Comments
Equifax Data Breach Prompts Calls For Tougher Security Requirements On Data Aggregators
Newest First  |  Oldest First  |  Threaded View
mattrjohnson21
50%
50%
mattrjohnson21,
User Rank: Apprentice
9/16/2017 | 6:12:53 PM
The Cybersecurity Battle - Time to Give Up?
Maybe it is time for a different approach for cybersecurity? See post on LinkedIn below.
https://www.linkedin.com/pulse/give-up-cybersecurity-programs-matthew-r-johnson-cpa-cisa/?trackingId=UbDoa%2BG4FpxaeSIyMQIzGg%3D%3D
lunny
50%
50%
lunny,
User Rank: Apprentice
9/8/2017 | 3:13:45 PM
The End Game
Once data is released, there's no getting it back.  Unless something changes, more and more data will be released.  As analytics advances, much more data will be made knowable through inference (having "yellow" and "blue" allows you to infer "green" with great confidence).  We need to focus on how to make private data useless to thieves.  If someone who is not me cannot use my data to impersonate me, then I don't really care that it's out there.  Medical data and other types of personal information is on a different level.  It can be used to extort people who might be vulnerable to such criminal methods.  Part of our problem is that it's still too easy to impersonate someone else with a little bit of their data.  That's the core problem we really aren't addressing.  At some point, we run out of fingers to put in the dike.
cybersavior
100%
0%
cybersavior,
User Rank: Strategist
9/8/2017 | 2:58:12 PM
Dispicable and probably criminal
Equifax is dispicable to include an arbitration clause in the sign-up acknowledgement as a prerequisite in front of the free credit monitoring offering.  That consent waives a consumers right to class action.

The EFX stock sales by company officers following the breach (some $1.8M) should be investgated by the SEC, too.


'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-7682
PUBLISHED: 2018-06-22
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
CVE-2018-12689
PUBLISHED: 2018-06-22
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
CVE-2018-12538
PUBLISHED: 2018-06-22
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage...
CVE-2018-12684
PUBLISHED: 2018-06-22
Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
CVE-2018-12687
PUBLISHED: 2018-06-22
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.