Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

4/12/2018
01:20 PM
50%
50%

Uber Agrees to New FTC Settlement Over 2016 Breach Disclosure

Uber has agreed to an updated settlement with the FTC after news of its massive 2016 data breach.

Uber has agreed to an expanded settlement with the Federal Trade Commission, which last year charged the ride-sharing company for deceiving customers with its privacy and data security practices. The new settlement takes into account Uber's massive 2016 data breach.

In the original settlement, proposed in August 2017, the FTC reported Uber failed to live up to claims that it closely monitored employees' access to rider and driver data, and that it implemented measures to secure personal data on third-party cloud servers.

The FTC later learned Uber had failed to disclose a significant breach of user data that occurred in 2016 while it was investigating this settlement. As a result, it has updated its complaint to note that Uber knew about the 2016 breach and paid the attackers $100,000 through a "bug bounty program" to keep quiet. The breach was disclosed a year after it occurred, in Nov. 2017.

In the new agreement, Uber is compelled to disclose future incidents involving consumer data and submit all reports from required third-party audits of its privacy program. It must retain certain records related to bug bounty reports of flaws that could compromise users' data. Uber could be subject to civil penalties if fails to share future incidents with the FTC.

Read more details here.

Interop ITX 2018

Join Dark Reading LIVE for two cybersecurity summits at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the security track here. Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Look Beyond the 'Big 5' in Cyberattacks
Robert Lemos, Contributing Writer,  11/25/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: I think the boss is bing watching '70s TV shows again!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16958
PUBLISHED: 2020-12-01
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
CVE-2020-8539
PUBLISHED: 2020-12-01
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to i...
CVE-2020-11990
PUBLISHED: 2020-12-01
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
CVE-2020-29315
PUBLISHED: 2020-12-01
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
CVE-2020-28971
PUBLISHED: 2020-12-01
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.