Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Daily news digest – 12th November 2013

by The Gurus
June 4, 2020
in Opinions & Analysis
Share on FacebookShare on Twitter

his week saw social network LinkedIn get itself into the headlines for the wrong reasons once again, as it wasreported that GCHQ created fake profiles in order to hack into a major Belgian telecommunications company.

The attack on Belgacom was reported back in September but it was unknown how it had been carried out, but fresh reports claim that GCHQ used fake LinkedIn pages to redirect employees to sites containing malware. Security blogger Graham Cluley said that GCHQ’s Network Analysis Centre identified which of Belgacom’s network security and maintenance staff used LinkedIn and read Slashdot, and serve up replicated and malware-laden versions of the pages.
Naturally this is bad news for LinkedIn, who after the major password breach from last year and it was described by hacker turned consultant Kevin Mitnick as an ideal place to find victims for targeted attacks, as through no fault of its own it has found itself in the headlines. The question to ask here is should it have done more to vet new sign-ups and ensure that they were not used for spear phishing (as this has been the case in the past), as well as ensuring that it is securing user details. It’s a tricky business.
Following the major Adobe breach of last month, this story continues to roll on and on with analysis now done of the passwords used. In analysis by Jeremi Gosney of the 130 million+ passwords that were breached, it was revealed that “123456” was used by 1.9 million, while 446,162 used “123456789” and “password” by 345,834.
The old battle of password v security has been rolling for many years and some great analysis of the most commonly used passwords has been done following the aforementioned LinkedIn breach among others, but this is another reminder of the denominator that is the human user who is encouraged to have a different password for each website and application and make them secure, and how they both fail and bypass that advice.
In a related story, Facebook is analysing that password data in order to alert users whose accounts may be vulnerable to compromise because they used the same passwords. In an alert, some Facebook users be notified that their accounts have been blocked from public view until the changes have been completed, all the while assuring users that “Facebook was not directly affected by the incident”.
People are using the internet and secure applications are a part of the internet, but for many everyday users (by which I mean non security types) passwords are a barrier to be overcome, and using the same one for everything is a simple solution. It is hard to drum this out of people unless a simple solution is offered, and while the banking indus
try has done a great job of addressing this with two-factor tokens, perhaps it is time to rethink this with existing solutions.
Finally, just when you thought it was safe to go back into space, it seems that space could be infected by Stuxnet. Of course you cannot infect the universe (unless badBIOS is used perhaps?) but in this case, the International Space Station was infected by a USB stick carried into space by a Russian astronaut.
This followed news that Stuxnet had badly infected the internal network of a Russian nuclear plant, and the worm which targeted an Iranian nuclear facility has accidentally continued its bad ways. In space, no-one can hear you scream “badBIOS”.
ShareTweet
Previous Post

Shaun Walsh from Emulex meets IT Security Guru

Next Post

IT Security Guru meets Phil Lieberman

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol