation proposes formal oversight
Human Rights Committee chair Harriet Harman has outlined a proposed bill to guarantee the security and privacy of data generated by the UK’s Covid-19 contact tracing app
 - 
			May 12, 2020
			
				12
				May'20
			
Pay the ransom and double your recovery costs, report warns
Paying cyber criminals a ransom to recover your data adds over half a million dollars to the cost of organisational recovery, says Sophos
 
