News
IT governance
-
November 08, 2021
08
Nov'21
How cosmetics retailer Lush made over its approach to authentication
Evolving approaches to IT at cosmetics retailer Lush meant the organisation’s previous approach to authentication was no longer up to scratch. Find out how it overcame this hurdle
-
November 05, 2021
05
Nov'21
Digital secretary calls for permanent online safety committee
Digital secretary commits to establishing ongoing oversight of the Online Safety Bill and its implementation, and suggests the grace period on criminal liability for tech company execs should be shortened from two years to a maximum of six months ...
-
November 05, 2021
05
Nov'21
US offers $10m reward for intel on DarkSide ransomware gang
US government puts up a $10m reward for information on the DarkSide ransomware gang, the group that attacked Colonial Pipeline six months ago
-
November 03, 2021
03
Nov'21
Spyware firm NSO and others added to US banned Entity List
US government bans target Israeli spyware makers and cyber firms in Russia and Singapore
-
November 03, 2021
03
Nov'21
Facebook self-imposes facial recognition moratorium
Facebook and Meta have committed to halting their use of facial recognition technology and deleting the biometric data of more than a billion people by the end of 2021, but will retain the underlying algorithms and software for potential use in ...
-
November 03, 2021
03
Nov'21
UK’s Labour Party hit by third-party data breach
Data on Labour Party members was recently compromised in an apparent cyber attack on a third-party data processor
-
November 02, 2021
02
Nov'21
Convicted Silk Road admin stripped of £500k in crypto earnings
Jailed Silk Road administrator Thomas White, aka Cthulhu, has been ordered to hand over more than £490,000 of illicit earnings
-
November 01, 2021
01
Nov'21
Businesses and governments urged to take action over Trojan Source supply chain attacks
Businesses and governments have been put on alert to guard against Trojan Source hacking attacks
-
November 01, 2021
01
Nov'21
MPs and Lords grill Facebook over online safety efforts
Facebook answers British lawmakers’ questions about the social media giant’s efforts to ensure the safety of its users, as part of legislative security of the government's proposed online safety bill
-
October 28, 2021
28
Oct'21
Illegal state surveillance in Africa ‘carried out with impunity’
Analysis of surveillance laws and practices in six African countries finds that existing privacy laws are failing to protect citizens from illegal digital surveillance, which is being facilitated and enabled by global tech companies
-
October 28, 2021
28
Oct'21
How ransomware crews pile on the pressure to get victims to pay
Sophos researchers share some of the more common tactics ransomware gangs use to pressurise their victims into paying up
-
October 27, 2021
27
Oct'21
Government commits millions to security investment
Spending Review adds more than £750m of funding to improve cyber security resilience across government
-
October 27, 2021
27
Oct'21
Cyber sector growth exacerbating skills shortage
Data from security association (ISC)² shows demand for cyber pros is still outpacing supply as the sector continues an upward growth trajectory
-
October 27, 2021
27
Oct'21
Russian IT market growing steadily after pandemic
Russia’s enterprise IT sector is recovering steadily after a slowdown caused by Covid-19
-
October 26, 2021
26
Oct'21
Cyber experts on how to nobble a Nobelium attack
A recent spate of attempted Nobelium cyber attacks were mostly unsuccessful, but serve as a reminder to pay attention to some more fundamental aspects of security
-
October 22, 2021
22
Oct'21
MEPs vote to expand Europol data mandate
The European Parliament has voted in favour of expanding Europol’s mandate to process data and develop AI tools, but critics claim it contradicts a previous vote which opposed using new technologies to predict crime
-
October 21, 2021
21
Oct'21
German regulator imposes limit on number of new customers digital bank can sign each month
BaFin limits the number of new customers that digital bank N26 can enrol until it is reassured on issues it has raised about the company
-
October 20, 2021
20
Oct'21
Police IT buyers should compel suppliers to prove AI claims
House of Lords told that UK law enforcement bodies should use their position as buyers to compel private sector suppliers to divulge more information about how their AI-powered technologies work
-
October 18, 2021
18
Oct'21
How Samlesbury, Lancashire became the home of the National Cyber Force
The National Cyber Force, a new branch of the military, is gearing up to fight battles in cyber space from the fields of Lancashire. Its presence is expected to bring a high-tech renaissance to the region
-
October 14, 2021
14
Oct'21
NHS Digital enhances in-house cyber awareness drive
Keep IT Confidential campaign aims to help NHS staff understand more about security threats and learn how to reduce risk
-
October 13, 2021
13
Oct'21
Google Cybersecurity Action Team springs into life
Google has announced a new Cybersecurity Action Team, with a mission to support security and digital transformation in governments, critical infrastructure, enterprises and small businesses
-
October 13, 2021
13
Oct'21
FCA warns over future hybrid working security risks
Earlier this week, the Financial Conduct Authority issued fresh guidance to regulated organisations on keeping hybrid workers safe and secure
-
October 13, 2021
13
Oct'21
Microsoft warns of MysterySnail on October Patch Tuesday
Microsoft has fixed a zero-day that is being actively exploited to deliver a new remote access trojan dubbed MysterySnail to targets
-
October 12, 2021
12
Oct'21
BCS calls on government to retain protections against AI
BCS, the Chartered Institute for IT, wants the government to retain protections that allow people to have decisions about them made by an AI reviewed by humans if needed
-
October 12, 2021
12
Oct'21
Microsoft thwarts mega-DDoS attack on Azure platform
2.4Tbps DDoS attack on an undisclosed Microsoft Azure customer may have been the largest ever attempted against a single target
