Duncan Riley
Latest from Duncan Riley
Canadian bank customers targeted in newly discovered phishing campaign
A newly detailed phishing campaign is targeting customers of Canadian banks, but this one has been around awhile: It’s believed to be at least two years old. Detailed by security researchers at Check Point Security Technologies Ltd., which published its findings today, the phishing campaign involves highly convincing emails sent to targeted customers that use ...
Critical Citrix flaw opens the door to unauthorized access and hacking
A newly discovered vulnerability in Citrix Systems Inc. software platforms exposes networks using the software to potential unauthorized access and hacking. Discovered and published today by security researchers at Positive Technologies, the vulnerability relates to both the Citrix Application Delivery Controller and the Citrix Gateway. CVE-2019-19781, as it’s officially known, has been ranked a 10. That’s the highest level ...
Holiday cheer as bitcoin bounces from its lowest level since May
After a fairly lackluster performance over the last four weeks, bitcoin investors may have something to cheer coming into Christmas as the cryptocurrency surged to its highest level in a month today. For the first time since late November, bitcoin passed $7,600, up over $1,000 from a $6,538.01 Dec. 18, bitcoin’s lowest price since May, ...
Card data stolen in point-of-sale hack of Wawa stores and gas stations
The year’s almost done but the data breaches keep on coming, and the latest involves East Coast convenience store and gas station operator Wawa Inc., which has suffered a point-of-sale hack. The data breach affected all of Wawa’s 850 locations and involved the theft of customer names, card numbers and expiration dates both at gas ...
Calling TikTok a ‘cybersecurity threat,’ US Navy bans popular social media app
The U.S. Navy has banned the popular social media app TikTok from mobile devices over increasing concerns that the Chinese-owned app presents a security risk. The ban, issued during last week, applies to all Navy-issued mobile devices. Anyone who does not remove the app will be banned from accessing the Navy Marine Corps intranet. A ...
ToTok messaging app claimed to be an Emirati surveillance tool
ToTok, a popular Middle Eastern messaging app launched earlier this year, is actually a mass-surveillance tool, according to a report today from the New York Times. Pitched as a secure alternative to services such as WhatsApp and Skype, ToTok found a willing audience in the millions. But it’s said to have been designed to enable tracking conversations, ...
MyKings cryptomining botnet hides code in Taylor Swift photo
A cryptomining botnet operator is using an image of Taylor Swift to infect computers, embedding the malicious code in the image itself. The botnet, primarily known as MyKings although also known by some security firms as DarkCloud and Smominru, targets Windows-based servers. Those servers are hosting a variety of services, including MySQL, MS-SQL, Telnet, ssh, IPC, ...
267M Facebook account details in unsecured database shared on hacking forum
An unsecured database with account details relating to 267 million Facebook Inc. users has been found online and has already been shared on a hacking forum. Discovered and publicized today by security researcher Bob Diachenko, the Elasticsearch database included Facebook user IDs, phone numbers, full names and a time stamp. Where the data comes from, however, ...
AI-powered contract management startup Evisort raises $15M
Artificial intelligence-powered contract management startup Evisort Inc. has raised $15 million in new funding, the company announced today. The Series A round was led by M12, Microsoft Corp.’s venture fund and included Amity Ventures and Serra Ventures. The money will be used to hire more people, expand product offerings, enhance its customer experience and launch a new ...
173M stolen Zynga account credentials find their way online
Nearly 173 million user records stolen from online games maker Zynga Inc. have found their way online. The theft of the data, which includes usernames, email addresses and encrypted passwords, was detailed today by breach monitoring site Have I Been Pwned, which added the data to its database of breached credentials. The hack took place in September, with ...









