UK MSPs will be brought under the same cybersecurity laws that govern essential services, such as critical infrastructure and health care. The move stems in large part from an increasing focus on MSPs by the most advanced nation-state security actors.
A new report from the FPF and ABLI promotes a shift from consent-based models to a focus on accountability for data processors in the interest of improving consistency between different jurisdictions and different data protection laws.
Ragnar Locker ransomware gang targeted the municipality of Zwijndrecht but instead hacked a local Belgian police unit, releasing sensitive police data, including investigation reports and criminal records.
Security leak of manufacturing keys from major device producers (such as LG and Samsung) allows signing of malware apps, providing full access to an Android device, as the operating system trusts any signed app with complete system-level access.
One of the few significant holes in Apple's end user security is set to be addressed, as Cupertino has announced plans to introduce end-to-end encryption to iCloud backups. A feature Apple has delayed due primarily to pressure from US federal law enforcement agencies.
The DoD has published a strategy and roadmap directing all the department's agencies to migrate to zero trust architecture by 2027. Strategy identified 90 target capabilities and 62 capabilities to achieve “more advanced zero trust.”
The US Secret Service is now pointing the finger at state-backed Chinese hackers, accusing a known advanced persistent threat group APT41 of stealing about $20 million of US Covid benefits during the pandemic.
Amnesty International Canada experienced a security breach on October 5 with the ultimate conclusion being that state-sponsored Chinese hackers penetrated the system for espionage purposes.
Security researchers discovered an Android malware active since 2008 in Google Play Store and third-party app stores stealing Facebook logins of 300,000 users in 71 countries.
Organizations found to be responsible for a privacy breach now face a maximum penalty of AUD 50 million, 30% of adjusted annual domestic turnover, or three times the value of any benefit obtained through the misuse of the leaked information.










