Matthew Vella reports: The data protection commissioner will be launching an investigation after a massive security vulnerability – in a database containing information on 337,384 voters from Malta that was being held by a Maltese IT company – led it to be exposed without security. The data includes ID numbers, names, addresses, gender, phone numbers…
Category: Of Note
UK: Morrisons not liable for 2014 data breach, says Supreme Court
Alex Scroxton reports: Supermarket chain Morrisons has succeeded in its appeal to the Supreme Court against judgments that held it liable for an insider data breach caused by a disgruntled employee. In its unanimous judgment, the Supreme Court said previous judgments had fundamentally misunderstood the principles governing vicarious liability in a number of ways, most notably because…
The UK Cabinet is meeting on Zoom… here’s the meeting ID
Yesterday, Graham Cluley wrote: UK Prime Minister Boris Johnson announced on Twitter this afternoon that he was chairing the first ever digital Cabinet, while he self-isolated himself at Downing Street after revealing he was suffering “mild symptoms” of Coronavirus. Johnson included in the tweet a screenshot of his desktop, showing there were 35 participants on the Zoom…
REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation
From Intel471’s Malware Intelligence Team: REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725. REvil is highly configurable and allows operators to customize the way it behaves on the infected…
FSB Takes Down Top-Tier Marketplace, Arrests Admins
Gemini Advisory has a fascinating piece on the takedown of a top-tier marketplace and the arrest of its administrators. Stas Alforov and Christopher Thomas report that when the Russian Federal Security Service (FSB) reportedly arrested 30 members of a hacker ring that specialized in selling stolen card data, Gemini noted that a popular dark web…
Dark web hosting provider hacked again — 7,600 sites down
Catalin Cimpanu reports: Daniel’s Hosting (DH), the largest free web hosting provider for dark web services, has shut down today after getting hacked for the second time in 16 months, ZDNet has learned. Almost 7,600 dark web portals have been taken offline following the hack, during which an attacker deleted the web hosting portal’s entire database….