Blog

SearchInform DLP, Hassas Verilerin Korunmasını 3 Adıma İndiriyor
SearchInform, yeni nesil DLP çözümü Risk Monitor’e 100’den fazla hazır güvenlik politikası ekledi. Güncelleme sayesinde güvenlik/BT ekipleri, kurumsal veriler için önceden yapılandırılmış kuralları birkaç adımda etkinleştirerek hassas bilgileri daha hızlı koruma altına alabiliyor.
Haftanın Alarmı: AMEX'e
Haftanın Alarmı: AMEX'e "İçerideki Erişim" Cezası
OAIC’nin AMEX kararı, yetkisiz erişimlerin; veri maskeleme, erişim kontrolü, loglama ve davranış analizi gibi katmanlarla neden proaktif biçimde yönetilmesi gerektiğini net biçimde gösteriyor.
Haftanın Alarmı: Diplomatik Veri Sızıntısında İç Tehdit Riski
Haftanın Alarmı: Diplomatik Veri Sızıntısında İç Tehdit Riski
Bu yazıda, diplomatik veri sızıntısı iddiası üzerinden iç tehdit riskleri, veri sınıflandırması, erişim kontrolü ve hızlı müdahale süreçlerinin neden kritik olduğu ele alınıyor.
SearchInform FileAuditor, Google Workspace'i Denetim Kapsamına Aldı
SearchInform, DCAP (veri merkezli denetim ve koruma) çözümü FileAuditor’un desteklediği veri kaynaklarını genişletti. Yeni özellikle birlikte FileAuditor, şirketlerin Google Workspace kurumsal bulut depolama alanlarını denetleyebiliyor.
Siber Günlük: GitHub Token Sızıntısı, Aşk Tuzağı ve Kurnaz Pazarlamacı
Siber Günlük: GitHub Token Sızıntısı, Aşk Tuzağı ve Kurnaz Pazarlamacı
Mayıs sayısında: Veri sızıntılarından BEC saldırılarına, GitHub token ihlalinden online aşk tuzağına ve içeriden dolandırıcılığa kadar ayın dikkat çeken siber güvenlik vakalarını derledik.
Haftanın Alarmı: Google’da İçeriden Bilgiyle Bahis Skandalı
Haftanın Alarmı: Google’da İçeriden Bilgiyle Bahis Skandalı
Bir Google yazılım mühendisinin, şirket içi arama trendi verilerini kullanarak Polymarket’te bahis yaptığı ve 1,2 milyon dolar kazanç elde ettiği iddiası, içeriden gelen tehditlerin yalnızca veri sızıntısı değil, doğrudan finansal suistimal riski de taşıdığını gösteriyor. Vaka, sıfır güven, ayrıcalıklı erişim kontrolü ve kullanıcı davranış analitiğinin kritik önemini yeniden gündeme taşıyor.
SearchInform DLP, Gizlilik Etiketi Taşıyan Dosyaların USB Belleklere Kopyalanmasını Engelliyor
SearchInform DLP’nin yeni özelliği, FileAuditor sınıflandırma etiketlerini kullanarak gizli bilgi içeren dosyaların USB belleklere aktarılmasını engeller.
SearchInform Sistemleri vs. Hacker'lar
SearchInform Sistemleri vs. Hacker'lar
Bu makalede, dahili kullanıcı hesaplarının ele geçirilmesi, uzak masaüstü erişimi ve zararlı yazılım yoluyla gerçekleştirilen veri sızdırma senaryolarını ele alıyor; DLP ve DCAP sistemlerinin bu tür girişimleri nasıl tespit edip engelleyerek kurumsal verileri koruduğunu açıklıyoruz.
Denizcilikte İç Tehditler: İnsider Kimdir ve Nasıl Korunulur?
Denizcilikte İç Tehditler: İnsider Kimdir ve Nasıl Korunulur?
Bu yazıda, insider tehditlerinin denizcilik şirketleri için neden kritik bir iş sürekliliği riski haline geldiğini ve bu risklerin DCAP, DLP, UEBA ve SIEM gibi çözümlerle nasıl azaltılabileceğini ele alıyoruz.
Veri Sızıntısı Olduğunda Ne Yapmalı? Şirketler İçin İlk 72 Saat Rehberi
Veri Sızıntısı Olduğunda Ne Yapmalı? Şirketler İçin İlk 72 Saat Rehberi
Veri sızıntısı yaşandığında hangi adımlar atılmalı? Teknik müdahale, hukuki süreç, kriz iletişimi ve itibar yönetimini kapsayan 6 kritik adımı kurumsal bakış açısıyla öğrenin.
Haftanın Alarmı: Gümrük Verileri Riskte
Haftanın Alarmı: Gümrük Verileri Riskte
Siber güvenlik uzmanı analizi: Hindistan Gümrük Dairesi’nde yaşanan veri sızıntısı vakası, içeriden gelen tehditlerin hassas kurum verileri için ne kadar ciddi bir risk oluşturduğunu gösteriyor.
Gizli Verileri Güvende Tutmanın 5 Pratik Yolu
Gizli Verileri Güvende Tutmanın 5 Pratik Yolu
Bu yazıda, kurumsal veri güvenliğini güçlendirmek ve sızıntı riskini azaltmak için uygulanabilecek 5 temel adımı bulabilirsiniz.
Çalışan İzleme Yazılımı: Şirketiniz İçin Hangisi Daha Uygun?
Çalışan İzleme Yazılımı: Şirketiniz İçin Hangisi Daha Uygun?
Personel zaman takip yazılımı, çalışan izleme sistemi ve DLP: Şirketiniz için hangisi daha uygun?
Siber Günlük: Yılın En Absürt Siber Olayları
Siber Günlük: Yılın En Absürt Siber Olayları
Siber Günlük'ün çok özel sayısında, dijital dünyanın en absürt ve ibretlik vakalarını bir araya getirdik. Polisin kendi eliyle yaptığı sızıntılardan havalimanlarını sarsan ihmallere kadar en ilginç hikayeler sizi bekliyor.
SearchInform DLP, Linux Bilgisayarlar için Açık Kontrol Yeteneklerini Genişletti
SearchInform, veri sızıntılarını önlemeye yönelik DLP çözümünde, kurumsal kullanıcıların güvenlik kuralları hakkında bilgilendirilmesini sağlayan özellikleri geliştirdi. Yeni güncellemeyle birlikte bu bildirimler artık Linux işletim sistemli bilgisayarlarda çalışan personel için de kullanılabiliyor. Sistem, USB belleğe veri kopyalama, mesaj gönderme ya da belge yazdırma gibi riskli bir işlemi engellediğinde; kullanıcı ekranda açılan uyarı penceresiyle engellemenin nedenini görebiliyor.
SearchInform FileAuditor’un Linux Tabanlı Dosya Sunucuları Üzerindeki Denetim Yetenekleri Genişletildi
SearchInform, DCAP çözümü SearchInform FileAuditor’un Linux altyapılarındaki yeteneklerini artırdı. Yeni geliştirmeyle birlikte çözüm, kurumsal verilerin tutulduğu Linux tabanlı dosya sunucuları ve ağ depolama sistemlerini de denetim kapsamına alabiliyor, ayrıca bu ortamlardaki veri hacmini de dikkate alıyor.
Haftanın Alarmı: Kripto Şirketinde Kaynak Kodu Hırsızlığı
Haftanın Alarmı: Kripto Şirketinde Kaynak Kodu Hırsızlığı
Memnuniyetsiz bir çalışanın ekran fotoğrafları ve toplu indirmelerle veri sızdırması, şirkete 300.000 Euro'ya mal oldu. DLP ve DCAP sistemlerinin bu tür senaryoları nasıl engellediğini ve hibrit altyapılarda tam kontrolün nasıl sağlandığını analiz ediyoruz
Ramazan Bayramı Mübarek Olsun!
Ramazan Bayramı Mübarek Olsun!
Sevdiklerinizle birlikte nice güzel bayramlar geçirmenizi dileriz!
8 Mart Dünya Kadınlar Günü Kutlu Olsun!
8 Mart Dünya Kadınlar Günü Kutlu Olsun!
Yüzünüzdeki gülümseme hiç solmasın, gözlerinizdeki ışıltı asla sönmesin!
