June 2021 Summaries
2 posts from Socket
Filter
Month:
Year:
Post Summaries
Back to Blog
A German court fined a security researcher €3,000 for unauthorized access and spying on data after he discovered and reported vulnerabilities in the systems of Modern Solution GmbH & Co., a company providing e-commerce services. The researcher's actions involved analyzing software on behalf of a client and revealing that the company stored customer passwords in plain text, a report which Modern Solution initially denied but subsequently acted upon to secure their systems. The case has sparked widespread debate over the implications for ethical hacking, with many in the cybersecurity community condemning the verdict as a potential deterrent to necessary security research. Critics argue that the court's decision undermines efforts to improve corporate software security and may discourage researchers from identifying vulnerabilities that could otherwise be exploited by malicious actors. The researcher has appealed the decision, highlighting the broader concern that such legal interpretations could stifle crucial cybersecurity initiatives and leave systems vulnerable.
Jun 23, 2021
1,111 words in the original blog post.
The US Justice Department has imposed a substantial $11.3 million penalty on consulting firms Guidehouse Inc. and Nan McKay and Associates for failing to meet cybersecurity requirements in federally funded projects, spotlighting a rigorous enforcement approach to safeguard sensitive government data. These firms, involved in the emergency rental assistance program during the COVID-19 pandemic, admitted to neglecting mandatory pre-production cybersecurity testing, leading to a security breach that exposed applicants' personal information. This enforcement action underscores the government's commitment to holding contractors accountable for cybersecurity lapses, as illustrated by the Civil Cyber Fraud Initiative launched in 2021. The case originated from a whistleblower lawsuit under the False Claims Act, which incentivizes individuals to report violations. This crackdown is part of a broader effort to ensure contractors adhere to cybersecurity measures, highlighted by other recent settlements involving companies like Verizon Business Network Services LLC, reinforcing the necessity for federal contractors to diligently maintain and secure information systems.
Jun 01, 2021
713 words in the original blog post.