Attacks/Breaches

3/14/2018
11:50 AM
50%
50%

SEC Charges Former Equifax Exec with Insider Trading

CIO of a US business unit within Equifax had reportedly learned of the company's data breach and sold his shares for nearly $1 million.

The Securities and Exchange Commission (SEC) has charged a former Equifax executive with insider trading ahead of the company's disclosure of a massive data breach in Sept. 2017. Jun Ying, a former CIO within a US business unit of Equifax, was next in line to be its global CIO.

The SEC alleges Ying used confidential corporate information to determine Equifax had been breached. Before Equifax disclosed the incident, the SEC claims Ying exercised his vested Equifax stock options and sold his shares, collecting nearly $1 million. The SEC says by selling his shares ahead of the company's announcement, he avoided more than $117,000 in losses.

"Corporate insiders who learn inside information, including information about material cyber intrusions, cannot betray shareholders for their own financial benefit," says Richard Best, director of the SEC's Atlanta Regional Office, in a statement. The SEC is charging Ying with violating the antifraud provisions of the federal securities laws.

This news follows updated guidance published by the SEC in Feb. 2018, that calls for public companies to give investors more intel on cybersecurity incidents and risks in a more timely fashion. The commission also states corporate officers, directors, and other insiders are not allowed to trade shares if they have unpublicized knowledge of a corporate security incident.

Read more details here.

Interop ITX 2018

Join Dark Reading LIVE for two cybersecurity summits at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the security track here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
More Than Half of Users Reuse Passwords
Curtis Franklin Jr., Senior Editor at Dark Reading,  5/24/2018
Is Threat Intelligence Garbage?
Chris McDaniels, Chief Information Security Officer of Mosaic451,  5/23/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11506
PUBLISHED: 2018-05-28
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer.
CVE-2018-11507
PUBLISHED: 2018-05-28
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm in image/image-pnm.cpp.
CVE-2018-11505
PUBLISHED: 2018-05-26
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
CVE-2018-6409
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.
CVE-2018-6410
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.