Siber Günlük: Bulutlardaki Delikler, Sosyal Mühendislik ve Lüks Ceza
Siber Günlük: Bulutlardaki Delikler, Sosyal Mühendislik ve Lüks Ceza
Şubat ayı siber güvenlik olayları özeti: Veri sızıntısı cezaları, kripto hırsızlığı, bulut güvenlik açıkları ve yeni nesil phishing saldırıları. Güncel tehditler ve detaylar haberimizde.
DLP Nedir? DLP Sistemleri Ne İşe Yarar ve Nasıl Çalışır?
DLP Nedir? DLP Sistemleri Ne İşe Yarar ve Nasıl Çalışır?
DLP’nin ne olduğunu, neden gerekli olduğunu, nasıl çalıştığını ve kurumlara sağladığı temel faydaları ele alıyoruz.
Webinar Duyurusu | DLP Yatırımı: Yönetimi İkna Etme ve Doğru Çözüm Seçme Rehberi
Webinar Duyurusu | DLP Yatırımı: Yönetimi İkna Etme ve Doğru Çözüm Seçme Rehberi
Bilgi güvenliği çözümleri geliştiricisi SearchInform, 27 Ocak Salı günü “DLP Yatırımı: Yönetimi İkna Etme ve Doğru Çözüm Seçme Rehberi” başlıklı bir webinar düzenliyor.
Siber Günlük: Samsung’da Dram, Coupang’da Trajikomedi, Ubisoft’ta Robin Hood Filmi
Siber Günlük: Samsung’da Dram, Coupang’da Trajikomedi, Ubisoft’ta Robin Hood Filmi
2026’ya “hoş geldin” derken aralık-ocak döneminde kulağımıza en çok takılan siber vakaları bir araya getirdik. Menü yine kalabalık. Çaylarınız hazırsa başlıyoruz.
Haftanın Alarmı: Hindistan’da Kaynak Kod Sızıntısı
Haftanın Alarmı: Hindistan’da Kaynak Kod Sızıntısı
Amadeus Software Labs India’da yaşanan olayı inceliyoruz.
SearchInform DLP’ye Linux Ortamları için Yeni Engelleme Seçenekleri Eklendi
SearchInform DLP çözümünde, Linux işletim sistemlerine yönelik son güncellemeyle birlikte anlık mesajlaşma uygulamaları, video konferans programları, çıkarılabilir depolama aygıtları ve uzaktan bağlantılar için gelişmiş engelleme seçenekleri devreye alındı.
KVKK’dan Peş Peşe İki Önemli Güncelleme
KVKK’dan Peş Peşe İki Önemli Güncelleme
KVKK, veri ihlali duyurularının yayında kalma süresine ilişkin yeni bir uygulamayı duyurdu. Aynı zamanda 2026 yılı için idari para cezaları, yeniden değerleme oranı yansıtılarak güncellendi.
Haftanın Alarmı: ABD Kamu Kurumlarında Veri İhlalleri
Haftanın Alarmı: ABD Kamu Kurumlarında Veri İhlalleri
Ocak ayının başında ABD’de iki farklı eyaletteki İnsan Hizmetleri Departmanları (DHS – sosyal hizmetler bakanlığı benzeri) veri güvenliği olayı duyurdu.
Webinar Duyurusu | Çalışan İzleme: Stalk mı, Makul Kontrol mü?
Webinar Duyurusu | Çalışan İzleme: Stalk mı, Makul Kontrol mü?
Bilgi güvenliği çözümleri geliştiricisi SearchInform, Beyaz.Net iş birliğiyle 27 Ocak Salı günü webinar düzenliyor.
2026’nın Bilgi Güvenliği Anti-Trendleri
2026’nın Bilgi Güvenliği Anti-Trendleri
Her yılın başında, farklı uzmanlardan “Önümüzdeki yıl bizi ne bekliyor?” türü tahminler yağmur gibi yağar. Biz bu kez tersinden bakalım dedik: Artık eskimiş, etkisini yitirmiş, hatta riski artıran güvenlik araçları ve alışkanlıklar hangileri? Listede kendinizi görürseniz, kurum içi güvenlik pratiklerini gecikmeden gözden geçirmenin zamanı gelmiş demektir.
Yeni Yılınız Kutlu Olsun!
Yeni Yılınız Kutlu Olsun!
Geride bıraktığımız yıl boyunca gösterdiğiniz güven ve iş birliği için yürekten teşekkür ederiz. 2026’nın hedeflerinize ulaştığınız, başarılarınızın arttığı bir yıl olmasını dileriz.
Siber Günlük – 2025’e Veda: Bira Rafları Boş, Sızıntı Sınırları Taştı, Gerçekle Yapay Karıştı
Siber Günlük – 2025’e Veda: Bira Rafları Boş, Sızıntı Sınırları Taştı, Gerçekle Yapay Karıştı
2025’te siber güvenlik gündemi boş durmadı. Yıl biterken “klasik” vakalara film gibi dosyalar da eklendi: BBC’ye içeriden sızma girişimi, yüz tanımada kopya çekilen mesai sistemi, yapay görselle trenlerin durması ve dahası. Buyurun, yılın en akılda kalanlarına.
SearchInform DLP’ye Whisper-AI Tabanlı Konuşma Tanıma Modülü Entegre Edildi
SearchInform, DLP platformunda sesli içerik denetimi için kullandığı otomatik konuşma tanıma (ASR) yeteneklerini genişletti. Artık SearchInform DLP, ek bir yapay zekâ modeli olarak Whisper-AI modülünü de konuşma tanıma motoru olarak kullanabiliyor ve sesli veriler üzerinde içerik analizi yapabiliyor.
SearchInform Ürünleri, Debian 12.11 Tabanlı İş İstasyonlarında Kurumsal Veriyi Koruyor
SearchInform, DLP ve DCAP ürünlerinde Linux tabanlı işletim sistemlerine yönelik desteğini genişletti. Çözümler artık Debian 12.11 tabanlı iş istasyonlarını da kapsamlı biçimde kontrol edebiliyor.
Tesadüflerle Şekillenen Bir Yol: Murat Göçe ile Teknolojiden Medyaya, Yapay Zekâdan Kuantuma
Tesadüflerle Şekillenen Bir Yol: Murat Göçe ile Teknolojiden Medyaya, Yapay Zekâdan Kuantuma
BThaber Başkanı ve aynı zamanda değerli iş ortağımız Murat Göçe ile teknolojiden medyaya uzanan etkileyici kariyer yolculuğunu; yapay zekânın medya ve iş dünyası üzerindeki etkisini, Türkiye’de siber güvenliğin gerçeklerini, regülasyonların rolünü ve ufukta beliren kuantum çağını konuştuk.
DLP’nin Gerçek Maliyeti Nelerden Oluşur?
DLP’nin Gerçek Maliyeti Nelerden Oluşur?
Kaliteli bir DLP çözümünün neden her zaman en ucuz seçenek olmadığını ve düşük fiyat etiketinin arkasında ne tür sürpriz maliyetlerin saklanabileceğini birlikte inceleyelim.
Siber Günlük: Usta İşi BEC, Rüzgârdan Kripto ve Verilerin Intel’e Vedası
Siber Günlük: Usta İşi BEC, Rüzgârdan Kripto ve Verilerin Intel’e Vedası
Kasımı kapatırken klasik siber vakalara film senaryosu tadında olaylar da eklendi. Bu ay: usta işi bir BEC saldırısıyla 254 bin doların buhar oluşunu, rüzgâr santralinde kurulan kripto çiftliğini, intikam ateşiyle tetiklenen parola tsunamisini ve daha fazlasını konuştuk. Çaylar demlendiyse başlıyoruz.
Çalışanlara Bilgi Güvenliği Farkındalığı Eğitimi: Nelere Dikkat Edilmeli?
Çalışanlara Bilgi Güvenliği Farkındalığı Eğitimi: Nelere Dikkat Edilmeli?
Gerçekten işe yarayan bir eğitim programı tasarlarken nelere dikkat etmek gerekir? Yıllar içinde edindiğimiz gözlemleri pratik önerilerle sizlerle paylaşıyoruz.
