Things I Hearted this Week, 26th October 2018

October 26, 2018 | Javvad Malik
X

Get the latest security news in your inbox.

Subscribe via Email

No thanks. Close this now.

Wordpress Wants to Erase its Past

I was just flexing my clickbait title muscles with the heading here. But according to a talk at DerbyCon, the WordPress security team stated its biggest battle is not against hackers but its own users, millions of which continue to run sites on older versions of the CMS, and who regularly fail to apply updates to the CMS core, plugins, or themes.

The Penalties Keep Rolling in

Looks like the regulators have recently seen the Arnie classic, Pumping Iron, as they flex their muscles to penalise companies for lax security.

First up, supermarket giant Morrisons has been told by the Court of Appeal that it is liable for the actions of a malicious insider who breached data on 100,000 employees, setting up a potential hefty class action pay-out.

In other news, Facebook has been fined £500,000 by the UK's data protection watchdog for its role in the Cambridge Analytica data scandal.

The Information Commissioner's Office (ICO) said Facebook had let a "serious breach" of the law take place.

The fine is the maximum allowed under the old data protection rules that applied before GDPR took effect in May.

Breaches at 32,000 feet

Cathay Pacific has admitted that personal data on up to 9.4 million passengers, including their passport numbers, has been accessed by unauthorised personnel in the latest security screw-up to hit the airline industry.

British Airways still encountering turbulence following its hack in September has revealed a further 185,000 customer details could have been compromised!

Fool Me Once

Children’s Hospital of Philadelphia has reported two data breaches that occurred in August and September of 2018.

The hospital on August 24 discovered that hacker had accessed a physician’s email account on August 23 via a phishing attack. A second breach found on September 6 revealed unauthorized access to an additional email account on August 29.

Some Notes for Journalists About Cybersecurity

The recent Bloomberg article about Chinese hacking motherboards is a great opportunity to talk about problems with journalism.

Journalism is about telling the truth, not a close approximation of the truth,  but the true truth. They don't do a good job at this in cybersecurity.

CVE-2018–8414: A Case Study in Responsible Disclosure

Vulnerability management and responsible disclosure can be a tricky tightrope to walk at times. But this writeup by Matt Nelson on the process he recently went through is really insightful.

What Does it Take to be a CISO?

How do people working in a Chief Information Security Officer (CISO) position or its equivalent view cybersecurity? Which problems do they face? To learn the answers to those questions, Kaspersky Lab surveyed 250 security directors from around the world.

The Hunting Cycle and Measuring Success

This is an older article I came across, but the principles are worthwhile going over again.

Other Things I Liked This Week

Javvad Malik

About the Author: Javvad Malik
The man, the myth, the blogger; Javvad Malik is a London-based IT Security professional. Better known as an active blogger, event speaker and industry commentator who is possibly best known as one of the industry’s most prolific video bloggers with his signature fresh and light-hearted perspective on security. Prior to joining AlienVault, Javvad was a senior analyst with 451 Research providing technology vendors, investors and end users with strategic advisory services, including competitive research and go-to-market positioning.
Read more posts from Javvad Malik ›

‹ BACK TO ALL BLOGS

Watch a Demo ›
GET PRICE FREE TRIAL