From a newly released GAO report: Modern vehicles contain multiple interfaces—connections between the vehicle and external networks—that leave vehicle systems, including safety-critical systems, such as braking and steering, vulnerable to cyberattacks. Researchers have shown that these interfaces—if not properly secured—can be exploited through direct, physical access to a vehicle, as well as remotely through short-range…
Category: Commentaries and Analyses
Edwin Shaw employee loses unencrypted flash drive with 975 patients’ info
An anonymous site visitor kindly pointed me to this item that was in the Akron Beacon Journal last week: If you went to Akron General Edwin Shaw Rehabilitation hospital in 2010 or 2011, expect to receive a letter from hospital officials saying that some of your information may have been compromised. Officials said the data…
SWIFT warns customers of multiple cyber fraud cases, issues software security update
Jim Finkle reports: SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of “a number of recent cyber incidents” where attackers had sent fraudulent messages over its system. The disclosure came as law enforcement authorities in Bangladesh and elsewhere investigated the…
Presidential campaign apps expose personal data, report says
First it was their web sites failing to protect privacy, and now it’s their apps. Cory Bennett reports: Over half of presidential campaign-related smartphone apps on Android devices are exposing users’ sensitive data, according to new research. Presidential campaigns — and the groups that support them — are increasingly using smartphone apps to try to…
SWIFT Software Bug Exploited by Bangladesh Bank Hackers
Phil Muncaster reports: A bug in SWIFT banking software may have been exploited to allow hackers to make off with $81 million from Bangladesh’s central bank in February, according to reports. Investigators at British defense contractor BAE Systems told Reuters that the malware in question, evtdiag.exe, had been designed to change code in SWIFT’s Access…
Structuring a Settlement After Asserting Class Members Did Not Suffer Any Concrete Injury
R. Locke Beatty of McGuireWoods writes: Frequently, a class action complaint will set forth an elaborate theory of why the defendant’s actions were negligent or wrongful, but fall short when trying to identify how that conduct has harmed the class members. This kind of complaint invites a motion to dismiss on the grounds that the…