30 Kasım Dünya Bilgisayar Güvenliği Günü Kutlu Olsun!
30 Kasım Dünya Bilgisayar Güvenliği Günü Kutlu Olsun!
Bugün vesilesiyle şifreleriniz biraz daha sağlam, antivirüsünüz hep güncel, siber ortamdaki dikkatiniz de tam olsun!
2025’te Kurumların %21’i Çalışan Kaynaklı Veri Sızıntısıyla Karşılaştı
2025’te Kurumların %21’i Çalışan Kaynaklı Veri Sızıntısıyla Karşılaştı
SearchInform’un Türkiye’de 103 kamu ve özel kurumun BT ve siber güvenlik yöneticileriyle yürüttüğü anket çalışması, iç tehditlerin kurumlar üzerindeki etkisini ve güvenlik yaklaşımlarındaki olgunluk farklarını değerlendirmektedir.
Webinar Tekrarı | SearchInform vs. Forcepoint / Symantec / GTB
Webinar Tekrarı | SearchInform vs. Forcepoint / Symantec / GTB
Gelen yoğun ilgi ve talep üzerine, bilgi güvenliği çözümleri geliştiricisi SearchInform, sektörde öne çıkan dört DLP sistemini bir kez daha canlı yayında karşılaştıracak: SearchInform, Forcepoint, Symantec ve GTB. Webinar boyunca bu çözümlerin işleyişini ile güçlü ve zayıf yönlerini doğrudan değerlendirme olanağı bulacaksınız.
SearchInform FileAuditor, Jira ve Confluence’ta Dosya Denetimini Devreye Aldı
SearchInform FileAuditor, artık Jira ve Confluence üzerinde paylaşılan dosyaların içeriğini denetleyebiliyor.
SearchInform, DLP ve DCAP Çözümlerinin Performansını Artırdı
SearchInform, büyük ölçekli kurulumlara yönelik DLP ve DCAP çözümlerinin çalışma mimarisini optimize etti.
Volkan Kaplan: “AI vs. AI dönemi geliyor”
Volkan Kaplan: “AI vs. AI dönemi geliyor”
Talus’un kurucusu Volkan Kaplan ile bir araya gelerek DLP’nin önemini, iş birliği için SearchInform’u seçme nedenlerini ve Türkiye’deki şirketlerin veri güvenliğine bakışını değerlendirdik.
Siber Günlük: Kül Olan Veriler, Koğuştaki “Mucize” ve Yeni Nesil Dualar
Siber Günlük: Kül Olan Veriler, Koğuştaki “Mucize” ve Yeni Nesil Dualar
Cadılar Bayramı temalı korku filmi arıyorsanız, bu ayki siber olaylar fazlasıyla yeterli. Devlet bulutunun gerçekten yandığı, bir mahkûmun içeriden sistemi hack’lediği, Las Vegas casinolarının bir lise öğrencisi tarafından çökertildiği ve yapay zekânın “dua ticaretine” alet edildiği bir aydan bahsediyoruz. Buyurun, Ekim’in siber güvenlik günlüğüne.
SearchInform FileAuditor, Microsoft 365’te Veri Erişim Yetkilerinin Dağıtımını Denetleme Özelliğini Kullanıma Sundu
FileAuditor DCAP çözümü, Microsoft 365 içinde paylaşıma açık dosya ve klasörlerde gerçekleştirilen işlemler için ayrıntılı denetim desteği kazandı.
SearchInform FileAuditor, Tüm Gizli Dosya İşlemlerini Tek Raporda Topladı
DCAP sistemine gelen güncelleme, kullanıcıların gizli dokümanlarla gerçekleştirdiği işlemleri değerlendirmeye yönelik ayrıntılı bir raporu kullanıma sundu.
29 Ekim Cumhuriyet Bayramımız Kutlu Olsun!
29 Ekim Cumhuriyet Bayramımız Kutlu Olsun!
Türkiye Cumhuriyeti’nin 102. yılını gurur ve mutlulukla kutluyor, başta Gazi Mustafa Kemal Atatürk olmak üzere tüm kurtuluş mücadelesi kahramanlarımızı saygı ve minnetle anıyoruz.
Veri Sızıntılarını Durdurun: Yeni Nesil DLP’nin Fark Yaratan Yetenekleri
Veri Sızıntılarını Durdurun: Yeni Nesil DLP’nin Fark Yaratan Yetenekleri
Beyaznet ve SearchInform, 5 Kasım 2025’te “Veri Sızıntılarını Durdurun: Yeni Nesil DLP’nin Fark Yaratan Yetenekleri” başlıklı online webinar düzenleyecek.
SearchInform DLP Web Konsolunda FileAuditor Arşivinde İçerik Arama Desteği Kullanıma Sunuldu
SearchInform DLP’nin web konsolu, FileAuditor verileri üzerinde içerik aramasını desteklemeye başladı.
Siber Günlük: Açık Menü, Çocuk Hackerlar ve 115 Siparişlik Vurgun
Siber Günlük: Açık Menü, Çocuk Hackerlar ve 115 Siparişlik Vurgun
Eylülü uğurlarken geride tuhaf ve öğretici siber olaylar bıraktık. Eylül ayı boyunca; Coinbase dosyasındaki yeni perde, bir başka delik deşik yapay zekâ platformu ve ABD hızlı servis zincirlerinde çıkan açıklar çok konuşuldu. Türk işi söyleyelim: çayı demleyin, ayrıntılar bol.
SearchInform vs. Forcepoint / Symantec / GTB: Karşılaştırmalı İnceleme
SearchInform vs. Forcepoint / Symantec / GTB: Karşılaştırmalı İnceleme
9 Ekim 2025 saat 11.00’de, bilgi güvenliği çözümleri geliştiricisi SearchInform, sektörün önde gelen dört DLP sistemini canlı yayında karşılaştıracak: SearchInform, Forcepoint, Symantec ve GTB. Webinar boyunca bu çözümlerin işleyişini, güçlü ve zayıf yönlerini doğrudan değerlendirme olanağı bulacaksınız.
SearchInform FileAuditor’da Dosyalara Geçici Erişim Sağlama Aracı Kullanıma Sunuldu
SearchInform, DCAP çözümü FileAuditor’a kısıtlı erişime sahip dosyalar için geçici yetkilendirme ihtiyacını karşılayan yeni bir erişim yönetimi özelliği eklediğini duyurdu.
Siber Günlük: McDonald’s Açıklarından Pokémon Kartlarına
Siber Günlük: McDonald’s Açıklarından Pokémon Kartlarına
Siber güvenlik dünyası sadece virüs, fidye yazılımları ya da açıklarla çalkalanmaz. Bazen bir muhasebeci bütün düzeni yerinden oynatır. Bazen bir yazılımcı emeklilik planlarını bir kart oyunu uğruna yakar. Ağustos tam da bu «bazenlerden» biri oldu. Buyurun, içinden Pikachu, mahkeme ve Shrek geçen siber güvenlik günlüğüne.
SearchInform DLP, Paylaşımlı Ağ Klasörlerine Veri Yazmayı Kontrol Altına Aldı
SearchInform DLP, veri sızıntılarını gerçekleşmeden önce önlemeye yönelik araç setini genişletti.
Veri Korumanın Türkiye Rotası: Engin Özşahin ile Sektöre İçeriden Bakış
Veri Korumanın Türkiye Rotası: Engin Özşahin ile Sektöre İçeriden Bakış
Sohbet Ağı röportaj serimizin ilk bölümüne hoş geldiniz. Bu seride; Türkiye’de bilgi güvenliğine bakış açısını, DLP ve DCAP çözümlerinin bugünü ile geleceğini, SearchInform ürünlerinin öne çıkan yönlerini ve daha fazlasını konuşacağız. İlk konuğumuz, Türkiye’deki ilk partnerlerimizden biri olan Everhub Bilişim Teknolojileri’nin kurucusu Engin Özşahin. Kendisiyle hem sektöre hem de iş birliğimize dair keyifli bir sohbet yaptık. Hadi başlayalım!
Siber Günlük: Çalışmadan Maaş, Bitcoin’le Market Alışverişi ve Daha Fazlası
Siber Günlük: Çalışmadan Maaş, Bitcoin’le Market Alışverişi ve Daha Fazlası
Siber güvenlik dünyasında bazı aylar vardır ki, sadece kötü amaçlı yazılımlar ya da sıfır gün açıkları değil; tamamen insan faktörü manşetleri belirler. Temmuz ayı da tam olarak böyleydi: içeriden vurulan şirketler, intikamcı sistem yöneticileri, işini yapmadan maaş alan efsanevi yazılımcılar… Buyurun, Temmuz’un bol ibretli siber güvenlik günlüğüne.
