Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

It’s been the story of the week; someone dumps a list of more than six million passwords on a Russian forum, and teams of people start cracking them. There are clear indications that they came from LinkedIn, which the social network later confirmed. Shortly after that, dating site eHarmony says they too had accounts compromised by the leak, and now Last.fm is in the mix. Here’s a recap, and a look at the letter LinkedIn is sending to users.

According to a report from Deutsche Presse-Agentur (DPA), German armed forces confirmed the existence of a cyberwarfare unit in a document presented to parliament earlier this week. The defensive side of the military’s cyber group is well-known, but the notice to parliament marks the first time that the offensive aspect has come to light in an official report.The report to legislators from Germany’s Defence Ministry outlines the group’s objectives only briefly.

Proofpoint, a provider of Security-as-a-service solutions, on Thursday announced “Proofpoint Targeted Attack Protection”, a new cloud-based security solution designed to provide protection against spear phishing and other malicious, targeted attacks.

A 39-year-old consultant from California, Michael Garcia, has been found guilty sentenced to fifty-seven months in prison for identity theft. According to the court, Garcia committed his crimes while working as an IT contractor.Garcia was a technical contractor, who offered IT support to various firms within the Stockton area. While employed with a law firm and an accounting firm, he accessed their records and copied the personal information for more than 1,450 people.

Yesterday, SecurityWeek published an early report on a story from Dangens IT that a hashed password list containing some 6.5 million records may have been leaked from LinkedIn. Throughout the morning, several people examining the list of password hashes reported discovering their own credentials in the stolen list.

Web performance and security firm, CloudFlare, this week announced launched new services with increased performance and features designed to address the needs of larger businesses.The two new offerings, CloudFlare Business and CloudFlare Enterprise, are built on top of the company’s infrastructure and provide services including broader DDoS Protection, WAN Optimization, content delivery, higher levels of support and more.

A hashed password list containing some 6.5 million records has been uploaded to a Russian forum earlier this week. An expert consulted for the story says that there are indications the passwords were taken from the corporate social network LinkedIn, and this has since been confirmed with LinkedEd.

On Tuesday, Google said that it will begin notifying an unnamed subset of users, which could equate to anywhere from thousands to millions of people daily, if it is believed they are the target of a state-sponsored attack.Google already has the systems in place to monitor for malicious activity, especially attempts by unknown third parties to monitor users via unauthorized access. Now, Google said, when there is specific intelligence (from either users or their own monitoring mechanisms) that someone is...

The EFF is warning activists in Syria to use caution when downloading documents via Skype, after a new attack blends social engineering with a malicious PDF to install a Trojan on the victim’s computer. This latest attack is just another example of such schemes, the EFF said, which started earlier this year.According to the EFF’s blog post on the matter, Syrian activists are contacted via Skype, and encouraged to download a PDF file that purports to contain plans of assistance...

Presidential hopeful Mitt Romney almost had a Sarah Palin experience, if it wasn’t for the fact that Gawker kept their hands off the leaked goods. After an AP story mentioned Romney’s Hotmail address, Gawker’s anonymous tipster used the password reset function to gain access to it, and sent the details to the news site.

A recent study by Experian Data Breach Resolution says that consumers are far from pleased with the typical response from a company during the aftermath of a data breach. Consumers expect a company to protect their data fully, but when that doesn’t happen, they would also like to have the issue explained fully, instead, they feel left in the dark.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.