www.secnews.physaphae.fr This is the RSS 2.0 feed from www.secnews.physaphae.fr. IT's a simple agragated flow of multiple articles soruces. Liste of sources, can be found on www.secnews.physaphae.fr. 2025-05-10T16:27:59+00:00 www.secnews.physaphae.fr AlienVault Lab Blog - AlienVault est un acteur de defense majeur dans les IOC Pour le manque de cyber ongle, le royaume est tombé<br>For want of a cyber nail the kingdom fell Richard’s Almanack in 1768, it was preceded by the cautionary words: “a little neglect may breed great mischief”. This simple proverb and added comment serve as emblematic examples of how seemingly inconsequential missteps or neglect can lead to sweeping, irreversible, catastrophic losses. The cascade of events resonates strongly within the increasingly complex domain of cybersecurity, in which the omission of even the most elementary precaution can result in a spiraling series of calamities. Indeed, the realm of cybersecurity is replete with elements that bear striking resemblance to the nail, shoe, horse, and rider in this proverb. Consider, for example, the ubiquitous and elementary software patch that may be considered the proverbial digital "nail." In isolation, this patch might seem trivial, but its role becomes crucial when viewed within the broader network of security measures. The 2017 WannaCry ransomware attack demonstrates the significance of such patches; an unpatched vulnerability in Microsoft Windows allowed the malware to infiltrate hundreds of thousands of computers across the globe. It wasn\'t just a single machine that was compromised due to this overlooked \'nail,\' but entire networks, echoing how a lost shoe leads to a lost horse in the proverb. This analogy further extends to the human elements of cybersecurity. Personnel tasked with maintaining an organization\'s cyber hygiene play the role of the "rider" in our metaphorical tale. However, the rider is only as effective as the horse they ride; likewise, even the most skilled IT professional cannot secure a network if the basic building blocks—the patches, firewalls, and antivirus software—resemble missing nails and shoes. Numerous reports and studies have indicated that human error constitutes one of the most common causes of data breaches, often acting as the \'rider\' who loses the \'battle\'. Once the \'battle\' of securing a particular network or system is lost, the ramifications can extend much further, jeopardizing the broader \'kingdom\' of an entire organization or, in more extreme cases, critical national infrastructure. One glaring example that serves as a cautionary tale is the Equifax data breach of 2017, wherein a failure to address a known vulnerability resulted in the personal data of 147 million Americans being compromised. Much like how the absence of a single rider can tip the scales of an entire battle, this singular oversight led to repercussions that went far beyond just the digital boundaries of Equifax, affecting millions of individuals and shaking trust in the security of financial systems. ]]> 2023-11-28T11:00:00+00:00 https://cybersecurity.att.com/blogs/security-essentials/for-want-of-a-cyber-nail-the-kingdom-fell www.secnews.physaphae.fr/article.php?IdArticle=8417468 False Ransomware,Data Breach,Malware,Vulnerability Wannacry,Wannacry,Equifax,Equifax 2.0000000000000000 AlienVault Lab Blog - AlienVault est un acteur de defense majeur dans les IOC Pourquoi les organisations ne détectent-elles pas les menaces de cybersécurité?<br>Why are organizations failing to detect cybersecurity threats? A survey finds that, on average, it takes more than five months to detect and remediate cyber threats. This is a significant amount of time, as a delayed response to cyber threats can result in a possible cyber-attack.  One can never forget the devastating impacts of the Equifax breach in 2017 and the Target breach in 2013  due to delayed detection and response. This is concerning and highlights the need for proactive cybersecurity measures to detect and mitigate rising cyber threats. Amidst this, it\'s also crucial to look into why it is challenging to detect cyber threats. Why do organizations fail to detect cyber threats? Security teams are dealing with more cyber threats than before. A report also confirmed that global cyber attacks increased by 38% in 2022 compared to the previous year. The increasing number and complexity of cyber-attacks make it challenging for organizations to detect them. Hackers use sophisticated techniques to bypass security systems and solutions - like zero-day vulnerabilities, phishing attacks, business email compromises (BEC), supply chain attacks, and Internet of Things (IoT) attacks. Some organizations are unaware of the latest cyber threat trends and lack the skills and resources to detect them. For instance, hackers offer professional services