SearchInform DLP’de Yeni Özellik: Buluta Aktarımlar Raporlanıyor
Yeni geliştirilen sistem raporu, kullanıcıların bulut depolama hizmetleriyle etkileşimlerini analiz ederek güvenlik politikalarının daha etkili yapılandırılmasına yardımcı oluyor.
FileAuditor’dan Amazon S3 Desteği: Kurumsal Bulutlara Tam Denetim Geliyor
​​​​​​​SearchInform, FileAuditor yazılımına S3 protokolü desteği ekledi. Yeni özellikle birlikte, bulutta tutulan veriler daha güvenli ve şeffaf biçimde yönetilebilecek.
Yapay Zeka Desteğiyle SearchInform’un DLP ve DCAP Sistemleri Güç Kazandı
SearchInform, DLP ve FileAuditor ürünlerine entegre ettiği yeni yapay zeka destekli motor sayesinde görsel analiz süreçlerini hızlandırdı. Bu geliştirme sayesinde, kurumsal verilerdeki görseller artık OCR (optik karakter tanıma) kullanılmadan, doğrudan içeriklerine göre sınıflandırılabiliyor.
Siber Günlük: Veriler Sızdı, Şirketler Battı, Hacker'lar Kaçtı
Siber Günlük: Veriler Sızdı, Şirketler Battı, Hacker'lar Kaçtı
Haziran ayında öne çıkan olaylar arasında, tek bir hesapla 300 bin kişiyi hedef alan bir hacker, fidye yazılımı saldırısıyla iflas eden köklü şirketler ve “dünyanın en büyük veri sızıntısı” başlığıyla gündeme gelen dev siber sızıntı yer aldı. Buyurun, Haziran’ın siber günlüğüne...
Siber Günlük: Veri Manyakları, 21 Milyon Adetlik Fiyasko ve Belalı USB
Siber Günlük: Veri Manyakları, 21 Milyon Adetlik Fiyasko ve Belalı USB
Karşınızda aylık bültenimizin ilk sayısı! Bu seride, güvenlik dünyasından en karmaşık – ve kimi zaman gülümsetecek kadar ilginç – olayları derleyip sizinle paylaşacağız.
SearchInform DLP'den Linux İçin Gelişmiş USB Veri Koruması
SearchInform DLP (veri sızıntısı önleme) sistemi, Linux işletim sistemli bilgisayarlar için DeviceController modülünü güncelledi.
Saat ve Saat, Veri Koruma İçin SearchInform'u Tercih Etti
Saat ve takı zinciri Saat ve Saat, bilgi güvenliğini üst seviyeye çıkarmak için SearchInform'un geliştirdiği DLP, FileAuditor ve TimeInformer sistemlerini kullanmaya başladı.
SearchInform DLP, Linux İçin Yazdırma ve Pano Engellemelerini Devreye Aldı
SearchInform’un DLP (veri sızıntısı önleme) çözümü, Linux işletim sistemli bilgisayarlarda güvenliği bir adım öteye taşıyor. Sistem, yazdırma işlemlerini kontrol eden PrintController modülüne getirdiği yeni özellikle, belirli kullanıcılar, cihazlar ve gruplar için yazıcı kullanımını sınırlandırma yeteneği kazandı.
SearchInform Türkiye’de Konumlandı
SearchInform Türkiye’de Konumlandı
2020 yılından bu yana DLP ve DCAP çözümleriyle Türkiye pazarında yer alan bilgi güvenliği yazılımları üreticisi SearchInform, İstanbul’da katma değerli distribütörlük şirketi kurduğunu duyurdu.
SearchInform, Risk Monitor Karantina Modülünün Performansını Optimize Etti
Yeni nesil DLP sisteminin e-posta kontrol modülü, artık daha hızlı çalışıyor ve kullanıcı dostu bir arayüz sunuyor.
Two Major Data Incidents and New Cybersecurity Strategy for UAE
Two Major Data Incidents and New Cybersecurity Strategy for UAE
Last week was eventful for cybersecurity. A huge data leak happened in a Brazilian bank; records about 30 million clients were exposed. The AI platform leaked personal information and chat history, including sensitive documents. In order to address cybersecurity issues, the UAE launched the National Cybersecurity Strategy.
Series of Data Leaks in Turkey, CAT’s Data is Stolen in Brazil
Series of Data Leaks in Turkey, CAT’s Data is Stolen in Brazil
In this overview you’ll find details on the following incidents: two Turkish universities experienced personal data breach, while energy holding lost its data; personal details and information about legal bodies was exposed as a result of data leak in Brazil.
First Data Leak from DeepSeek and Potential Insider Involvement in Kenya
First Data Leak from DeepSeek and Potential Insider Involvement in Kenya
Chinese AI DeepSeek keeps everyone’s attention-news about a data leak was as loud as its release. Over a million log lines became accessible; the breach also enabled privilege escalation. Simultaneously, Kenya’s governmental body leaked over 2 million records. Without many words, let’s dive in!
(In)Secure Digest: FortiGate leak, Google phishing Ads, Trojan gadgets
(In)Secure Digest: FortiGate leak, Google phishing Ads, Trojan gadgets
It's time to find out what happened in the field of information security in January. In this Digest, you’ll find the most notable data breaches from the last month.
Golden Classics of Data Breaches and Increased Fines
Golden Classics of Data Breaches and Increased Fines
In this weekly digest, we will look at two different incidents. They have something in common—both of them could be put in an information security textbook. Wrong addressee for email and gap in cloud storage security rules. At the same time, Turkey raised fines for data protection for 2025.
Data Breach of Tech Giant and Publication of Draft Data Protection Rules
Data Breach of Tech Giant and Publication of Draft Data Protection Rules
Recently it became known that valuable data was stolen from Hewlett Packard Enterprise, examination results were leaked in South Africa, while a draft of key data protection law was published in India. Learn more about these events in this weekly digest.
ICAO and South African Companies Fell Victim to Data Related Incidents
ICAO and South African Companies Fell Victim to Data Related Incidents
The beginning of the new year was marked by a bunch of major information security incidents. Let’s dive into the incidents, which happened with the International Civil Aviation Organization and South Africa Govchain and Cell C companies.
(In)Secure Digest: 2024’s Internal Fumbles
(In)Secure Digest: 2024’s Internal Fumbles
With 2024 drawing to a close, we have rounded up some of the year’s eye-catching incidents where internal factors stole the spotlight. From mishaps to true malice of insiders, these stories have it all. Take a moment to read and see what lessons can be learned!
Namibia is under Attack, Kenya Bolsters Data Protection Laws
Namibia is under Attack, Kenya Bolsters Data Protection Laws
Namibia is affected by a big data breach, including contractual records and personal data of high-ranking officials, while neighboring Kenya enhances its own Data Protection Act.
Central Bank of Brazil exposed sensitive information
Central Bank of Brazil exposed sensitive information
The Central Bank of Brazil reported that a data leak occurred on the 4th of December. According to the statement made by the Central Bank, the incident is a result of operational error during publishing the survey results.
Round-Up of Severe Data Leaks in Asia
Round-Up of Severe Data Leaks in Asia
In this weekly review of data security incidents, you will find details on the alleged theft of identity cards data in Malaysia and an incident with the cloud storage provider in Hong Kong.
Troves of Personal Data Were Exposed, While Regulators Work on Protection
Troves of Personal Data Were Exposed, While Regulators Work on Protection
In this weekly overview of major security incidents, you will learn about a several cases, which lead to exposure of hundreds of GB of confidential data.
(In)Secure Digest: Baguettes' Thief, Disney Sabotage, Credentials' Waterfall
(In)Secure Digest: Baguettes' Thief, Disney Sabotage, Credentials' Waterfall
It's time to review November's most noticeable and high-profile information security incidents. In this digest, you’ll find: a multi-million-dollar scam by a former top manager, a “cyber-poisoner” at Disney World, echoes of the MOVEit hack at Amazon and others.