-
October 11, 2021
11
Oct'21
Covid-19 will loom over cyber strategy for years to come
In remarks delivered to a Chatham House conference, NCSC head Lindy Cameron reflects on the security challenges facing the UK, and sets out some plans for the future
-
October 08, 2021
08
Oct'21
Craft beer specialist Brewdog fixes serious app vulnerability
Vulnerability in brewer’s mobile app could have resulted in serious consequences for its shareholders and customers
-
October 08, 2021
08
Oct'21
NatWest admits to weaknesses in anti-money laundering systems
Bank pleads guilty to failures concerning the laundering of hundreds of millions of pounds, but says it has since improved its anti-money laundering systems
-
October 07, 2021
07
Oct'21
ICO expresses concerns over its future independence
In its response to the government’s data protection consultation, the Information Commissioner’s Office has raised worries over its future ability to function independently of government interference
-
October 07, 2021
07
Oct'21
Twitch data breach investigations continue
Investigations are ongoing into a 125GB data breach that hit livestreaming platform Twitch, apparently the work of hacktivists
-
October 06, 2021
06
Oct'21
MEPs approve report opposing certain uses of AI by police
European policymakers have approved a report on the use of AI in criminal matters, rejecting several amendments in the process that would have made it easier for police to potentially conduct predictive analytics and biometric surveillance
-
October 06, 2021
06
Oct'21
US lawmakers propose ransomware reporting rules
Former presidential candidate Elizabeth Warren lends her support to a bill that would require corporate ransomware victims to disclose more information about their attacks to the authorities
-
October 06, 2021
06
Oct'21
Gaming service Twitch hacked, data leaked
Users of livestreaming platform Twitch may be at risk after a 125GB torrent of data was leaked
-
October 06, 2021
06
Oct'21
Apache web server users urged to patch immediately
New zero-day in Apache HTTP Server is already being actively exploited and must be addressed immediately
-
October 06, 2021
06
Oct'21
Auto-enrolment begins for Google multi-factor authentication
Google has started to turn on multi-factor authentication on consumer accounts by default, and aims to auto-enrol 150 million users by the end of 2021
-
October 05, 2021
05
Oct'21
CIO interview: Lisa Heneghan, chief digital officer, KPMG
KPMG UK’s digital leader says that in her 25-year career she has never known a more exciting time to work in IT
-
October 05, 2021
05
Oct'21
New Python-based ransomware attacks unfold in record time
Sophos researchers detail a new variety of Python-based ransomware attack targeting VMware ESXi-hosted VMs
-
October 05, 2021
05
Oct'21
Australian organisations lack maturity in responsible AI
Most Australian organisations are still in the early stages of their responsible artificial intelligence efforts despite growing use of AI by businesses and consumers, study finds
-
October 04, 2021
04
Oct'21
Mandiant name returns to fore ahead of FireEye sale
Mandiant has completed its corporate rebrand pending the imminent sale of the FireEye products business to a private equity group
-
October 04, 2021
04
Oct'21
One Identity buys OneLogin for access management expertise
Acquisition of OneLogin adds access management solutions to One Identity’s Unified Identity Security platform
-
October 01, 2021
01
Oct'21
Met Police purchase new retrospective facial-recognition system
Retrospective facial-recognition software purchased for £3m by the Met Police will be deployed in coming months amid continuing controversy around the use of biometric technologies by law enforcement bodies
-
October 01, 2021
01
Oct'21
BEIS urged to prioritise funding to protect umbrella workers in government Spending Review
In an open letter to the Department for Business, Energy and Industrial Strategy, umbrella regulation draft policymakers Rebecca Seeley Harris and James Poyser urge the government to prioritise funding for a single enforcement body
-
October 01, 2021
01
Oct'21
Amnesty International exploited in malware campaign
According to new intelligence from Cisco Talos, Amnesty International’s branding and profile is being used as part of a new malware campaign that exploits people’s fears of the notorious Pegasus spyware app
-
October 01, 2021
01
Oct'21
JVCKenwood hit by Conti ransomware attack
Nearly 2TB of data was stolen from Japanese electronics firm in a Conti ransomware hit
-
October 01, 2021
01
Oct'21
IR35: Giant Group cyber attack prompts renewed calls for statutory regulation of umbrella companies
As details about the fallout from the cyber attack on the Giant Group umbrella company emerge, stakeholders say the incident should prompt the government to expedite regulating contractor payroll processing firms
-
September 29, 2021
29
Sep'21
Russia arrests prominent cyber security executive
Founder and CEO of cyber security firm Group-IB detained in Moscow on treason charges
-
September 29, 2021
29
Sep'21
FoggyWeb malware latest tool of dangerous Nobelium APT
Microsoft’s threat intelligence team warns of a new strain of malware being used by the Russia-linked Nobelium APT
-
September 29, 2021
29
Sep'21
The Security Interviews: How SolarWinds came through its darkest hour
In his first major UK press interview, SolarWinds CEO Sudhakar Ramakrishna tells Computer Weekly how a relentless focus on transparency saw the company safely through a nightmare cyber breach scenario
-
September 28, 2021
28
Sep'21
Digital regulators need discrete but cooperative remits
The UK’s information commissioner has told MPs that digital economy regulators need discrete remits backed up by strong information sharing powers to both provide clear focus as well as allow for greater cooperation between their disparate but ...
-
September 28, 2021
28
Sep'21
How one red team exercise averted a new SolarWinds-style attack
Palo Alto Networks shares details of how its red teamers found and sealed a customer vulnerability that could have led to another SolarWinds-style supply chain attack