A hacker who uses the handle @SQLiNairb has announced a leak of data from a well known Nazi Parties website. The breach is on the The National-Socialist Party of Canada official website (https://nspcanada.nfshost.com/) and was breached with a very simple GET based MySQL injection. The website which hosts information is really nothing important but considering the…
Why otherwise adequate breach response plans may fail
One of the recurring themes by commenters on this blog is that they got a breach notification that offered them free credit monitoring services, but: 1. They can’t access the site they’re directed to; 2. They are alarmed that the site asks them for their personal information; and/or 3. They have no reason to trust…
Snowden Swiped Password From NSA Coworker – NSA memo
Michael Isikoff reports that although Edward Snowden has publicly denied using co-workers’ credentials to access documents he downloaded and shared with media outlets: A civilian NSA employee recently resigned after being stripped of his security clearance for allowing former agency contractor Edward Snowden to use his personal log-in credentials to access classified information, according to an…
NIST releases final voluntary cybersecurity framework
Patrick Ouellette reports: Following months of feedback and different tweaks, the National Institutes of Standards and Technology (NIST) has finally issued its voluntary cybersecurity framework. The release completes the year-long NIST public-private effort and a key part of the Executive Order on “Improving Critical Infrastructure Cybersecurity” that President Obama announced in the 2013 State of the Union….
MI: Dental patients' information stolen, misused after employee invites some friends to the office after hours
Steve VanBergen reports: A full prescription fraud investigation is taking shape after a dentist office employee invited people to the office after hours, resulting in stolen information. Police say patients’ credit card information may also be compromised. The incident happened on Tuesday at a dental office in Antwerp Township, according to the Van Buren County…
South Korea regulator reaffirms harsher measures against card firms over data leak
Yonhap News reports that in addition to some stiff penalties imposed by its financial regulator on credit card firms who suffered data leaks, the government continues to look at ways to strengthen the protection of private data: In a report to the parliament, FSC chairman Shin Je-yun said the regulator plans to suspend the card…