Algeria Faces 70M Attacks While Tesla Breach Turns Out False
Algeria Faces 70M Attacks While Tesla Breach Turns Out False
As November wraps up, headlines tell of cybercriminals targeting Algeria and a recent data breach mistakenly linked to Tesla. Let’s explore the details.
Africa’s Security Landscape: Kenya Rises, Nigeria Struggles, SA loses data
Africa’s Security Landscape: Kenya Rises, Nigeria Struggles, SA loses data
This week’s digest is packed with news from Africa. Let’s explore how the continent is battling with cybersecurity problems.
(In) Secure Digest Halloween Edition: What Spooked IS Specialists in October
(In) Secure Digest Halloween Edition: What Spooked IS Specialists in October
The Halloween agenda includes a million-dollar scam, a hacker offended by non-recognition of merit, and frighteningly frequent attacks on the game industry representatives.
UAE’s AI Investments & LinkedIn’s GDPR Fine
UAE’s AI Investments & LinkedIn’s GDPR Fine
The last IS news roundup of October is here for you—let’s dive in!
The New Portion of Insider Incidents: Cases of Remote Employee and CISO
The New Portion of Insider Incidents: Cases of Remote Employee and CISO
In this incident roundup, we are exploring two cases of customer data leakage with insiders being accused of security rules violation.
The Pokémon Developer and Well-known Electronic Device Manufacturer are Facing Data Leaks
The Pokémon Developer and Well-known Electronic Device Manufacturer are Facing Data Leaks
In today's roundup, we'll discuss how unauthorized access to Game Freak's servers and a ransomware attack on Casio resulted in the leak of a trove of confidential personal and corporate data.
Qatar’s Data Breach Fine & Kenya’s Move Toward Digital Inclusion
Qatar’s Data Breach Fine & Kenya’s Move Toward Digital Inclusion
In this week’s new roundup, we are exploring the details of the data breach that occurred in Qatar and how Africa is making its way to digital safety.
(In) Secure Digest: Cyberattack on Dell, Fortinet Cloud Leak, Blackmailing Employee
(In) Secure Digest: Cyberattack on Dell, Fortinet Cloud Leak, Blackmailing Employee
A roundup of high-profile IS incidents that occurred or came to light last month is here. During September, we witnessed attacks on IS vendors and the leaking of data on millions of Americans.
UAE Warns Residents About Cyber Traps
UAE Warns Residents About Cyber Traps
Today we will talk about the UAE authorities' warnings regarding malicious advertising and... sharing secrets with ChatGPT.
Data Watchdog Fines Nigerian Banks for Compromising Data
Data Watchdog Fines Nigerian Banks for Compromising Data
In this review, we examine how Nigerian banks are getting slammed with fines for noncompliance with regulatory requirements.
Indonesia’s ID Leak & Link Between Layoffs and Data Breaches
Indonesia’s ID Leak & Link Between Layoffs and Data Breaches
Today, we are here with updates on a data breach investigation from Indonesia and news of an extremely interesting study on the correlation between mass layoffs and increasing data breaches.
From Cyber Stars to Data Scars: Africa's Top Cybersecurity Role Models Shine as Cameroon Faces Major Data Breach
From Cyber Stars to Data Scars: Africa's Top Cybersecurity Role Models Shine as Cameroon Faces Major Data Breach
This week’s IS news roundup comes from Africa. Let’s delve into the Global Cybersecurity Index report and see where African countries rank on it, and explore the details of a serious data breach in Cameroon.
Slim CD Breach and Turkish Ministry Data Leak
Slim CD Breach and Turkish Ministry Data Leak
Here’s the first news roundup of the autumn, where we explore the details of the Slim CD data breach and provide updates on the Turkish Ministry of Health information leak during the pandemic.
(In) Secure Digest: Netflix Leak, McDonald's Scammers, Rodents vs.Tokens
(In) Secure Digest: Netflix Leak, McDonald's Scammers, Rodents vs.Tokens
In this review: a nightmare for League of Legends fans, the largest leak in US history, and another Microsoft outage.
Data Security Failures of the Week
Data Security Failures of the Week
In today’s IS news roundup, we will explore the details of the FlightAware and Enzo Biochem cases.
Another Day, Another Leak
Another Day, Another Leak
The past week brought various news about severe data breaches. In this digest, we look at the details of the most significant cases.
Malaysia's Information Security Boost and the UK's $9.6 Million Data Blunder
Malaysia's Information Security Boost and the UK's $9.6 Million Data Blunder
Today we will explore Malaysia’s significant step towards mitigating data leaks and the consequences of a 2022 ransomware attack on a British IT company.
(In) Secure Digest: Stolen Shib Coins, the Disney Villian, and the Leak of Millions of Americans' Data
(In) Secure Digest: Stolen Shib Coins, the Disney Villian, and the Leak of Millions of Americans' Data
In this edition: the latest twist in the Snowflake saga, the adventures of robots.txt, and the case of meme-coin theft.
Rising Breach Costs, AI’s Double-Edged Sword, and HealthEquity’s Data Drama
Rising Breach Costs, AI’s Double-Edged Sword, and HealthEquity’s Data Drama
In the last IS news roundup for July, we cover the key findings of IBM and Ponemon's Cost of a Data Breach Report 2024 and share details of the HealthEquity case.
A Turbulent Week for Tech and Travelers
A Turbulent Week for Tech and Travelers
This week's news roundup might not be the most uplifting for those planning a trip. However, it is important to dive deeper into the recent events to ensure you are well-informed before you head to the seaside.
Lulu Data Breach & SOC Future Study
Lulu Data Breach & SOC Future Study
In this week’s digest we are to explore the details of the recent data breach in a major retail company and the key takeaways of the research on SOC future.
Roblox Incident & Security Pros’ Fears
Roblox Incident & Security Pros’ Fears
Today we are going to talk about the details of the Roblox data breach and the main outcomes of a recent cybersecurity professionals survey.
Why Data Theft Can't be Tolerated – Yet Still it Happens
Why Data Theft Can't be Tolerated – Yet Still it Happens
It’s impossible to completely exclude the possibility of data theft, given the speed with which technology is developing and the volumes of assets going digital. However, the risks can be mitigated.
Insurance Market Shake-Up & Digital Diary Breach
Insurance Market Shake-Up & Digital Diary Breach
In this week's IS digest, we will delve deeper into the news about a recent incident and explore the outcomes of new research.
(In) Secure Digest: Wiped Out Servers, Phish in Sales, and Summer Leak Season
(In) Secure Digest: Wiped Out Servers, Phish in Sales, and Summer Leak Season
In our June review, we look at recent information security incidents reported in the media during the first month of summer.
Cybersecurity Remains a Top Concern as Professionals Face Burnout
Cybersecurity Remains a Top Concern as Professionals Face Burnout
The present news digest explores the main findings of recent research on burnout among cybersecurity experts and the state of smart manufacturing in the automotive industry.
Beware of Fakes and Exes
This week’s news digest is about how fired and fake employees can cause disasters.
Cybersecurity Challenges Revealed by New Research & the Epsilon Case Completion
In this week’s cyber news review, we are going to delve deeper into the recent CDW research findings and the Epsilon case updates.
A Bunch of Fines for Serious Breaches
A Bunch of Fines for Serious Breaches
In this overview we are reporting on two recent major data leaks, which resulted into loss of troves of data and significant penalties by regulatory authorities.
April 2024 Breaks Data Breach Records
In the text below, we will take a closer look at a couple of the recent cyber incidents.
(In) Secure Digest: the Unprotected Server, the Marine Data Leak and a Supply Chain Attack
(In) Secure Digest: the Unprotected Server, the Marine Data Leak and a Supply Chain Attack
In May's edition, we'll reveal: the case of an unscrupulous medical company; accidental data leak caused by the SaaS vendor; consequences of the India's largest electronics manufacturer negligence.
(In) Secure Digest: if There was Darwin Awards in 2024
(In) Secure Digest: if There was Darwin Awards in 2024
In April, we traditionally ask our Leading Analyst Sergio Bertoni to share his selection of funny, ridiculous and silly IS incidents.
How to Select Data Security Solution and not Fall for Marketing
With information security threats on the rise, vendors release a slew of data protection solutions. Sergio Bertoni, Lead Analyst at SearchInform suggests following 4 steps to choose the one easily and avoid mistake.