like ransomware-as-a-service (RaaS) to launch ransomware attacks. Surprisingly, two out of three ransomware attacks are facilitated by the RaaS setup, but still, companies fail to have a defensive strategy against them. Enterprises relying on legacy devices and outdated software programs are no longer effective at recognizing certain malicious activities, leaving the network vulnerable to potential threats. Additionally, the lack of trained staff, insider threats, and human errors are other reasons why many organizations suffer at the hands of threat actors. Besides this, much of the company\'s data is hidden as dark data. As the defensive teams and employees may be unaware of it, the hackers take complete advantage of dark data and either replicate it or use it to fulfill their malicious intentions. Moreover, cloud migration has rapidly increased in recent years, putting cybersecurity at significant risk. The complexity of the cloud environments, poorly secured remote and hybrid work environments, and sharing security responsibilities between cloud service providers and clients have complicated the situation. In addition, cloud vulnerabilities, which have risen to 194% from the previous year, have highlighted the need for organizations to look out for ways to strengthen their security infrastructure. Security measures to consider to prevent cyber threats Since businesses face complex cyber threats, mitigating them require]]> 2023-10-19T10:00:00+00:00 https://cybersecurity.att.com/blogs/security-essentials/why-are-organizations-failing-to-detect-cybersecurity-threats www.secnews.physaphae.fr/article.php?IdArticle=8397627 False Ransomware,Data Breach,Tool,Vulnerability,Threat,Cloud Equifax 2.0000000000000000 SecurityWeek - Security News Equifax a condamné à une amende de 13,5 millions de dollars par rapport à la violation de données 2017<br>Equifax Fined $13.5 Million Over 2017 Data Breach La Watchdog financier de l'UK \'s FCA impose A & Pound; 11 millions (environ 13,5 millions de dollars) amende à Equifax sur la violation de données de 2017.
>UK\'s financial watchdog FCA imposes a £11 million (approximately $13.5 million) fine to Equifax over the 2017 data breach. ]]>
2023-10-16T11:41:41+00:00 https://www.securityweek.com/equifax-gets-13-5-million-fine-over-2017-data-breach/ www.secnews.physaphae.fr/article.php?IdArticle=8396199 False Data Breach,Legislation Equifax 2.0000000000000000
Recorded Future - FLux Recorded Future Les amendes britanniques Equifax 13,6 millions de dollars pour la violation de données 2017<br>UK fines Equifax $13.6 million for 2017 data breach Vendredi, la société britannique de rédaction de crédit a été condamnée à une amende et à 11 164 400 (environ 13,6 millions de dollars) par un régulateur britannique pour avoir permis aux pirates d'accéder à des informations personnelles de millions de personnes en 2017. Environ 13,8 millions de consommateurs britanniques ont été touchés dans l'incident, selonà la Financial Conduct Authority, et il reste l'un des
The UK arm of credit reporting firm Equifax was fined £11,164,400 (about $13.6 million) on Friday by a British regulator for allowing hackers to access personal information of millions of people in 2017. About 13.8 million UK consumers were affected in the incident, according to the Financial Conduct Authority, and it remains one of the]]>
2023-10-13T18:15:00+00:00 https://therecord.media/uk-fines-equifax-millions-for-2017-data-breach www.secnews.physaphae.fr/article.php?IdArticle=8395238 False Data Breach,Legislation Equifax 3.0000000000000000
InfoSecurity Mag - InfoSecurity Magazine Amendes du régulateur britannique Equifax & Pound; 11m pour la violation de données 2017<br>UK Regulator Fines Equifax £11m for 2017 Data Breach The UK FCA held Equifax Ltd responsible for failing to protect UK consumer data held by its US-based parent company]]> 2023-10-13T11:45:00+00:00 https://www.infosecurity-magazine.com/news/regulator-fine-equifax-data-breach/ www.secnews.physaphae.fr/article.php?IdArticle=8395107 False Data Breach Equifax 2.0000000000000000 CSO - CSO Daily Dashboard The 12 biggest data breach fines, penalties, and settlements so far data breaches since 2019 suggest that regulators are getting more serious about organizations that don't properly protect consumer data. Marriott was hit with a $124 million fine, later reduced, while Equifax agreed to pay a minimum of $575 million for its 2017 breach. Now, the Equifax fine has been eclipsed by the $1.19 billion fine levied against the Chinese firm Didi Global for violating that nation's data protection laws, and by the $877 million fine against Amazon last year for running afoul of the General Data Protection Regulation (GDPR) in Europe.To read this article in full, please click here]]> 2022-08-16T02:00:00+00:00 