Iowa County Pays $600,000 Settlement to Security Professionals Wrongfully Arrested During Authorized Courthouse Assessment
By
MBCook
Half-baked but well-meaning. A passing snack.
Summary
Two security professionals who were arrested in 2019 after performing an authorized security assessment of an Iowa county courthouse will receive $600,000 to settle their lawsuit alleging wrongful arrest and defamation. Gary DeMercurio and Justin Wynn, penetration testers from Coalfire Labs, had written authorization from the Iowa Judicial Branch to conduct "red-team" security exercises but were arrested anyway. The settlement comes more than 6 years after their ordeal began.
Key quotes
· 4 pulledTwo security professionals who were arrested in 2019 after performing an authorized security assessment of a county courthouse in Iowa will receive $600,000 to settle a lawsuit they brought alleging wrongful arrest and defamation.
The case was brought by Gary DeMercurio and Justin Wynn, two penetration testers who at the time were employed by Colorado-based security firm Coalfire Labs.
The men had written authorization from the Iowa Judicial Branch to conduct 'red-team' exercises, meaning attempted security breaches that mimic techniques.
Settlement comes more than 6 years after Gary DeMercurio and Justin Wynn's ordeal began.
You might also wanna read
Phishing Campaign Targets Signal Users by Stealing Backup Recovery Keys
A new wave of phishing attacks is targeting Signal users by impersonating the app's support team. Hackers send messages inside Signal claimi
cybersecuritynews.com·5h agoCalifornia Sues 23andMe Over 2023 Data Breach Affecting Nearly 7 Million Users
California Attorney General Rob Bonta has filed a lawsuit against Chrome Holding Co. (formerly 23andMe) over a 2023 data breach that exposed
New phishing campaign targets Signal users to steal chat backup recovery keys
Hackers are targeting Signal users in a new phishing campaign that attempts to steal their chat backups. The attackers pose as Signal's supp
Weekly cybersecurity roundup: FortiClient EMS infostealer, Trend Micro Apex One exploit, and crypto payment security
A weekly roundup of cybersecurity news, featuring an interview with Coinflow's CISO about crypto payment security under AI-driven threats, c

CISA Adds Palo Alto Networks PAN-OS Authentication Bypass Vulnerability to Known Exploited Vulnerabilities Catalog
CISA has added a new vulnerability (CVE-2026-0257) to its Known Exploited Vulnerabilities (KEV) Catalog, affecting Palo Alto Networks PAN-OS

CISA Adds Palo Alto Networks PAN-OS Authentication Bypass Vulnerability to Known Exploited Vulnerabilities Catalog
CISA has added a new vulnerability (CVE-2026-0257) to its Known Exploited Vulnerabilities (KEV) Catalog, affecting Palo Alto Networks PAN-OS