(In)Secure Digest: Mega Leaks, Deepfakes Calls and Ransomware Attack
(In)Secure Digest: Mega Leaks, Deepfakes Calls and Ransomware Attack
In our traditional monthly digest, we've gathered a bunch of recent information security incidents.
8 Dangerous Employees’ Actions Which Endanger Corporate Security
8 Dangerous Employees’ Actions Which Endanger Corporate Security
Sergio Bertoni, the Senior analyst at SearchInform reveals typical mistakes basing on the real life stories.
Travel Agency and COVID-19 Testing Platform Exposed Client Data
In this article you’ll find details on two notifiable information security incidents.
(In) Secure Digest The New Year Edition: Stolen Code, DNA leaks and Safe Data Leak
(In) Secure Digest The New Year Edition: Stolen Code, DNA leaks and Safe Data Leak
In the final digest of 2023, we’ll tell about stealing corporate secrets, putative labourers, genetic information leaks and very vindictive employees.
Connected Devices Remain the Most Popular Data Leakage Channel
SearchInform together with its partner NEXTA ÇÖZÜM surveyed representatives of 100 Turkish leading companies to find out how their experts ensure data leaks protection, whether they are planning to increase data security budgets and what data channels their security officers consider the riskiest.
Ways to Ensure Children’s Safety on the Internet: Cybersecurity Experts’ Views and Advice
On the occasion of World Children’s Day, we share an article, containing recommendations and a few tools, which can help to protect children from inappropriate content on the Internet.
(In)Secure Digest: a Leak via Contractor, Hack of Airline and Case of Corporate Fraud
(In)Secure Digest: a Leak via Contractor, Hack of Airline and Case of Corporate Fraud
At the end of the month, traditionally, we’ve  gathered a selection of high-profile IS incidents.
Casio and Redcliffe Labs Data Leaks Expose Customer Information
Today, let's examine the incidents those resulted in the disclosure of customer information at two large companies.
Film Festival Website Leak and Data Theft by Former Employee
Once again, we've rounded up two information security incidents worth knowing about with a short report to keep you informed.
A Case in Point: You’ve got Mail
Recently, it was the birthday of electronic mail. To celebrate the occasion, we would like to share the case study from our practice that involves email.
Not all the DLP Solutions are Equally Useful: How to Choose the System and not be Disappointed
In this article we will examine, DLP class systems reproaches are fair and which ones are unfair and will reveal, which limitations are typical for all DLP systems and which are in fact disadvantages of some specific products.
E-mail Compromise: How to Protect Business Against BEC-attacks
The senior analyst at SearchInform, Sergio Bertoni reveals, why BEC attacks are so popular and how to protect against them.
38TB Private Data Leak and $9,000 Fine for 7 Years of Customer Data Exposure
38TB Private Data Leak and $9,000 Fine for 7 Years of Customer Data Exposure
In a new roundup of recent information security incidents, we examine two more cases of inadvertent disclosure of private information.
How to Train Employees in Information Security Related Issues Efficiently
In this article, Sergio Luis Bertoni, Leading Analyst at SearchInform will share my observations, based on the practical experience in the sphere of educational courses development.
A Case in Point: Set a Search Rule to Catch a Thief
It's time to present a compelling case study that underscores the criticality of maintaining comprehensive visibility into your organization's file system.
Ransom Demand for Human Error and Two-year Data Leakage
Today we will examine two recent instances of data disclosure, both of which, as is often the case, have resulted in serious financial and reputational losses for the companies involved.
Leaked personal data of more than 500,000 employees and an unprotected 4GB database
Leaked personal data of more than 500,000 employees and an unprotected 4GB database
Today you will learn about the data leak of over 500,000 employees from a major clothing retailer and the 4GB open database from a popular digital publisher.
Two recent incidents involving inadvertent personal data exposure
In our new report on recent information security incidents, we examine two cases of inadvertent disclosure of personal data.
Two recent insider incidents: Tesla and Jefferson Health affected
It's time for another roundup of recent information security incidents. Today we're going to reveal details of the Tesla insider incident and the alleged patient data compromise at Jefferson Health.
SearchInform SIEM system – out-of-the box analytics and proactive incident management
Employees in charge of numerous organizations worldwide tend to understand the necessity to implement a SIEM class solution, which detects security events within the digital infrastructure.
Bunch of new personal data leak incidents: police officers and hospital patients affected
In this report we reveal details on the recent major data related incidents: exposure of hospital patients’ and police officers’ personal data.
(In)Secure Digest: a patented data leak, Bangladeshi open register and water treatment plant hack
(In)Secure Digest: a patented data leak, Bangladeshi open register and water treatment plant hack
The time has come to find out if July was full with information security incidents. In our traditional digest we've gathered the most memorable incidents.
A case in point: The thirst for revenge
A case in point: The thirst for revenge
Over the years of working, we have collected a large number of interesting cases. Some of them are amusing, some of them are surprising, but most of them has prevented serious losses for our clients. So, we figured: Why not share them with you?
Sabotage of a water treatment facility: a former employee endangered the health of thousands of people
We often report on incidents involving former employees. This time it is an incident that could have had serious consequences not only for the company itself but also for a large number of people.
Exposure of 61,000 private addresses and one more email error
Exposure of 61,000 private addresses and one more email error
This week we will look at two incidents that have affected thousands of people by exposing their personal information.
Human Vulnerabilities in Cyber Security
As technology continues to advance, one persistent problem remains: the vulnerability of humans to cyberattacks.
Implementation department specialists' workdays: millions of questions and the requirement to know literally everything
Implementation department employees can help customers to quickly manage to work with our solutions and benefit as much as possible from the software usage.
MSSP vs MDR
MSSP vs MDR
MSSP vs MDR: what should you choose? This article will help you understand which one suits to your business needs better.
Inadvertent disclosure of personal information
The Public Appointments Service accidentally leaked the personal data of 15,471 candidates for public jobs.
Risks of neural networks and chat bots usage
SearchInform expert reveals artificial intelligence usage related risks and shares advice on how to mitigate them.
One more victim of MOVEit application vulnerability and exposure of data on 260,000 car owners
Learn more about two recent data incidents, which affected Toyota and Prudential subsidiaries' clients.
How to put on a vacation
How to put on a vacation
We implement a few strategies to ensure secure access and help employees not to forget all the IS rules while they're on the road. Let's have a look at the checklist and find out, how we do it.
(In)secure digest:  data leaks with mileage, refuse to use AI and hack of an account
(In)secure digest: data leaks with mileage, refuse to use AI and hack of an account
The time has come for our traditional gather of so-called classic and extraordinary information security incidents, which were reported by mass media.
Recent data privacy incidents
A data leak and massive phishing attack on social network users.
Risk Management Certification
Let's consider one of the most significant frameworks for managing risk is ISO 31000, an international standard that provides principles, best practices, and guidelines for managing risk in organizations.
The new portion of significant data incidents
Recently details on a number of tremendous data related incidents were exposed.
More than half of companies limit their protection with nominal information security literacy
A research on how companies prefer to train employees in information security and what methods do they implement
(In)Secure digest: if there was the “Darwin Award” in information security sphere – 2023 edition
(In)Secure digest: if there was the “Darwin Award” in information security sphere – 2023 edition
In this April compilation, you’ll find details on aquarium fraudsters, the financial manager, who squandered the company's money, "super-secure" apps, but something went wrong with them and much more.
EPP vs EDR
What is the difference between EPP and EDR? Do they complement each other or they should be used separately?
A new portion of fines for inadequate data protection
A new portion of fines for inadequate data protection
Details on a few cases when companies, which failed to implement adequate data protection were fined.
Best Digital Forensics Certifications
The article helps you answer the three most important questions when choosing the right IT security and digital forensics certification.
Australian companies have experienced large data privacy incidents
Australian large company Latitude Financial, involved in the financial industry and IP firm IPH have experienced data privacy incidents.
Large troves of tech giants’ data leaked
Large troves of tech giants’ data leaked
Recently, ACER and Acronis companies’ have experienced massive data related incidents.
Large retailer employees’ data leaked
WHSmith, British retailer has experienced an incident, which led to employees’ personal data leak.
A famous video game publisher has recently experienced an alleged data related incident
An unidentified intruder has exposed Activision employees’ data. Overall, nearly 20.000 recordings were made publicly available.
