• HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE
  • HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE

Knowledge Update: 01 December 2017

01-December-2017
-
Blog
-
No comments
-
Posted by Tom Lejava

This week’s Knowledge Update talks about the Imgur data breach that exposed 1.7 million users, the Scarab ransomware that uses Necurs bots to spread to millions of inboxes and Apple rush to fix a major password bug.

 

Imgur Breach exposes 1.7 million users

 

Imgur’s, COO, Roy Sehal has recently confirmed that the popular image sharing site suffered a data breach of 1.7million user accounts in 2014. The information compromised included email accounts and passwords.

Imgur are still investigating how account information was compromised as passwords had been encrypted on their database. However, they believe that the account information was compromised due to an older hashing algorithm (SHA-256) that was being used at the time. Imgur has now updated their algorithm to the new bcrypt algorithm.

Large data breaches reinforce the need to have strong and separate passwords for each account. Using separate passwords limits your exposure to third-party data breaches. Where possible companies and individuals should deploy technical controls to support authentication, such as Two Factor Authentication (2FA).

For more information contact [email protected] or visit www.londondsc.co.uk.

Read more.

 

Scarab Ransomware uses Necurs bots to spread to millions of inboxes

 

Security researchers have been warned of a new major ransomware campaign that uses the infamous Necurs botnet to spread millions of spam emails.

According to Forcepoint, It was first spotted on 23 November. The Scarab ransomware is being primarily sent to .com and .co.uk inboxes, With 12.5million email addresses affected in the first four hours. The emails that have been sent have a subject line called “Scanned from (Printer company name)” and contain a 7zip attachment with a VBScript downloader.

As strains of Ransomware develop and evolve it is increasingly important for businesses to regularly and securely back up their critical data. Businesses cannot rely on anti-virus alone to protect themselves from Ransomware, a guide to Ransomware can be found here.

For more information contact [email protected] or visit www.londondsc.co.uk.

Read more.

 

Apple rush to fix major password bug

 

Apple have said that it is working to fix a serious password bug within its operating system. The flaw makes it possible for anyone to gain access to a device without a password. Granting the attacker powerful administrator rights. In a statement, Apple have said that “We are working on a software update to address this issue.

The issue was found by a Turkish developer, Lemi Ergin. He would be granted unrestricted access to the machine if he entered the username “root”, leaving the password field empty and hitting “Enter” numerous times.

Although Apple’s latest update will be applied automatically, users should ensure that their operating systems and devices are updated regularly, if not automatically. This will protect your organisation from the latest known flaws and vulnerabilities. It is also recommended that all default passwords should be changed. Information on what makes a strong password can be found here.

For more information contact [email protected] or visit www.londondsc.co.uk.

 

Read more.

Tags
2 Factor Authentication
Apple
Data breach
Necurs botnet
Out of date operating systems
Password Security
Ransomware
← PREVIOUS POST
Knowledge Update: 08 December 2017
NEXT POST →
Knowledge Update: 24 November 2017
Categories
  • Blog
  • Press Release
Recent Posts
  • Is your business cyber-ready?
  • You’ve Got Mail: 5 Tips to Secure Your Email
  • #OneReset - What could you really lose in a hack?
  • Here’s what GDPR means for your business!
  • Essential Advice for Small Business Cyber Security
London Digital Security Centre

We are a Not for Profit organisation, launched by the Mayor of London as a joint venture with the Metropolitan Police and City of London Police.

Leave a Comment

Your feedback is valuable for us. Your email will not be published.
Cancel Reply

Please wait...
Submit Comment

Related News

Other posts that you should not miss.

Is your business cyber-ready?

18-March-2019
-
Blog

99.9% of UK businesses are small and medium sized. With these enterprises being such an integral part of the UK’s economy, it is imperative they are as …

Read More →
Posted by Tom Lejava
1 MIN READ
LDSC knowledge update

Knowledge Update: 17 November 2017

17-November-2017
-
Blog

This week’s Knowledge Update talks about how one-fifth of healthcare organisations still run XP, GDPR is a business opportunity and 50 million fraud attacks are expected next week. …

Read More →
Posted by Tom Lejava
3 MIN READ
LDSC news roundup

News Roundup August 2017

04-September-2017
-
Blog

  Below details the online publications that have featured or made reference to the London Digital Security Centre during August 2017 – please click on the link to …

Read More →
Posted by Tom Lejava
2 MIN READ
Twitter Follow
Tweets by LondonDSC
Social Connect
News
  • 18-March-2019
    Is your business cyber-ready?
  • 05-February-2019
    You’ve Got Mail: 5 Tips to Secure Your Email
  • OneReset
    23-October-2018
    #OneReset - What could you really lose in a hack?
Contact Us

Company Number : 09639299
Mail to : [email protected]
Address : One Wood Street, London,
United Kingdom, EC2V 7WS.

Built by Cyber Rescue
Privacy   T & C
Copyright London Digital Security Centre (LDSC) 2017
Knowledge Update: 01 December 2017 - London Digital Security Centre
 Logo Header Menu
MENU
  • HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE