Attacks/Breaches
10/5/2017
02:30 PM
50%
50%

Equifax Lands $7.25 Million Contract with IRS

The embattled credit monitoring agency will provide taxpayer identification verification and fraud prevention services to the federal tax agency.

Equifax has received a $7.25 million contract from the Internal Revenue Service (IRS) to verify the identities of taxpayers and provide fraud prevention services, according to a Politico report.

The credit monitoring agency, which has been under siege by consumers and legislators since it disclosed its massive breach of sensitive personally identifiable information on up to 145.5 million Americans, was awarded the deal under a no-bid contract on Sept. 30, which marks the end of the fiscal year for the federal government. Equifax disclosed its breach on July 29.

Legislators took the IRS to task for its decision to issue a contract to Equifax. "In the wake of one of the most massive data breaches in a decade, it's irresponsible for the IRS to turn over millions in taxpayer dollars to a company that has yet to offer a succinct answer on how at least 145 million Americans had personally identifiable information exposed," Orrin Hatch, (R-Utah) and Senate Finance chairman, was quoted in Politico.

Read more about the IRS contract here.

 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
HowardE668
50%
50%
HowardE668,
User Rank: Apprentice
10/11/2017 | 6:06:44 AM
This story is from The Onion, right?
I'm sure that this story is copied from The Onion, right> 
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
10/9/2017 | 3:47:34 PM
Re: Why?
"Government is not the solution to the problem.  Government IS the problem"  --- Ronald Reagan.  This is ample proof that government knows NOTHING.,
djvimaxasli
50%
50%
djvimaxasli,
User Rank: Apprentice
10/8/2017 | 10:05:59 AM
Re: Why?
Informative article, just what I wanted to find.
tcubed
50%
50%
tcubed,
User Rank: Apprentice
10/6/2017 | 10:37:15 AM
Thanks
Our government looking out for us, what could possibly go wrong...
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
10/6/2017 | 7:12:28 AM
Why?
Nothing more be said. 
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
Hyatt Hit With Another Credit Card Breach
Dark Reading Staff 10/13/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.