Duncan Riley
Latest from Duncan Riley
Jira Server-Side vulnerability exposes user data on cloud-based hosting
Security firm Palo Alto Networks Inc. has uncovered a serious Server-Side vulnerability in Atlassian Corp. PLC’s Jira issue tracking product that exposes data stored using the product. The Server-Side Request Forgery vulnerability involves a web application redirecting an attacker’s request to the internal network or localhost behind a set firewall. Posing a particular threat to cloud services because of the ...
OneCoin lawyer found guilty of money laundering and bank fraud
The first conviction has been handed down in the investigation into OneCoin, a dubious Ponzi scheme that was pitched as a legitimate cryptocurrency and blockchain. The outfit raised an estimated $4 billion before eventually being shut down in 2017. Mark Scott, an attorney who worked with the company in 2016, was convicted by the federal court in the ...
Vistaprint exposes customer data via unsecured database
Online printing service Vistaprint is the latest company to expose customer data online in what seems like a never-ending stream of companies exposing data to all and sundry. The database, which contained more than 51,000 customer service interactions, was found by security researcher Oliver Hough via the Shodan security search engine, and it was not protected ...
Not a ‘fit and proper’ operator: Uber loses its license to operate in London
Uber Technologies Inc. has lost its license to operate on London, one of its biggest markets outside of the U.S., after the local transport regulator ruled once again that it was not a “fit and proper” operator. The decision, made by Transport for London, dates back September 2017 when the regulator first banned Uber. It ruled ...
Palo Alto Networks acquires cloud security startup Aporeto for $150M
Palo Alto Networks Inc. has entered an agreement to acquire cloud security startup Aporeto Inc. for $150 million in an all-cash deal. Founded in 2016, Aporeto offers a zero-trust cloud security platform that auto-generates identity by analyzing workload metadata from any available system and user identity data. Zero trust is an increasingly popular security model ...
Indian digital payments startup Paytm raises $1B in round led by T. Rowe Price
Indian digital payments startup Paytm has raised $1 billion in new funding as it heads toward a likely initial public offering within two to three years. The Series G round, announced Monday in India, was led by T. Rowe Price and backed by existing investors Ant Financial, SoftBank Vision Fund and Discovery Capital. It was raised on ...
In test case, Huawei sues critics in France for linking it to Chinese government
Huawei Electronics Co. Ltd. has taken legal action in France against critics who claim it has ties to the Chinese government in what could be an interesting test case with global ramifications. The world’s second-largest smartphone maker and leading 5G technology provider is currently tendering to provide its 5G tech in France. The lawsuit targets ...
HP rejects Xerox $33.5B takeover offer again
HP Inc. has once again pushed back against efforts by Xerox Corp. to acquire it, as its board sent a letter Sunday bluntly telling Xerox it’s not interested. The letter, addressed to John Visentin, vice chairman and chief executive officer of Xerox, a company most famous for its photocopiers, reiterated that HP rejects Xerox’s proposal as it ...
Account records for up to 1.2B people exposed in massive data leak
In possibly the second-largest data exposure of all time, account records for 1.2 billion people were found unprotected online. Wired reported today that the data on an open Elasticsearch server included various databases with a trove of data. Some of the data included IP addresses as well other various personally identifiable data such as names, email addresses, phone numbers, LinkedIn ...
FBI warns automakers they’re being targeted by hackers
The U.S. Federal Bureau of Investigation has sent a notice to automotive manufacturers warning them that they’re being targeted by hackers. First reported Wednesday by CNN, the notice warned that hackers were known to be attempting to compromise auto industry computer systems using sophisticated techniques. Previous attacks “have resulted in ransomware infections, data breaches leading to the ...