https://www.csoonline.com/article/3410278/the-biggest-data-breach-fines-penalties-and-settlements-so-far.html#tk.rss_all www.secnews.physaphae.fr/article.php?IdArticle=6349701 False Data Breach Equifax,Equifax None CSO - CSO Daily Dashboard Vulnerability management mistakes CISOs still make the massive 2017 data breach at the credit reporting agency Equifax, have been traced back to unpatched vulnerabilities-a 2019 Tripwire study found that 27% of all breaches were caused by unpatched vulnerabilities, while a 2018 Ponemon study put the number at a jaw-dropping 60%.To read this article in full, please click here]]> 2022-06-14T02:00:00+00:00 https://www.csoonline.com/article/3663493/vulnerability-management-mistakes-cisos-still-make.html#tk.rss_all www.secnews.physaphae.fr/article.php?IdArticle=5141340 False Data Breach Equifax None Fortinet ThreatSignal - Harware Vendor Incomplete Fix for Apache Struts 2 Vulnerability (CVE-2021-31805) Amended 2022-04-14T19:54:44+00:00 https://fortiguard.fortinet.com/threat-signal-report/4501 www.secnews.physaphae.fr/article.php?IdArticle=4453059 False Data Breach,Vulnerability,Guideline Equifax,Equifax None Veracode - Application Security Research, News, and Education Blog Dangers of Only Scanning First-Party Code When it comes to securing your applications, it???s not unusual to only consider the risks from your first-party code. But if you???re solely considering your own code, then your attack surface is likely bigger than you think. Our recent State of Software Security report found that 97 percent of the typical Java application is made up of open source libraries. That means your attack surface is exponentially larger than just the code written in-house. Yet a study conducted by Enterprise Strategy Group (ESG) established that less than half of organizations have invested in security controls to scan for open source vulnerabilities. If the majority of applications are made up of open source libraries, why are most organizations only scanning their first-party code? Because most organizations assume that third-party code was already scanned for vulnerabilities by the library developer. But you can???t base the safety of your applications on assumptions. Our State of Software Security: Open Source Edition report revealed that approximately 42 percent of the third-party code pulled directly by an application developer has a flaw on first scan. And even if the third-party code appears to be free of flaws, more than 47 percent of third-party code has a transitive flaw that???s pulled indirectly from another library in use. Over the years, several organizations have learned the hard way just how dangerous it is to only scan first-party code. In 2014, the notorious open source vulnerability ??? Heartbleed ??? occurred. Heartbleed was the result of a flaw in OpenSSL, a third-party library that implemented the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. The vulnerability enabled cyberattackers to access over 4.5 million healthcare records from Community Health Systems Inc. In 2015, there was a critical vulnerability in Glibc, a GNU C library. The open source security vulnerability nicknamed ???Ghost,??? affected all Linux servers and web frameworks such as Python, PHP, Ruby on Rails as well as API web services that use the Glibc library. The vulnerability made it possible for hackers to compromise applications with a man-in-the-middle attack. In 2017, Equifax suffered a massive data breach from Apache Struts which compromised the data ??? including social security numbers ??? of more than 143 million Americans. Following the breach, Equifax's stock fell over 13 percent. On the good news front: Close to 74 percent of open source flaws can be fixed with an update like a revision or patch. Even high-priority open source flaws don???t require extensive refactoring of code ??? close to 91 percent can be fixed with an update. Equifax had to pay up to $425 million to help people affected by the data breach that the court deemed ???entirely preventable.??? In fact, it was discovered that the breach could have been avoided with a simple patch to its open source library, Apache Struts. Open source patches and updates Don???t become a victim to the monsters lurking in your third-party libraries. Download our whitepaper Accelerating Software Development with Secure Open Source So]]> 2021-02-24T13:30:31+00:00 https://www.veracode.com/blog/intro-appsec/dangers-only-scanning-first-party-code www.secnews.physaphae.fr/article.php?IdArticle=2399323 False Data Breach,Vulnerability Equifax,Equifax None AlienVault Blog - AlienVault est un acteur de defense majeur dans les IOC Why cybersecurity awareness is a team sport Image Source This blog was written by an independent guest blogger. Cybersecurity may be different based on a person's viewpoint. One may want to simply protect and secure their social