Kaseya hires FireEye to help deal with ransomware outbreak – Security

Kaseya hires FireEye to help deal with ransomware outbreak – Security

WASHINGTON (Reuters) – Ransomware-hit IT firm Kaseya said on Sunday it hired cybersecurity company FireEye Inc to help deal with the fallout of a major breach that has affected hundreds of businesses worldwide. In a message posted to its website, Miami-based Kaseya said its employees “have been actively engaged with FireEye and other security assessment…

Mongolian Certification Authority MonPass Breached

Mongolian Certification Authority MonPass Breached

3rd Party Risk Management , Governance & Risk Management , Incident & Breach Response Avast: This Supply Chain Attack Used Cobalt Strike Prajeet Nair (@prajeetspeaks) • July 6, 2021     This bitmap image file was used for a steganography attack on MonPass. (Source: Avast) Researchers at Avast discovered a compromised server belonging to MonPass,…

Kroger, British Airways Agree to Settle Data Breach Lawsuits

Kroger, British Airways Agree to Settle Data Breach Lawsuits

Governance & Risk Management , Incident & Breach Response , Legislation & Litigation Class Actions Filed Against Each Company After Hacking Incidents Marianne Kolbasuk McGee (HealthInfoSec) , Doug Olenick (DougOlenick) • July 6, 2021     U.S.-based pharmacy and supermarket chain Kroger and U.K.-based British Airways have each agreed to settle class action lawsuits filed…

Did Kaseya Wait Too Long to Patch Remote Software Flaw?

Did Kaseya Wait Too Long to Patch Remote Software Flaw?

Business Continuity Management / Disaster Recovery , Fraud Management & Cybercrime , Governance & Risk Management 90 Days After Vulnerability ID Reserved, REvil Exploited Bug to Hit Kaseya Customers Mathew J. Schwartz (euroinfosec) • July 6, 2021     Kaseya’s vulnerability disclosure page on its website Ransomware-wielding criminals continue to hone their illicit business models,…

Google removes popular Android apps that stole Facebook passwords

Google removes popular Android apps that stole Facebook passwords

Google is still racing to pull Android apps that commit major privacy violations. Ars Technica notes that Google has removed nine apps from the Play Store after Dr. Web analysts discovered they were trojans stealing Facebook login details. These weren’t obscure titles — the malware had over 5.8 million combined downloads and posed as easy-to-find…

Google Removes 9 Android Apps That Stole Facebook Users’ Credentials

Google Removes 9 Android Apps That Stole Facebook Users’ Credentials

Google recently removed nine malicious apps from the Play Store after they were found stealing Facebook users’ logins and passwords. Discovered by security researchers at Dr. Web, these stealer trojans were found using a special mechanism to trick users into disclosing their Facebook login details by offering them photo editing and app lock features as well…

3 more internet firms scrutinized amid rising data security concern

3 more internet firms scrutinized amid rising data security concern

The headquarters of DiDi in Beijing Photo:VCG  China’s cyberspace regulator on Monday put three more internet platforms under scrutiny, three days after it announced a review of cybersecurity into the country’s top ride-hailing platform Didi Chuxing, indicating the country’s resolve to clamp down on data breaches and misuse as part of a broader move to…

US shares of Chinese platform operators under cybersecurity reviews plummet pre-market

US shares of Chinese platform operators under cybersecurity reviews plummet pre-market

A man walks near the New York Stock Exchange (NYSE) on August 31, 2020 at Wall Street in New York City.Photo: CFP  Chinese ride-hailing giant Didi’s US shares plunged in pre-market trading on Tuesday, in a rout that was joined by two other platform firms that have recently been in China’s cybersecurity crosshairs. As of…