A state audit finds the UW System could be an easy target for cyber attacks or hacks if changes are not made to information technology (IT) security systems. Auditors found risks to accounting, payroll and student data. The UW System has until the end of August to submit plans to the Joint Legislative Audit Committee…
Month: August 2018
Fashion Nexus reports 650k affected by hack by “white hat hacker” or “ethical hacker”
Tim Clark reports: Details including the email and home addresses of around 650,000 fashion shoppers were stolen following a security breach at ecommerce platform provider Fashion Nexus. The data breach allowed hackers to access customer details from fashion brands including Elle Belle Attire, AX Paris and Traffic People. Online fashion retailers Perfect Handbags and DLSB…
Web doc iCliniq plugs leaky S3 bucket full of medical files
Another data leak by an Indian firm, it seems. John Leyden reports on this one: Online medical consultation service iCliniq has restricted access to thousands of medical documents it left in a public AWS S3 bucket. iCliniq acted earlier this week only after the slip-up was brought to its attention by German security researcher Matthias…
Credit Card Issuer TCM Bank Leaked Applicant Data for 16 Months
Brian Krebs reports: TCM Bank, a company that helps more than 750 small and community U.S. banks issue credit cards to their account holders, said a Web site misconfiguration exposed the names, addresses, dates of birth and Social Security numbers of thousands of people who applied for cards between early March 2017 and mid-July 2018….
Data leaks at 2 Thai banks spark call for legal safeguards
Cyber-security experts have urged the government to quickly strengthen legal safeguards by adding measures to prevent data leaks after the computer systems of two major Thai banks were hacked recently. According to the Bank of Thailand (BOT) on Wednesday, the computer systems of Kasikornbank (Kbank) and Krungthai Bank (KTB) were compromised in the attacks, affecting…
Leaked chats show alleged Russian spy seeking hacking tools
Just catching up with this great report by Ralph Satterson and Matthew Bodner of AP. It provides a great example of how innocent researchers need to remain vigilant about being played by spies. Six years ago, a Russian-speaking cybersecurity researcher received an unsolicited email from Kate S. Milton. Milton claimed to work for the Moscow-based…