One year ago, Canadian businesses became subject to increased data breach notification requirements under PIPEDA (the Personal Information Protection and Electronic Documents Act). Rather than deciding whether to voluntarily disclose or report breaches, they were now required to report all breaches that pose a significant risk of harm to individuals to the Office of the…
Category: Commentaries and Analyses
Ca: Digital pirates search for prey in Southwestern Ontario
Kathleen Saylors and Galen Simmons report: It may have just been a coincidence. But the revelation by Stratford officials on Sept. 19 that the city paid $75,000 to a hacker to regain access to its computer network following a cyber attack five months earlier was followed by a wave of cyber attacks across Southwestern Ontario. In little…
Hackers can steal the contents of Horde webmail inboxes with one click
Zack Whittaker reports: A security researcher has found several vulnerabilities in the popular open-source Horde web email software that allow hackers to near-invisibly steal the contents of a victim’s inbox. […] Numan Ozdemir disclosed his vulnerabilities to Horde in May. An attacker can scrape and download a victim’s entire inbox by tricking them into clicking a malicious…
Florida Virtual School needs new board, new ethics standards, state education department says
Beth Kassab and Leslie Postal report: The troubled Florida Virtual School should get a new governor-appointed board, new ethics standards for employees and a new inspector general inside the school to oversee internal audits and investigations, according to a report released Friday by the Florida Department of Education. And some of the criticism relates to…
More victims of yet another Click2Gov breach this week
Yet another report of a data breach involving Click2Gov software by Central Square Technology. Previous coverage of the publicly disclosed breaches from 2017, 2018, and 2019 are linked from here. Also see research reports by FireEye, Gemini Advisory, and RBS for additional background. The latest victim to come forward — at least the most recent…
It’s “completely ridiculous” that pentesters are still facing criminal charges in Iowa for doing what they were hired to do.
If Iowa doesn’t get its act together, businesses and government will have trouble getting security firms to analyze and test their security. Even after law enforcement was told that Justin Wynn and Gary DeMercurio were Coalfire employees just doing what Coalfire had been hired to do by the judicial branch, the men are still facing…