Assessing a supplier’s sustainability credentials

Many owners and operators of digital infrastructure have the attitude that using third-party suppliers – cloud and colocation services, IT equipment suppliers, IT hardware recyclers and energy suppliers – absolves them of attendant sustainability responsibilities. They believe the sustainability of an outsourced operation is the supplier’s responsibility. In today’s marketplace, this view is not […]

Read more
API management: Assessing reliability and security

Application programming interfaces (APIs) have had their status upgraded from the domain of programming tool to the proverbial icing on the cake to top a digitisation business plan. APIs allow business leaders to enable workflows across organisational boundaries, connecting siloed business systems and providing a controlled way for external business partners to access data […]

Read more
Malicious WhatsApp add-on highlights risks of third-party mods

Threat researchers at Kaspersky have warned of the risks associated with downloading third-party add-ons for other services, after uncovering a malicious version of a popular WhatsApp messenger mod known as YoWhatsApp. YoWhatsApp offers a number of features that are not available in WhatsApp, such as the ability to block calls from contacts or unsaved […]

Read more
Annual costs of Hackney ransomware attack exceed £12m

The cost of the October 2020 Pysa ransomware attack on the systems of Hackney Council in London continues to mount, with the local authority spending £12.2m during the past financial year (2021-22). The figures were disclosed to community newspaper The Hackney Citizen during an annual inspection of the council’s accounts, and are understood to […]

Read more
Office 365 email encryption flaw could pose risk to user privacy

Security researchers at WithSecure, the company formerly known as F-Secure, have published details of a potentially dangerous vulnerability in Microsoft Office 365 Message Encryption (OME) that could expose the contents of users’ emails to a threat actor if left unmitigated. OME is used by organisations to send encrypted emails both internally and externally. It […]

Read more
Healthcare data was stolen in LockBit 3.0 attack

Business management software supplier Advanced has revealed that a total of 16 customers in the health and social care sector had their data compromised in a ransomware attack on its systems that took place in August 2022, and has now been found to be the work of the Lockbit 3.0 cyber crime gang. The unnamed […]

Read more
Protecting children by scanning encrypted messages is ‘magical thinking’, says Cambridge professor

Governments are in danger of turning to “magical software solutions” to fight child abuse and terrorism, rather than investing in police, social workers and teachers who can deal with the underlying causes, a Cambridge academic claims. Professor of security engineering Ross Anderson has argued in a paper that governments should view the child safety […]

Read more
Cyber training firm KnowBe4 bought by private equity firm

Barely 18 months after an initial public offering (IPO) valued it at $3.5bn (£3.13bn), cyber security training, phishing simulation and awareness specialist KnowBe4 is to be taken private after being acquired by private equity outfit Vista Equity Partners for $4.6bn. Quietly announced on 12 October, the deal represents a 44% premium to KnowBe4’s closing […]

Read more
Unsung Heroes Awards celebrate diversity in cyber community

The UK’s cyber security community descended en masse on a central London venue on 12 October to celebrate the 2022 Security Serious Unsung Heroes Awards, which recognised champions of diversity and mental health in security for the first time. Set up by cyber public relations specialist Eskenzi PR seven years ago as a means […]

Read more
Dutch influence standards for post-quantum cryptography

The US National Institute of Standards and Technology (NIST) has chosen the first group of encryption tools designed to withstand the attack of a future quantum computer, which could potentially crack the security used to protect privacy in the digital systems we rely on today.  Léo Ducas, senior researcher in the cryptology group at […]

Read more