media accounts from hackers, and that would be the definition of what cybersecurity is to them. On the other hand, a small business owner may want to protect and secure credit card information gathered from their point-of-sale registers and that is what they define as cybersecurity. Despite differences in implementation, at its core, cybersecurity pertains to the mitigation of potential intrusion of unauthorized persons into your system(s). It should encompass all aspects of one’s digital experience--whether you are an individual user or a company. Your cyber protection needs to cover your online platforms, devices, servers, and even your cloud storage. Any unprotected area of your digital journey can serve as an exploit point for hackers and cyber criminals intent on finding vulnerabilities.  People assume that it is the responsibility of the IT Department to stop any intrusion. That may be true up to a certain point, cybersecurity responsibility rests with everyone, in reality. Cybersecurity should be everybody’s business. The cybersecurity landscape is changing. With 68% of businesses saying that their cybersecurity risks have increased, it is no wonder that businesses have been making increased  efforts to protect from, and mitigate attacks. During the height of the pandemic,  about 46% of the workforce shifted to working from home. We saw a surge in cybersecurity attacks - for example, RDP brute-force attacks increased by 400% around the same time. This is why cybersecurity must be and should be everybody’s business. According to the 2019 Cost of Cybercrime Study, cyberattacks often are successful due to employees willingly participating as an internal actors or or employees and affiliates carelessly clicking a link by accident. Sadly, it is still happening today. Unsuspecting employees can be caught vulnerable and cause a corporate-wide cyberattack by opening a phishing email or bringing risks into the company’s network in a BYOD (Bring Your Own Device) system. Just a decade ago, Yahoo experienced a series of major data breaches, via a backdoor to their network system established by a hacker (or a group of hackers). Further digital forensic investigation shows the breach started from a phishing email opened by an employee. Another example was Equifax when it experienced a data breach in 2017 and was liable for fines amounting to $425 million by the Federal Trade Commission (FTC). Companies continue to double up on their investments in cybersecurity and privacy protection today to ensure that incidents like these do not happen to their own networks. But a network is only as strong as its weakest link. Hackers continue to innovate, making their attacks more and mo]]> 2021-01-12T11:00:00+00:00 https://feeds.feedblitz.com/~/641451762/0/alienvault-blogs~Why-cybersecurity-awareness-is-a-team-sport www.secnews.physaphae.fr/article.php?IdArticle=2175341 False Ransomware,Data Breach,Malware,Vulnerability,Guideline Equifax,Equifax,Yahoo,Yahoo None Veracode - Application Security Research, News, and Education Blog Nature vs. Nurture Tip 3: Employ SCA With SAST For this year???s State of Software Security v11 (SOSS) report, we examined how both the ???nature??? of applications and how we ???nurture??? them contribute to the time it takes to close out a security flaw. We found that the ???nature??? of applications ??? like size or age ??? can have a negative effect on how long it takes to remediate a security flaw. But, taking steps to ???nurture??? the security of applications ??? like using multiple application security (AppSec) testing types ??? can have a positive effect on how long it takes to remediate security flaws. In our first blog, Nature vs. Nurture Tip 1: Use DAST With SAST, we explored how organizations that combine DAST with SAST address 50 percent of their open security findings almost 25 days faster than organizations that only use SAST. In our second blog, Nature vs. Nurture Tip 2: Scan Frequently and Consistently, we addressed the benefits of frequent and consistent scanning by highlighting the SOSS finding that organization that scan their applications at least daily reduced time to remediation by more than a third, closing 50 percent of security flaws in 2 months. For our third tip, we will explore the importance of software composition analysis (SCA) and how ??? when used in conjunction with static application security testing (SAST) ??? it can shorten the time it takes to address security flaws. What is SCA and why is it important? SCA inspects open source code for vulnerabilities. Some assume that open source code is more secure than first-party code because there are ???more eyes on it,??? but that is often not the case. In fact, according to our SOSS report, almost one-third of applications have more security findings in their third-party libraries than in primary