Darren Pauli reports: Auscert Security bod Alfonso De Gregorio says buyers and sellers in the cut-throat exploit marketplace should release their zero-days to the public if they are fleeced. The BeeWise founder says full disclosure of security vulnerabilities helps punish both buyers who fail to pay or on-sell zero-days, and sellers who break contracts and re-sell…
Category: Of Note
Tox owner ‘tox’ putting his business up for sale
Archiving this, which was posted on Pastebin on June 3 by YDKLIJNSMA (Yonathan Klijnsma, 0x3a) Dear users, Just one month ago, in one instant, all what I’ve studied for months fused in one brilliant idea, which was then named Tox. I knew it was something new, something that was completely different from what was already there. I started designing…
OPM notifying 4 million current and former federal employees of hack
Oh my. From the U.S. Office of Personnel Management, 4 million federal employees may have had their information compromised. But it’s not just OPM that was hacked. It appears that China may have successfully hacked not just OPM, but the Interior Department, and possibly every federal agency. Here’s the press release from OPM: The…
CT Governor Malloy Expected To Sign Data-Breach Bill Requiring One Year Of Identity-Theft Protection
Matthew Sturdevant reports: In the wake of several major data breaches in recent years at The Home Depot, Target and Anthem, Connecticut’s legislature has passed a bill that would provide greater consumer protections. One of the key provisions is at least one-year of identity-theft protection for any customer that is a victim of a data…
Ca: Ontario Securities Commission lays criminal charges in patient records privacy breach at two Toronto hospitals
Diana Mehta reports: Criminal charges have been laid after thousands of confidential records were allegedly stolen from two Toronto hospitals and used to market registered education savings plans to new mothers. The alleged incidents involved the Rouge Valley Health System and the Scarborough Hospital and were investigated by Ontario’s financial regulator, which oversees the sale…
56 MEEELLION credentials exposed by apps say infosec boffins
Darren Pauli reports: Researchers from the University of Darmstadt say app developers have exposed 56 million credentials by borking login processes using services from Google, Amazon, and Facebook. The research team tested 750,000 Android and iOS applications, examining the way they used the federated identity services to make authentication smooth across different devices. The team…