article thumbnail

Microsoft: Office 2013 will reach end of support in April 2023

Bleeping Computer

Microsoft has reminded customers this week that Microsoft Office 2013 is approaching its end of support next year, advising to switch to a newer version to reduce their exposure to security risks. [.].

Risk 98
article thumbnail

Credit Reporting Companies Put Customer Data at Risk

Adam Levin

Experian, 2013 – 2015: Hackers stole a trove of information from T-Mobile customers whose data had passed through Experian to check credit there and open a new account. The post Credit Reporting Companies Put Customer Data at Risk appeared first on Adam Levin.

Risk 218
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

The ticking time bomb of Microsoft Exchange Server 2013

DoublePulsar

I’ve discovered two organisations with ransomware incidents, where the entry point appears to have been Exchange Server 2013 with Outlook Web Access enabled, where all available security updates were applied. It was introduced in Exchange Server 2013. Obviously, almost nobody replied. Including Microsoft. I’d like to add some context.

article thumbnail

Two NSA Algorithms Rejected by the ISO

Schneier on Security

These algorithms were both designed by the NSA and made public in 2013. The risk of using NSA-designed ciphers, of course, is that they include NSA-designed backdoors. The ISO has rejected two symmetric encryption algorithms: SIMON and SPECK. They are optimized for small and low-cost processors like IoT devices.

IoT 194
article thumbnail

Why is Third-Party Risk Management important in 2021?

CyberSecurity Insiders

Third-party risk management is important because failure to assess third-party risks exposes an organization to supply chain attacks , data breaches, and reputational damage. This can include the management of sub-contracting and on-sourcing arrangements ( fourth-party risk ). What is third-party risk management?

Risk 134
article thumbnail

Qualys Automates Ransomware Risk Assessment

eSecurity Planet

Qualys this week launched a new Ransomware Risk Assessment Service that’s designed to help enterprises understand their potential exposure to ransomware and automate the process of patching any associated vulnerabilities or misconfigurations. CVE-2013-1493. March 2013. CVE-2013-0431. February 2013.

article thumbnail

First American Financial Pays Farcical $500K Fine

Krebs on Security

Under First American’s documented vulnerability remediation policies, the data leak was classified as a security weakness with a “level 3” severity, which placed it in the “medium risk” category and required remediation within 45 days. “The [employee] did not request a waiver or risk acceptance from the CISO.”

Insurance 336