code. Given that a typical Java application is 97 percent third-party code, this is a concerning statistic. Flaws Since SCA is the only AppSec testing type that can identify vulnerabilities in open source code, if you don???t employ SCA, you could find yourself victim of a costly breach. In fact, in 2017, Equifax suffered a massive data breach from Apache Struts that compromised the data ??? including Social Security numbers ??? of more than 143 million Americans. Following the breach, Equifax's stock fell over 13 percent. How can SCA with SAST shorten time to remediation? If you are only using static analysis to assess the security of your code, your attack surface is likely bigger than you think. You need to consider third-party code as part of your attack surface, which is only uncovered by using SCA. By incorporating software composition analysis into your security testing mix, you can find and address more flaws. According to SOSS, organizations that employ ???good??? scanning practices (like SCA with SAST), tend to be more mature and further along in their AppSec journey. And organizations with mature AppSec programs tend to remediate flaws faster. For example, employing SCA with SAST cuts ti]]> 2021-01-05T13:25:00+00:00 https://www.veracode.com/blog/intro-appsec/nature-vs-nurture-tip-3-employ-sca-sast www.secnews.physaphae.fr/article.php?IdArticle=2146384 False Data Breach Equifax None Veracode - Application Security Research, News, and Education Blog 96% of Organizations Use Open Source Libraries but Less Than 50% Manage Their Library Security Flaws Most modern codebases are dependent on open source libraries. In fact, a recent research report sponsored by Veracode and conducted by Enterprise Strategy Group (ESG) found that more than 96 percent of organizations use open source libraries in their codebase. But ??? shockingly ??? less than half of these organizations have invested in specific security controls to scan for open source vulnerabilities. Percentage of codebase pulled from open source Why is it important to scan open source libraries? For our State of Software Security: Open Source Edition report, we analyzed the security of open source libraries in 85,000 applications and found that 71 percent have a flaw. The most common open source flaws identified include Cross-Site Scripting, insecure deserialization, and broken access control. By not scanning open source libraries, these flaws remain vulnerable to a cyberattack. ツ?ツ?ツ? Equifax made headlines by not scanning its open source libraries. In 2017, Equifax suffered a massive data breach from Apache Struts which compromised the data ??? including social security numbers ??? of more than 143 million Americans. Following the breach, Equifax's stock fell over 13 percent. The unfortunate reality is that if Equifax performed AppSec scans on its open source libraries and patched the vulnerability, the breach could have been avoided. ツ? Why aren???t more organizations scanning open source libraries? If 96 percent of organizations use open source libraries and 71 percent of applications have a third-party vulnerability, why is it that less than 50 percent of organizations scan their open source libraries? The main reason is that when application developers add third-party libraries to their codebase, they expect that library developers have scanned the code for vulnerabilities. Unfortunately, you can???t rely on library developers to keep your application safe. Approximately 42 percent of the third-party code pulled directly by an application developer has a flaw on first scan. And even if the third-party code appears to be free of flaws, more than 47 percent of third-party code has a transitive flaw that???s pulled indirectly from another library in use. Transitive and direct open source vulnerabilities What are your options for managing library security flaws? First off, it???s important to note that most flaws in open source libraries are easy to fix. Close to 74 percent of the flaws can be fixed with an update like a revision or patch. Even high priority flaws are easy to fix ??? close to 91 percent can be fixed with an update. patching open source flaws So, when it comes to managing your library security flaws, the concentration should not just be, ???How]]> 2020-10-01T14:10:28+00:00 https://www.veracode.com/blog/intro-appsec/96-organizations-use-open-source-libraries-less-50-manage-their-library-security www.secnews.physaphae.fr/article.php?IdArticle=2103312 False Data Breach,Tool,Vulnerability Equifax None Graham Cluley - Blog Security China denies it was behind the Equifax hack, as four men charged for data breach 2020-02-11T15:52:00+00:00 https://www.grahamcluley.com/china-denies-it-was-behind-the-equifax-hack-as-four-men-charged-for-data-breach/ www.secnews.physaphae.fr/article.php?IdArticle=1535714 False Data Breach,Hack Equifax None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) U.S. Charges 4 Chinese Military Hackers Over Equifax Data Breach ]]> 2020-02-10T07:57:01+00:00 http://feedproxy.google.com/~r/TheHackersNews/~3/3bn3pKfuKMM/equifax-chinese-military-hackers.html www.secnews.physaphae.fr/article.php?IdArticle=1533847 False Data Breach Equifax None Dark Reading - Informationweek Branch 2017 Data Breach Will Cost Equifax at Least $1.38 Billion 2020-01-15T18:00:00+00:00 https://www.darkreading.com/attacks-breaches/2017-data-breach-will-cost-equifax-at-least-$138-billion-/d/d-id/1336815?