Deloitte is a sitting duck: Key systems with RDP open, VPN and proxy 'login details leaked'

Yes, that's Gartner’s security consultancy of the year

Equifax CEO falls on his sword weeks after credit biz admits mega-breach

Well, what else could he do?

Mobile stock trading apps riddled with security holes

Did someone just nick your shares?

Docs ran a simulation of what would happen if really nasty malware hit a city's hospitals. RIP :(

DerbyCon Equipment still taking too long to patch, leaving systems exposed

Boffins take biometric logins to heart, literally: Cardiac radar IDs users to unlock their PCs

2026, when a change of heart will mean a pretty bad day

Researchers promise demo of 'God-mode' pwnage of Intel mobos

Black Hat Europe to reveal more trouble for Chipzilla's leaky Management Engine

Brit broke anti-terror law by refusing to cough up passwords to cops

Rabbani found guilty, vows to appeal after resisting demand for iPhone, laptop passcodes

CBS's Showtime caught mining crypto-coins in viewers' web browsers

Who placed the JavaScript code on two primetime dot-coms? So far, it's a mystery

Sensitive client emails, usernames, passwords exposed in Deloitte hack

Oops, did someone forget to turn on 2FA?

Insteon and Wink home hubs appear to have a problem with encryption

Which is to say neither do it

Brit military wants a small-drone-killer system for £20m

Too small for lasers, too big for nets

Cops shut 28k sites flogging knock-off footie kits and other tat

Warn Joe Public: they'll nick your ID and ruin your credit

Pesky users! They're always compromising endpoints! Security baked into silicon helps

Sponsored Intel chippery tech mitigates the most careless of workers

Guess – go on, guess – where a vehicle tracking company left half a million records

No prize, because it's too easy: SVR Tracking had an unsecured AWS S3 bucket

Shock! Hackers for medieval caliphate are terrible coders

DerbyCon Daesh-bags give up on writing their own attack code, copy successful hackers

Don’t fear the software shopkeeper: T&Cs banning bad reviews aren’t legal in America

DerbyCon Doesn’t stop them trying to put the frighteners, tho

Want to get around app whitelists by pretending to be Microsoft? Of course you can...

DerbyCon ...And here's how

Aw, not you too, Verizon: US telco joins list of leaky AWS S3 buckets

Now is a good time to go check your own Amazon settings. It's OK, we'll wait

NBD: Adobe just dumped its private PGP key on the internet

Updated Change the name to A-d'oh!-be

IoT botnet Linux.ProxyM turns its grubby claws to spam rather than DDoS

I don't know which is worse

Finance sector is littered with vulns, and guess what – most can be resolved by patching

But pen-testers have questioned the figures

Ethereum-backed hackathon excavates more security holes

Smart contracts language easy to use and create exploits with

Mini-Heartbleed info leak bug strikes Apache, airborne malware, NSA algo U-turn, and more

Roundup The security week in review

IT plonker stuffed 'destructive' logic bomb into US Army servers in contract revenge attack

He's now facing 10 years in prison for act of spite

Slain: Unions' US OPM mega-hack lawsuit against Uncle Sam

You have to get shafted before you can sue, says court

SEC 'fesses to security breach, says swiped info likely used for dodgy stock-market trading

EDGAR database a veritable goldmine of financial tips

Researchers claim ISPs are 'complicit' in latest FinSpy snooping rounds

Dictators' favourite spyware is working at the top, says report

Equifax fooled again! Blundering credit biz directs hack attack victims to parody site

Tim on the social media team will need a new job

You lost your ballpoint pen, Slack? Why's your Linux version unsigned?

No digital signature on hipster collab app means it's easy to make dangerous fakes

CCleaner targeted top tech companies in attempt to lift IP

Infected Avast tool's payload went after the likes of Microsoft, Intel and Cisco, hit 20 targets

Orland-whoa! Chap cops to masterminding $100m Microsoft piracy racket

Chinese national pleads guilty to running a massive counterfeiting ring

FedEx: TNT NotPetya infection blew a $300m hole in our numbers

File-scrambling malware put a bomb under shipping giant's sales growth

IT fraudster facing four years' bird time for $10k blackmail

Blackmailed former employer, redirected company website for porn portal

Manchester plod still running 1,500 Windows XP machines

Issue 'endemic' across public sector, shriek experts

Lloyds Bank payments glitch frustrates merchants

C'mon, you POS... >:(

More data lost or stolen in first half of 2017 than the whole of last year

That's 1.9 BEEELLION records – and just you wait till GDPR