Which sources should be controlled by the SIEM system first of all?
Which sources should be controlled by the SIEM system first of all?
It is very useful to maximize the SIEM system load to make sure that you won’t face a situation when something does not work appropriately in the real-life circumstances.
AI media manipulation service has leaked large trove of users’ data
AI photo editor Cutout.pro users’ data was leaked. Overall, 9 GB of generated pictures and other data was exposed.
The SearchInform DLP deals with the smartphone threat
Learn how the SearchInform DLP functionality helps to detect, whether an insider has a smartphone in hands.
Fizzy giant manufacturer experienced a data related incident
Fizzy giant manufacturer experienced a data related incident
Pepsi Bottling Ventures LLC data was illicitly obtained and extracted because of deployment of info stealer malware.
Data privacy incident in the healthcare sector
Details on a cybersecurity incident in the healthcare sector became publicly known recently.
Email marketing service hacked
MailChimp mail service was hacked… again
Update on the Last Pass data related incident
The data leak, which happened in August turned out to be much more serious that it was believed initially.
Resonant cases of data leakages in APAC region
Resonant cases of data leakages in APAC region
There is a step change taking place in the number of data-related incidents and that is critical.
Data on 5.6 million users exposed
Social Blade, the American social media analytics service has experienced a massive data related incident.
Uber experienced another data related incident
Uber experienced one more data related incident. However, no link between the September incident and this one has been established.
The “misalignment of databases” resulted into a massive data related incident
A large data related incident has recently affected Australian telecom giant Telstra clients.
In(secure) digest: lost accounts, compensations for mega leaks and “quick as the wind” leaks
In(secure) digest: lost accounts, compensations for mega leaks and “quick as the wind” leaks
This time we’ve gathered data on serious incidents: attacks on large companies, phishing, forgetful employees, whose actions led to the loss of clients’ data.
Notifiable Privacy Breaches
What is required to do if a data breach incident somehow takes place?
Cyber Threats to National Security
Cyber Threats to National Security
National Cybersecurity: this is how the cyber threat has intensified
Recent data leak incidents
A brief overview of two recent data leak incidents.
Booz Allen Hamilton Holding Corporation experienced a data breach
Due to insider's actions some personally identifiable information was exposed in a recent incident.
Data Loss Prevention Use Cases
This article will help you to learn how to avoid losing data.
Benefits of Managed Security Services
How to implement efficient information security protection with MSSP?
Famous Data Breaches
General Data Protection Regulation, fines, real cases.
Recent Security Breaches
Recent Security Breaches
Young employees, zero trust security and other security breach risks.
Healthcare Cyber Attacks
What makes healthcare organizations a popular target for cyber attacks?
Retail online marketplace clients' data leak
Recently, data on 2.2 million customers of Australian retail markeplace has leaked
Best Network Security Software
What should you look for when choosing a provider of best network security software?
(in)Secure digest: boredom motivated attacks, love to fines and ethical hack
We’ve compiled a selection of information security incidents, which became publicly known in September.
Fraud Cases
Fraud Cases
How to detect some common types of fraud and what may you do about it
Car manufacturer clients' data exposure incident
An inappropriate method of code storage has resulted into a data exposure incident
Outsourcing Security Services
Internal and external information security personnel
Cyber Attacks on Critical Infrastructure
Critical infrastructure: current situation and best cybersecurity practices
A large database with personal data has been leaked
A 6GB database, which allegedly contained personal information on 16 million users has been leaked.
Best Practices for Network Security
The ultimate guide to securing your industrial network using the best network security practices
Biggest Cyber Attacks in History
An overview of some of the most notorious cyberattacks
Australian telecom breached
Australian telecommunications company breach turned out to be one of the biggest cyberattack in Australian history
Emerging Cyber Threats
An overview of cyber threats, endangering companies and organizations worldwide in 2022.
Data Privacy Day
What is The European Data Protection Day and why data privacy is so important
Worst Data Breaches
Prerequisites and consequences of data breaches
Best SIEM Tools
What is a SIEM system and how to choose one?
Best Endpoint Protection
Best Endpoint Protection
What is an efficient endpoint protection and a slight overvierw of best solutions.
(In)secure digest: the smell of data leaks, deep fake in the Zoom and an option of becoming the nobility member for only €1000
In August many employees are still on a vacation, however, this doesn’t refer to fraudsters, judicial and law enforcement system representatives.
Microsoft credentials leak
Internal login credentials were accidentally uploaded to the company’s own infrastructure on GitHub.
Internet-marketing giant clients’ data leak
Klaviyo clients' data leak took place because of phishing attack
Insider Threat Statistics for 2022 The seriousness of insider threat
What is an insider threat and who is an insider? What types of insider threats exist? How to detect an insider threat and what is required to do in order to mitigate risks? You may refere to the article and find out.
A real fortune was made on phone unlocking and unblocking
An American resident managed to earn $25 million by a phone unlocking and unblocking service.
Significant fines are imposed due to information security incidents
Significant fines are imposed due to information security incidents
Recently, plenty of news on fines imposed due to information security incidents have been published. Let’s have a look at a few significant cases, which took place lately.
Confidential documents and personal data leaked due to an insider activities
Central Florida construction firm has recently experienced a data breach. An employee stole a massive of confidential data just before resignation.
Sensitive Data Of Colorado Springs Utilities Clients Leaked
Colorado Springs Utilities notified their customers via email that sensitive data was obtained by an “unauthorized party”. The problem appeared to be on a subcontractor side. The name of the company remains unrevealed due to “security reasons”.
Razer data breach case: a claim against IT solution provider is filled
Due to a security misconfiguration by third-party IT-solution provider, Razer's client's data was at a stake of being exposed.
Demotivation for intruders: no more ransom payments
Recently the National Cyber Security Centre (NCSC) and the Information Commissioners Office (ICO) published a joint letter, addressed to the Law Society.
Exposure of 23 million users’ data
Exposure of 23 million users’ data
Due to the dangerous misconfiguration of a third-party database owner, personal data of 23 million users was exposed.
(In)secure digest: personal data newsletter, hacked state services and endangered farmers
The time has come to reveal some “classic” and non-trivial information security incidents. As usual, we’ve gathered some of the most impressive cases of the month in our digest.
Insider incident affected nonfungible token (NFT) marketplace
This time, one of the largest nonfungible token (NFT) marketplace experienced an insider related data leak.
Avaya system administrator: illegal licenses generating and selling
Avaya system administrator was accused of fraud. It was stated that together with accomplices he sold software with additional options for IP-ATC. The overall sum of their financial operations exceeds $88 million.
Another personal data leak CafePress clients affected this time
Another personal data leak CafePress clients affected this time
CafePress got its consumers’ sensitive personal data, including Social Security numbers, exposed. The claim against Residual Pumpkin Entity, former owner of CafePress and PlanetArt, current owner of CafePress was filled by the Federal Trade Commission. The main issue of the claim is that the organization had failed to ensure safety of client’s personal data (including Social Security numbers), and covered up the data breach.
Important trends in corporate security
In this article we continue to deal with the topic of corporate security, and we’ll provide a slight overview of some information security trends and advice on how top-managers may eliminate the ongoing risks.
Massive database exposed to public access
Another data leak has taken place recently. About 60 GB of data has been exposed to public access.
General Motors clients’ personal data was obtained by intruders
General Motors, one of the leading car manufacturer accepted the fact, that last month cybercriminals managed to conduct the credential stuffing attack.
Excessive data supplement
According to newest research, people are becoming more conscious in their work with data. Still, a lot of excessive data is transmitted.
I resolve to… leave those security errors for good in 2021
I resolve to… leave those security errors for good in 2021
The resolutions for businesses to begin the New Year without old mistakes finally cleaning up the awareness mess which never seems to be untangled
Panasonic is recovering from a 4-month exposure
The company detected the incident only after a discovery of an extreme network traffic.
Major fraud cases in healthcare revealed this year
Pfizer discovers an insider working for a competitor, whereas Genentech hit the news with a deep-rooted story months ago.
When your sellers obtain your data
Amazon program was misused by its sellers, and data was intended for rankings boosting. California Pizza Kitchen announces a data employee breach.
