The great state of Texas has 15.2 million registered voters. Unfortunately, personal details belonging to nearly all of them (14.8 million) have been compromised, but don’t blame the state’s election officials.
This staggering breach was caused by the carelessness of a conservative-focused data firm, ironically named “The Data Trust.” They left their research file completely exposed and unprotected on a server that anyone could access with no password required. It’s hard to see how the exposure could have been more damaging or all-inclusive.
The Single, massive file contained the following details:
Voter name
Voter address
Gender
Voting history for past elections, including primaries and presidential elections
According to the independent New Zealand researcher who discovered it, who goes by the name of “Flash Gordon,” the file also contained indications of voter views on abortion, immigration, the Second Amendment, and whether or not the voter in question trusted Hillary Clinton.
Bill Evans, the VP of the security firm “One Identity,” had this to say about the incident:
“The idea of having a database like this sitting with no password is such an incredible lapse in judgement today. While we all know that keeping up with password best practices can be somewhat annoying – forgetting and resetting them in a broken cycle – it is inexcusable and maybe illegal to leave data that contains personal information like this completely unprotected.
It is a good reminder, however, and call to action for any organization that is storing sensitive data, that it is their responsibility to ensure security, as well as authentication to access it. There are four basic security measures that should be part and parcel of doing business today. Those include end-user education, multi-factor authentication, privileged-access management, and access governance to ensure only the right people have the right access to the right things at the right time.”
Indeed.
There’s a new threat to point of sale (POS) systems coming out of Russia, according to security researchers from Booz Allen Hamilton. The malware, which they’re calling “RtPOS” isn’t bleeding edge technology, and does not approach the level of sophistication of other recently discovered strains, but that doesn’t mean it should be taken lightly. These strains include RawPOS, MajikPOS, UDPOS, and Treasure hunter.
Quick question – how much do the world’s cyber criminals make every sixty seconds?
It may sound like something straight out of a science fiction movie, but recently, researchers have made a disturbing discovery. Using nothing more than an off-the-shelf microphone, it’s possible for an attacker to determine what content you’re viewing on your computer monitor.
Telecommunications giant T-Mobile is the latest victim of a large-scale data breach, with personal data belonging to more than two million of its customers having been leaked. The exposed information included customer name, phone number, email address, billing zip code, account number and whether the account was pre-paid or post-paid.
Android users have a new threat to contend with, according to a sixteen-page whitepaper outlining a new malware strain.
According to a recent survey conducted by Pew Research Center, 54 percent of teens say that they spend too much time on their cellphones.
Earlier this year, Microsoft announced that it had entered into a partnership with Open Whisper Systems, the makers of the Signal app. The purpose of the partnership was to bring Signal’s open source, end-to-end encryption protocol to Skype.
Google has introduced a new Gmail feature called “Confidential Mode,” which seeks to make sending and receiving important or sensitive emails more secure. Unfortunately, it may have inadvertently created as many problems as it solves.
Do you use Photoshop? Does anyone who works for you use it? If so, you’ll want to apply the latest security patch immediately.