Friday Five 9/9 | Digital Guardian

The Industry’s Only SaaS-Delivered Enterprise DLP

Our unique approach to DLP allows for quick deployment and on-demand scalability, while providing full data visibility and no-compromise protection.

No-Compromise Data Protection is:

  • Cloud-Delivered
  • Cross Platform
  • Flexible Controls
DATAINSIDER

Digital Guardian's Blog

Friday Five 9/9

by Robbie Araiza on Friday September 9, 2022

Contact Us
Free Demo
Chat

This week saw two social media giants come under fire once again, malware that cons cybercriminals, and more cyberattacks in Ukraine. Read about these stories and more in this week's Friday Five!

1. Instagram receives record fine of $400M for abuse of children's data by Jovi Umawing

Following an investigation into how Instagram handles teens’ data on their platform, Ireland’s Data Protection Commissioner (DPC) has slapped the company with a near $402 million fine, marking the DPC’s highest fine to date. In response to the investigation and resulting fine, a spokesperson for Instagram said, "This inquiry focused on old settings that we updated over a year ago, and we've since released many new features to help keep teens safe and their information private. Anyone under 18 automatically has their account set to private when they join Instagram, so only people they know can see what they post, and adults can't message teens who don't follow them. We engaged fully with the DPC throughout their inquiry, and we're carefully reviewing their final decision." Read more about what led to the regulator’s final decision in the full story from Malwarebytes Labs.

Read more

2. CISA to formally solicit industry feedback on cybersecurity incident reporting rules by Suzanne Smalley

Jen Easterly, the current director of CISA, noted this week that federal cyber officials will formally ask industry leaders for feedback for the regulatory structure for cyber incident reporting. This decision comes months after President Biden signed a new bill, the Consolidated Appropriations Act, into law, which requires critical infrastructure owners and operators to report major cyberattacks to CISA within 72 hours and ransomware attacks within 24. According to Easterly, “this will finally allow us a much better understanding what’s going on across the ecosystem… We don’t want to burden industry and we don’t want to burden the federal government with noise either.” Read more to find out why she thinks “defense needs to be the new offense” when it comes to cybersecurity.

Read more

3. Dev backdoors own malware to steal data from other hackers by Bill Toulas

Cybercriminals using Prynt Stealer, a type of info-stealing malware used to steal cryptocurrency wallet information, sensitive info stored in web browsers, VPN account data, cloud gaming account details, and more, has been backdoored so that any information stolen by the cybercriminal is also routed to the malware’s developer via Telegram. Read the full story from BleepingComputer to find out more about how Prynt Stealer works and which other malware families it may be related to.

Read more

4. TikTok Users Were Vulnerable to a Single-Click Attack by Dan Goodin

Microsoft stated recently that it discovered a vulnerability in TikTok’s Android app this past February, tracked as CVE-2022-28799, that could have allowed cybercriminals to hijack accounts after users clicked an errant link. According to researchers, “the vulnerability allowed the app’s deep link verification to be bypassed… Attackers could force the app to load an arbitrary URL to the app’s WebView, allowing the URL to then access the WebView’s attached JavaScript bridges and grant functionality to attackers.” Microsoft says there is no evidence the vulnerability was actively exploited in the wild.

Read more

5. Ukraine is under attack by hacking tools repurposed from Conti cybercrime group by Dan Goodin

As Ukraine continues to fight against Russian invasion, hackers with ties to the notorious Conti ransomware group have been repurposing tools to use in attacks against hotels, non-government organizations, and others in the war-torn country. But according to a researcher in Google’s Threat Analysis, "the attacker has recently shifted their focus to targeting Ukrainian organizations, the Ukrainian government, and European humanitarian and non-profit organizations," indicating that the attackers’ intentions may align with those of the Kremlin. Read the full story from Ars Technical for a full breakdown of recent incidents that have been linked back to these cybercriminals.

Read more

Tags: Data Privacy, Malware, Vulnerabilities

Recommended Resources


  • The seven trends that have made DLP hot again
  • How to determine the right approach for your organization
  • Making the business case to executives
  • Why Data Classification is Foundational
  • How to Classify Your Data
  • Selling Data Classification to the Business

Robbie Araiza

Robbie is a Content Creator for the Data Protection team at HelpSystems. Prior to joining the organization, he studied psychology and social work at Texas State University in San Marcos, TX.