Robinhood employee tricked by social engineering
7 million users got their data affected in the breach announced by Robinhood.
What kind of DLP system do you need in 2022?
David Balaban reflects on the DLP vendors' race for attention, adding of new features, sometimes going beyond the boundaries.
Ransomware attacks keep companies on alert
The amount isn't disclosed as the hackers' groups haven't received the companies reaction yet
Acer offices in Taiwan hacked
This year the company has already faced a major incident as they were to pay a $50-million ransom.
The more they know the less they care
More and more people are unwilling to share their personal data with third parties
Facebook security upgrade decision leaked
The company decided to exempt a number of employees from groups which have access to internal message boards.
Former employees took company's security issue to court
The company's staff is aware of what information security is, and disregard to data safety decreases the loyalty of workers.
Data overexposed in manufacturing sector
The relevant statistics and most common security issues in 2021 so far
Government sector faces human factor data breach issue
Government sector faces human factor data breach issue
Australian public sector is concerned with the growing number of information leakage episodes due to employee mistakes.
Dallas schools compromised by a city IT employee
Whereas a disgruntled former employee's case was brought to the court.
How to configure DLP and not to overlook a leak
How to configure DLP and not to overlook a leak
How efficient are DLP systems with preset configurations? Can a system be configured once and for good? Learn how to adjust the settings here.
Former employees and foolhardy ransomware attackers
Several information security incidents which have happened recently are all based on utter carefreeness
T-Mobile hacked for the 5th time
The unauthorized access was detected a few days after a number of customers got their data affected.
Russian officials obliged to use only domestic messengers
Ministry of Digital Development prepares a regulatory framework for transferring state employees to state-owned platforms by December 2021. 
Tokyo visitors' data affected
Olympics ticket holders and event volunteers' details have been compromised
Does an identity theft has an end or any terms?
Does an identity theft has an end or any terms?
Education workers of the Francophone Sud School District are dealing with identity theft.
Will or won't paying ransom be made illegal?
Another surge of ransom attacks makes the necessity to remind how slippery the way to deal with them is if you choose to pay.
DarkSide behind Guess breach
The famous fashion retailer Guess has officially announced a data breach comprising details of 1,300 people,
Air India is asked to recompense the breach
The affected customers might be given more than $400,000 for having their data impacted.
Call a hacker - he'll tell you about a breach
Don't have enough information about how the data breach occurred? Speak with the hacker who let it happen.
Treasurer’s office vs. mayor
Westfield clerk treasurer's office brought the case regarding the city's mayor act to court
JBS chose to pay ransom
JBS, the largest meat producer, paid a $11 million ransom, according to Andre Nogueira, chief executive of Brazilian JBS SA’s U.S. division
Euro 2020 fraudulent websites
Euro 2020 fraudulent websites
It has been recently explored that since the beginning of the year there have been 130 new domains registered – all related to EURO 2020 (EURO 2021) tickets.
Trello boards indexed by major search engines put at peril business processes of Russian companies
Almost a million Trello boards, thousands of which contain corporate data of large and small Russian companies, were publicly available.
UK Special Forces soldiers aren't sure in their data safety
Over 1,000 UK Special Forces soldiers got their data exposed. The document containing their personal data was distributed via WhatsApp.
Why FileAuditor? SearchInform customer gives an elaborate answer
SearchInform customer – scientific technological pharmaceutical company Polysan – has deployed FileAuditor, a DCAP system, and shared the first impression with the company.
Why is it important to control third-party security policies?
According to the recent report it seems that roughly half of companies don't know how to deal with third-party security
Microsoft threat and database security time bomb
Companies using Microsoft 365 might jeopardise their data safety and be more vulnerable than those who don't. 19 petabytes of data are exposed right now according to CyberNews.
Order in your files and folders: how to organize access control and protection against leaks
Expansion of the IT infrastructure complicates controlling who accesses, copies, moves from folders, and deletes information.
Was there a breach?
Companies refuse to admit leakage accusing announcers of misleading its readers.
All about invisible DLP control and where its invisibility ends
The DLP doesn’t function in a hidden mode for nothing: on the one hand, it doesn’t interfere with the work of respectable employees, on the other hand, it helps to catch insiders off guard.
Fraudsters won’t miss a chance — what threats to people and business remain in 2021
The “Roaring 20s” is no longer a euphemism from the last century, in the 21st the new decade also began loudly.
Shell goes through a data breach
Shell goes through a data breach
Accellion service the company uses got destabilised by a hack
(In)Secure digest: default passwords, sensitive info for free, and phisher salary
Every month we collect "classic" and non-trivial incidents on Infosecurity across the world and in Russia in particular. Here is our first digest for 2021.
iPhones which weren't meant for selling
An employee of a recycling company profiteered from selling Apple products
ABSA leak might still have impact
ABSA leak might still have impact
How is ABSA bank doing after an employee’s security policy violation?
Insider check: could you be damage to your company?
The test will define you as a certain type of insider. Remember: any employee could become a culprit of a leak, however, circumstances are different. We don’t mean to pretend “scientific”, we intend to make this test entertaining and informative.
Legal monitoring, smartphones control and your employee personal portrait
These and other ticklish issues regarding the launch of information security solution within your system.
Signal replaces WhatsApp?
The most popular messenger has recently announced an update which made users question its necessity
Ex-employee takes data to a new job
Ex-employee takes data to a new job
SoftBank former employee took data to another company, whereas a Canadian firm Aurora Cannabis informed its staffers about breached personal data on the last day of the year.
Why does healthcare require the severest cybersecurity measures?
Why does healthcare require the severest cybersecurity measures?
Innovations are designed to improve the quality of service and save time for patients and doctors, however, doctors and patients realize how vulnerable medical information is.
2020 infosec in pictures
You've been with us all this year and you remember all 2020 news we've shared with you. Let's smile and frown at it together!
Ledger hardware wallet breach echoes with phishing
The investigation into the Ledger compromised security case was launched after the data breach which dates back to June 25, 2020.
An entire database stolen, Microsoft hacked
People’s Energy company faces an overwhelming data exposure, Microsoft becomes another company tricked by hackers via SolarWinds in case the investigation proves it.
FAQ: Frequently Asked and Finally Answered
FAQ: Frequently Asked and Finally Answered
15 questions the monitoring solution developer responds to during seminars.
South Koreans data was leaked by Facebook
South Koreans data was leaked by Facebook
Facebook is penalized by South Korea’s regulatory authority for divulging user data.
(In)secure digest: Tesla sabotage, hospital blackmailer and excessively patriotic President
(In)secure digest: Tesla sabotage, hospital blackmailer and excessively patriotic President
Every month we enrich our collection of classic and non-trivial cybersecurity cases. Data leaks, frauds, sabotage, and other incidents caused by insiders are of our interest.
Indian companies chose cloud
83% of companies chose cloud to deal with cybersecurity issues of remote work quick
How much can a former employee cost you?
Keeping the accounts of dismissed employees active and failing to revoke excessive rights might be one of the biggest mistakes a company can make.
U.S. city will pay the Office for Civil Rights $202,400
New Haven, Connecticut, didn’t deny access and left confidential health information available to a former employee.
A customer guessed a password
A customer guessed a WeWork shared user account password for employees
Aetna charged $1m for three data breaches under HIPAA
The HIPAA (the Health Insurance Portability and Accountability Act) has exacted a $1 million penalty from Aetna, U.S. health care insurance company.
Awareness doesn’t prevent from human factor
Employees keep opening emails even though they look like a phishing attack
British Airways has been charged £20 million
British Airways has been charged £20 million
British Airways have been charged £20 million instead of paying £183 million – the initial fine imposed by the Information Commissioner’s Office.
Shifting to the cloud
Almost half of IT companies shifted to the cloud during the lockdown
10 questions about the DLP system: why do I need it, what can I do, and what can't I do?
10 questions about the DLP system: why do I need it, what can I do, and what can't I do?
Today DLP system’s purpose is not just monitoring data leaks as it was in the beginning - now DLP systems are commonly used to solve a much broader list of problems.
Rights and wrongs when creating profile
How can you analyse employee personality and steer clear of breaching privacy?
Letter Bültenimize abone olun! Sektör trendlerini takip edin, veri sızıntıları ve siber olaylara karşı nasıl önlem alacağınızı öğrenin.