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple www.secnews.physaphae.fr/article.php?IdArticle=1501538 False Data Breach Equifax None IT Security Guru - Blog Sécurité 10 percent of small businesses to impacted by Data breach 2019-10-30T09:51:54+00:00 https://www.itsecurityguru.org/2019/10/30/10-percent-of-small-businesses-to-impacted-by-data-breach/?utm_source=rss&utm_medium=rss&utm_campaign=10-percent-of-small-businesses-to-impacted-by-data-breach www.secnews.physaphae.fr/article.php?IdArticle=1434671 False Data Breach Equifax None InformationSecurityBuzzNews - Site de News Securite COMMENT: Equifax Used Default \'Admin\' User Name And Password To Secure Hacked Portal COMMENT: Equifax Used Default ‘Admin’ User Name And Password To Secure Hacked Portal]]> 2019-10-22T13:39:47+00:00 https://www.informationsecuritybuzz.com/expert-comments/comment-equifax-used-default-admin-user-name-and-password-to-secure-hacked-portal/ www.secnews.physaphae.fr/article.php?IdArticle=1419806 False Data Breach Equifax None CSO - CSO Daily Dashboard Equifax data breach FAQ: What happened, who was affected, what was the impact? 2019-10-14T03:00:00+00:00 https://www.csoonline.com/article/3444488/equifax-data-breach-faq-what-happened-who-was-affected-what-was-the-impact.html#tk.rss_all www.secnews.physaphae.fr/article.php?IdArticle=1402160 False Data Breach Equifax None The Last Watchdog - Blog Sécurité de Byron V Acohido NEW TECH: How \'cryptographic splitting\' bakes-in security at a \'protect-the-data-itself\' level 2019-09-23T08:46:59+00:00 https://www.lastwatchdog.com/new-tech-how-cryptographic-splitting-bakes-in-security-at-a-protect-the-data-itself-level/ www.secnews.physaphae.fr/article.php?IdArticle=1355563 False Data Breach Equifax,Yahoo,Uber None SecurityWeek - Security News 200,000 Sign Petition Against Equifax Data Breach Settlement 2019-09-20T15:43:55+00:00 http://feedproxy.google.com/~r/Securityweek/~3/_585AIyGv0E/200000-sign-petition-against-equifax-data-breach-settlement www.secnews.physaphae.fr/article.php?IdArticle=1353790 False Data Breach Equifax None SecurityWeek - Security News ID Theft Stings, But it\'s Hard to Pin on Specific Data Hacks Equifax 2017. Marriott 2018. Capital One 2019. ]]> 2019-08-05T16:25:04+00:00 https://www.securityweek.com/id-theft-stings-its-hard-pin-specific-data-hacks www.secnews.physaphae.fr/article.php?IdArticle=1248573 False Data Breach Equifax None Malwarebytes Labs - MalwarebytesLabs Capital One breach exposes over 100 million credit card applications The Capital One data breach is an exceptional example, if only because of how much we already know. Not only that, but the breach happened to one of the technical front-runners in banking. Categories: Reports Tags: (Read more...) ]]> 2019-08-02T16:00:00+00:00 https://blog.malwarebytes.com/reports/2019/08/capital-one-breach-exposes-over-100-million-credit-card-applications/ www.secnews.physaphae.fr/article.php?IdArticle=1239194 False Data Breach Equifax None SecurityWeek - Security News FTC Warns Cash Option May be Small for Equifax Settlement 2019-08-01T15:20:05+00:00 https://www.securityweek.com/ftc-warns-cash-option-may-be-small-equifax-settlement www.secnews.physaphae.fr/article.php?IdArticle=1239273 False Data Breach Equifax None Bleeping Computer - Magazine Américain FTC Tells Equifax Victims to Opt for Credit Monitoring Over $125 2019-07-31T19:31:02+00:00 https://www.bleepingcomputer.com/news/security/ftc-tells-equifax-victims-to-opt-for-credit-monitoring-over-125/ www.secnews.physaphae.fr/article.php?IdArticle=1235920 False Data Breach Equifax None CSO - CSO Daily Dashboard IDG Contributor Network: Is the cloud lulling us into security complacency? CapitalOne breach has certainly made lots of headlines in less than a day since the story broke out. And sadly, it has already thrust the $700M settlement that was reached from the largest ever data breach – the Equifax one – onto the sidelines just days after the news of that settlement broke out.But going back to CapitalOne, there are lots of lessons to be learned there certainly. I want to focus on where CapitalOne's data centers were and what that means for the rest of the planet from a security perspective. CapitalOne has been one of the most vocal AWS customers. They have appeared at numerous AWS events and touted how they have completely shuttered all their data centers and run exclusively on Amazon. And to be fair, they have also shared their best practices and use of AWS services.]]