720-891-1663

Security News for the Week Ending January 24, 2020

Breaches Gone Wild – Very Wild Since EU’s GDPR went into effect on May 25, 2018 – about 18 months ago – 160,000 Breaches have been reported to EU authorities.  A calculator will tell you that means that people are reporting between 250 and 300 security incidents A DAY! If you think that magically, 18 […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending January 17, 2020

Orphaned Data in the Cloud Researchers at security firm vpnMentor found an unsecured S3 bucket with passport, tax forms, background checks, job applications and other sensitive data for thousands of employees of British consultancies.  Many of the firms involved are no longer in business. The researchers reported this to Amazon and the UK’s Computer Emergency […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Telcos Not Doing Good at Preventing SIM Swap Attacks

A SIM is the (usually) hardware card that gives your phone its “personality”.  The SIM is tied to the carrier and contains all the information that the phone needs to talk to your carrier. As users SLOOOOWLY migrate to using text messages as an extra layer of authentication for logging in to a variety of […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending January 10, 2020

Albany Int’l Airport Hit By Ransomware via MSP In what is becoming an all too common story, the Managed Service Provider that supported Albany, NY’s airport, Logical Net of Schenectady, NY, was hacked and from there, the hackers were able to connect to the airports administrative network and infect it with REvil ransomware, the same […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending January 3, 2020

Starbucks Leaves Their API Key in a Public Github Repository Vulnerability hunter Vinoth Kumar found a Starbucks API key in a public Github repo. The flaw was set to CRITICAL after they verified that the key gave anyone access to their Jumpcloud (An AD alternative) directory. The problem was reported on October 17th and it […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Cloud Hopper Attack Bigger Than Reported. MUCH Bigger

I hate to keep beating on this drum, but the message is important and the news keeps getting worse. Yesterday I wrote about yet another managed service provider that was hit by a ransomware attack and a number of their clients had their data encrypted. Today the Wall Street Journal is reporting that the Cloud […]

Continue reading → [DISPLAY_ACURAX_ICONS]