Most phishing kits last less than 20 days, a sign defenders are keeping up in the race against cybercrime.
from Dark Reading: https://ift.tt/2picWIs
via IFTTT
Most phishing kits last less than 20 days, a sign defenders are keeping up in the race against cybercrime.
from Dark Reading: https://ift.tt/2picWIs
via IFTTT
Top domain name registrars NetworkSolutions.com, Register.com and Web.com are asking customers to reset their passwords after discovering an intrusion in August 2019 in which customer account information was accessed.
“On October 16, 2019, Web.com determined that a third-party gained unauthorized access to a limited number of its computer systems in late August 2019, and as a result, account information may have been accessed,” Web.com said in a written statement. “No credit card data was compromised as a result of this incident.”
The Jacksonville, Fla.-based Web.com said the information exposed includes “contact details such as name, address, phone numbers, email address and information about the services that we offer to a given account holder.”
The “such as” wording made me ask whether the company has any reason to believe passwords — scrambled or otherwise — were accessed.
A spokesperson for Web.com later clarified that the company does not believe customer passwords were accessed.
“We encrypt account passwords and do not believe this information is vulnerable as a specific result of this incident. As an added precautionary measure, customers will be required to reset passwords the next time they log in to their accounts. As with any online service or platform, it is also good security practice to change passwords often and use a unique password for each service.”
Both Network Solutions and Register.com are owned by Web.com. Network Solutions is now the world’s fifth-largest domain name registrar, with almost seven million domains in its stable, according to domainstate.com; Register.com listed at #17 with 1.7 million domains.
Web.com’s homepage currently makes no mention of the breach notification.
NetworkSolutions.com does not appear to currently link to any information about the incident on its homepage, nor does Web.com. To get to the advisory, one needs to visit notice.web.com.
Web.com said it has reported the incident to law enforcement and hired an outside security firm to investigate further, and is in the process of notifying affected customers through email and via its website.
The company says it plans to circle back with customers when it learns the results of its investigation, but I wonder whether we’ll ever hear more about this breach.
Web.com wasn’t clear how long the intrusion lasted, but if the breach wasn’t detected until mid-October that means the intruders potentially had about six weeks inside unnoticed. That’s a long time for an adversary to wander about one’s network, and plenty of time to steal a great deal more information than just names, addresses and phone numbers.
H/T to domaininvesting.com‘s Elliot Silver for the heads up on this notification.
from Krebs on Security https://ift.tt/2MY3pz3
via IFTTT
Cybersecurity professionals often talk about the economic drivers of security. But should the conversation shift to include a moral component? At least one analyst says “yes.”
from Dark Reading: https://ift.tt/331jSbh
via IFTTT
Don’t miss all the promising enterprise security Briefings at Black Hat Europe in London this December.
from Dark Reading: https://ift.tt/34eNSk5
via IFTTT
PayPal and the PayPal Giving Fund launch a disaster relief campaign for organizations in CA to support relief efforts.
from PayPal – PayPal Stories https://ift.tt/2ovKcvb
via IFTTT
Evidence suggests NSO Group used WhatsApps servers to distribute mobile spyware to targeted devices.
from Dark Reading: https://ift.tt/2r0uTM9
via IFTTT
The attack early in the morning of October 29 has taken all of the school district’s systems offline.
from Dark Reading: https://ift.tt/2NjSDly
via IFTTT
More than half of security practitioners surveyed say insider attack detection has grown more difficult since migrating to cloud.
from Dark Reading: https://ift.tt/2N2nILP
via IFTTT
Decentralized threat intel sharing, more public-private collaboration, and greater use of automated incident response are what’s needed to combat phishing
from Dark Reading: https://ift.tt/2Puc1Pw
via IFTTT
However, the social network harbors no plans to deploy the technology in any of its services any time soon
The post Facebook builds tool to confound facial recognition appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/2PAm7hV
via IFTTT