> 2019-07-31T05:55:00+00:00 https://www.csoonline.com/article/3412006/is-the-cloud-lulling-us-into-security-complacency.html#tk.rss_all www.secnews.physaphae.fr/article.php?IdArticle=1235036 False Data Breach Equifax None CSO - CSO Daily Dashboard The biggest data breach fines, penalties and settlements so far Here's where the money goes. | Get the latest from CSO by signing up for our newsletters. ]]]> 2019-07-26T03:00:00+00:00 https://www.csoonline.com/article/3410278/the-biggest-data-breach-fines-penalties-and-settlements-so-far.html#tk.rss_all www.secnews.physaphae.fr/article.php?IdArticle=1224662 False Data Breach Equifax None CSO - CSO Daily Dashboard Equifax\'s billion-dollar data breach disaster: Will it change executive attitudes toward security? Here's where the money goes. | Get the latest from CSO by signing up for our newsletters. ]]]> 2019-07-24T04:38:00+00:00 https://www.csoonline.com/article/3411139/equifax-s-billion-dollar-data-breach-disaster-will-it-change-executive-attitudes-toward-security.html#tk.rss_all www.secnews.physaphae.fr/article.php?IdArticle=1221143 False Data Breach Equifax None InformationSecurityBuzzNews - Site de News Securite Experts Commentary On Equifax Settlement Experts Commentary On Equifax Settlement]]> 2019-07-23T17:26:01+00:00 https://www.informationsecuritybuzz.com/expert-comments/experts-commentary-on-equifax-settlement/ www.secnews.physaphae.fr/article.php?IdArticle=1220104 False Data Breach Equifax None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Equifax to Pay up to $700 Million in 2017 Data Breach Settlement ]]> 2019-07-23T00:55:00+00:00 https://thehackernews.com/2019/07/equifax-data-breach-fine.html www.secnews.physaphae.fr/article.php?IdArticle=1219933 False Data Breach Equifax None Krebs on Security - Chercheur Américain What You Should Know About the Equifax Data Breach Settlement 2019-07-22T19:27:01+00:00 https://krebsonsecurity.com/2019/07/what-you-should-know-about-the-equifax-data-breach-settlement/ www.secnews.physaphae.fr/article.php?IdArticle=1220036 False Data Breach Equifax None Dark Reading - Informationweek Branch Equifax to Pay Up to $700mn for Data Breach Damages 2019-07-22T18:23:00+00:00 https://www.darkreading.com/attacks-breaches/equifax-to-pay-up-to-$700mn-for-data-breach-damages/d/d-id/1335315?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple www.secnews.physaphae.fr/article.php?IdArticle=1220068 False Data Breach Equifax None ZD Net - Magazine Info Equifax, regulators sign $700m deal to settle data breach lawsuits 2019-07-22T14:31:00+00:00 https://www.zdnet.com/article/equifax-regulators-sign-700m-deal-to-settle-data-breach-lawsuits/#ftag=RSSbaffb68 www.secnews.physaphae.fr/article.php?IdArticle=1219845 True Data Breach Equifax None BBC - BBC News - Technology Equifax to pay up to $700m to settle data breach 2019-07-22T11:21:04+00:00 https://www.bbc.co.uk/news/technology-49070596 www.secnews.physaphae.fr/article.php?IdArticle=1219420 False Data Breach Equifax None ZD Net - Magazine Info Equifax, regulators close to signing $700m deal to settle data breach lawsuits 2019-07-22T08:06:05+00:00 https://www.zdnet.com/article/equifax-regulators-close-to-signing-700m-deal-to-settle-data-breach-case/#ftag=RSSbaffb68 www.secnews.physaphae.fr/article.php?IdArticle=1219367 False Data Breach Equifax None ZD Net - Magazine Info Former Equifax executive sent behind bars for insider trades, profiting on data breach 2019-07-01T11:30:03+00:00 https://www.zdnet.com/article/former-equifax-executive-sent-behind-bars-for-insider-trading-after-data-breach/#ftag=RSSbaffb68 www.secnews.physaphae.fr/article.php?IdArticle=1181356 False Data Breach Equifax None SecurityWeek - Security News Former Equifax Executive Gets 4 Months for Insider Trading sold stock a week and a half before the company announced a massive data breach was sentenced Thursday to serve four months in federal prison for insider trading. ]]> 2019-06-28T04:58:04+00:00 https://www.securityweek.com/former-equifax-executive-gets-4-months-insider-trading www.secnews.physaphae.fr/article.php?IdArticle=1179009 False Data Breach Equifax None SecurityWeek - Security News Moody\'s Downgrades Equifax Outlook to Negative Over 2017 Data Breach 2019-05-23T12:04:01+00:00 https://www.securityweek.com/moodys-downgrades-equifax-outlook-negative-over-2017-data-breach www.secnews.physaphae.fr/article.php?IdArticle=1122023 False Data Breach Equifax None SecurityWeek - Security News Equifax Was Aware of Cybersecurity Weaknesses for Years, Senate Report Says impacted 148 million Americans in 2017 was the result of years of poor cybersecurity practices, a new Staff Report from the United States Senate's Permanent Subcommittee on Investigations reveals.  ]]> 2019-03-11T16:31:00+00:00 https://www.securityweek.com/equifax-was-aware-cybersecurity-weaknesses-years-senate-report-says www.secnews.physaphae.fr/article.php?IdArticle=1064626 False Data Breach Equifax None Kaspersky Threatpost - Kaspersky est un éditeur antivirus russe Data Breach Bonanza: Dating Apps, Equifax, Mass Credential Dumps 2019-02-15T22:30:01+00:00 https://threatpost.com/data-breach-equifax-credential-dumps/141925/ www.secnews.physaphae.fr/article.php?IdArticle=1028765 False Data Breach Equifax None InformationSecurityBuzzNews - Site de News Securite Equifax Data Breach A Sign Of Global Cyberwarfare? Equifax Data Breach A Sign Of Global Cyberwarfare?]]> 2019-02-15T21:30:00+00:00 https://www.informationsecuritybuzz.com/expert-comments/equifax-data-breach-a-sign-of-global-cyberwarfare/ www.secnews.physaphae.fr/article.php?IdArticle=1028646 False Data Breach Equifax None The State of Security - Magazine Américain Regulatory Fines, Prison Time Render “Check Box” Security Indefensible Read More ]]> 2019-01-28T04:00:01+00:00 https://www.tripwire.com/state-of-security/regulatory-compliance/regulatory-fines-prison-time-render-check-box-security-indefensible/ www.secnews.physaphae.fr/article.php?IdArticle=1011836 False Data Breach Equifax None CSO - CSO Daily Dashboard IDG Contributor Network: Managing identity and access management in uncertain times 2019-01-07T06:05:00+00:00 https://www.csoonline.com/article/3331598/identity-management/managing-identity-and-access-management-in-uncertain-times.html#tk.rss_all www.secnews.physaphae.fr/article.php?IdArticle=978974 False Data Breach Equifax,Deloitte,Yahoo None Infosec Island - Security Magazine Conflicted External Auditors at Heart of Equifax Data Breach 2018-12-13T11:49:00+00:00 https://www.infosecisland.com/blogview/25149-Conflicted-External-Auditors-at-Heart-of-Equifax-Data-Breach.html www.secnews.physaphae.fr/article.php?IdArticle=944533 False Data Breach Equifax None InformationSecurityBuzzNews - Site de News Securite Equifax Offers Free Credit Monitoring - Via Rival Experian Equifax Offers Free Credit Monitoring - Via Rival Experian]]> 2018-11-05T17:15:01+00:00 https://www.informationsecuritybuzz.com/expert-comments/equifax-offers-free-credit/ www.secnews.physaphae.fr/article.php?IdArticle=881183 False Data Breach Equifax None Krebs on Security - Chercheur Américain Equifax Has Chosen Experian. Wait, What? 2018-11-01T16:47:01+00:00 https://krebsonsecurity.com/2018/11/equifax-has-chosen-experian-wait-what/ www.secnews.physaphae.fr/article.php?IdArticle=874857 False Data Breach Equifax None SecurityWeek - Security News Ex-Equifax Manager Gets Home Confinement for Insider Trading 2018-10-18T04:43:01+00:00 https://www.securityweek.com/ex-equifax-manager-gets-home-confinement-insider-trading www.secnews.physaphae.fr/article.php?IdArticle=853577 False Data Breach Equifax None The State of Security - Magazine Américain ICO to Fine Equifax £500,000 for 2017 Data Breach Read More ]]> 2018-09-20T11:09:03+00:00 https://www.tripwire.com/state-of-security/security-data-protection/ico-to-fine-equifax-500000-for-2017-data-breach/ www.secnews.physaphae.fr/article.php?IdArticle=817289 False Data Breach Equifax None ZD Net - Magazine Info Equifax fined £500,000 over customer data breach 2018-09-20T07:25:00+00:00 https://www.zdnet.com/article/equifax-fined-500000-over-customer-data-breach/#ftag=RSSbaffb68 www.secnews.physaphae.fr/article.php?IdArticle=816949 False Data Breach Equifax None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) UK Regulator Fines Equifax £500,000 Over 2017 Data Breach ]]> 2018-09-20T06:54:05+00:00 https://thehackernews.com/2018/09/equifax-credit-reporting-breach.html www.secnews.physaphae.fr/article.php?IdArticle=817552 False Data Breach Equifax None BBC - BBC News - Technology Equifax fined by ICO over data breach that hit Britons 2018-09-19T23:12:00+00:00 https://www.bbc.co.uk/news/uk-england-essex-45574163 www.secnews.physaphae.fr/article.php?IdArticle=816437 False Data Breach Equifax None IT Security Guru - Blog Sécurité A cybersecurity fund has returned more than 30 percent since the Equifax data breach 2018-07-04T14:18:02+00:00 http://www.itsecurityguru.org/2018/07/04/cybersecurity-fund-returned-30-percent-since-equifax-data-breach/ www.secnews.physaphae.fr/article.php?IdArticle=731082 False Data Breach Equifax 2.0000000000000000 Dark Reading - Informationweek Branch Equifax Software Manager Charged with Insider Trading 2018-06-29T11:15:00+00:00 https://www.darkreading.com/cloud/equifax-software-manager-charged-with-insider-trading/d/d-id/1332188?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple www.secnews.physaphae.fr/article.php?IdArticle=729017 False Data Breach Equifax None