Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

December 2009

December 31, 2009

TSA Subpoenas Bloggers, Wants to Know Who Leaked Airline Security Changes

In the wake of an alleged terrorist attempt to bring a bomb onto a U.S.-bound plane, the Transportation Security Administration has subpoenaed two bloggers who wrote about a directive to increase sec... More >

Microsoft Downplays Claims of IIS Flaw

According to V3.co.uk , Microsoft is insisting that there is no critical flaw in the company’s popular Internet Information Services Web server product.   Earlier this week, security research... More >

Network Box: Phishing Attacks Surge in December

It may come as no surprise that phishing attacks soared in December as cyber criminals looked to take advantage of the higher number of online shoppers in the run up to Christmas.   V3.co.uk ... More >

December 30, 2009

Penn State Victim of Security Breach

According to eSecurity Planet , Penn State University is notifying some 30,000-plus students of a series of malware-induced data breaches that exposed their personal information for an unknown per... More >

Laptop Theft Puts MBNA Customers at Risk

MBNA has confirmed that customer data has been compromised following the theft of a laptop from the offices of credit and finance firm NCO Europe. According to SC Magazine , the laptop contained s... More >

Hacker Gonzalez Pleads Guilty Again

Computer hacker Albert Gonzalez has pleaded guilty to two counts of conspiracy in Boston in the final three cases brought by federal prosecutors, reports The Wall Street Journal . Under the plea a... More >

December 29, 2009

McAfee: Adobe to Be Top Target for Hackers in 2010

According to McAfee's "2010 Threat Predictions" report, Adobe Systems' Flash and Acrobat Reader products will become the top targets for hackers in 2010, reports Computerworld .   With Micros... More >

Researcher Hacks GSM Encryption

According to TG Daily , German security expert Karsten Nohls claims he has cracked the GSM encryption algorithm , making calls vulnerable to snooping. Using equipment that cost a few thousand dolla... More >

December 28, 2009

DDos Attack Strikes Amazon

InformationWeek reports that Amazon.com and Amazon Web Services were affected by a DDoS attack last Wednesday that struck their DNS provider, UltraDNS. UltraDNS says there was never an outage, but... More >

Researcher Warns of New Critical IIS Flaw

Security researcher Soroush Dalili is warning of a highly critical new zero-day vulnerability in Microsoft’s Internet Information Services web server product, V3.co.uk reports. The vulnerability ... More >

Judge Gives Preliminary Approval to Countrywide Settlement

U.S. District Judge Thomas B. Russell has granted preliminary approval to a settlement between Countrywide Financial Corp. and as many as 17 million customers whose financial data was exposed in a ... More >

December 23, 2009

Former Inmate Sentenced for Prison Hacking

A former prison inmate faces 18 months back in the slammer for hacking a computer provided to help inmates with their legal research, reports Computerworld .   The thin client device was supp... More >

December 22, 2009

Palisade Offers DLP for Facebook, Twitter

CTO Edge reports that Palisade Systems, which makes its data loss prevention technology available as a service, now supports Facebook and Twitter protocols in its PacketSure service for DLP . &nbs... More >

Will Microsoft's 'Whitelist' Help Hackers?

Computerworld reports that Trend Micro has taken exception with Microsoft's publishing of a list of file extensions and folders that the tech giant believes can be excluded from antivirus scans. T... More >

Conflicting Reports About Alleged Citibank Hack

There are conflicting stories regarding an FBI investigation of an alleged theft of an estimated tens of millions of dollars from Citibank by hackers.   According to Computerworld , the securit... More >

December 21, 2009

MessageLabs Warns of MP3 Spam

Researchers at MessageLabs say that a spam attack using MP3 files has surfaced. According to V3.co.uk , the scam uses a sound file to advertise a pharmacy site that sells Viagra. Although, the mes... More >

Donbot Revives Pump-and-Dump Scam

According to researchers at MessageLabs, the Donbot network has been linked to a rash of stock-related spam messages that try to get users to invest in a low-priced stock. V3.co.uk says that once... More >

Heartland Reaches Settlement with American Express

According to V3.co.uk , Heartland Payment Systems has reached a $3.6 million settlement with American Express . While Heartland has set aside more than $12 million to compensate credit card compani... More >

Twitter Hack Linked to Internal Credentials

Somebody used a “set of valid Twitter credentials ” to redirect Twitter visitors to an Iranian opposition Web site, Tom Daly, chief technology officer at Dyn, told Wired News . From our perspective... More >

December 18, 2009

Iraqi Insurgents Hack U.S Drones

Iraqi militants have used $26 off-the-shelf software to intercept live video feeds from U.S. Predator drones , reports The Wall Street Journal .   Although U.S. officials say there is no evide... More >

Twitter Hijacked by Pro-Iranian Hackers

The New York Times reports that Twitter was the target of a cyber attack that disrupted the microblogging service for many users. Twitter founder Biz Stone says hackers broke into the company’s do... More >

Cloud Security Alliance Publishes New Guidelines

PCWorld.com reports that the Cloud Security Alliance has published the second edition of its guidelines for secure cloud computing . The voluminous document (76 pages) provides an architectural fra... More >

Hacker Hits Computer Server for N.C. Colleges

According to WRAL.com , a hacker gained access to a computer server for 25 North Carolina community colleges that contained the personal information of nearly 51,000 people . The information includ... More >

December 17, 2009

Five Notable Security Breaches of 2009

Companies continue struggle more with usual security issues likes lost laptops, unpatched or poorly coded software and inadvertent disclosures, rather than sneaky new attack techniques. To illustrate... More >

China ISP Hardest Hit By Conficker

According to data by Shadowserver, China Telecom's Chinanet has been the hardest hit by the Conficker worm , reports Computerworld . The Chinese ISP had more than 1 million infected systems, which ... More >

Reporter Hacks Minnesota State Data

A recent security breach involving the state of Minnesota has caused all kinds of trouble.   As the Houston Chronicle reports, the incident began when Minnesota Public Radio reporter Sasha Asl... More >

RockYou Hack Exposes More Than 30 Million Accounts

Social-networking application maker RockYou Inc. suffered a database breach that allowed hackers to access username and password information on more than 30 million people, according to Computerwo... More >

December 16, 2009

Court Dismisses BJ's Data Breach Suit

The Massachusetts Supreme Judicial Court has thrown out a lawsuit by dozens of credit unions against BJ's Wholesale Club over a 2004 data breach, Computerworld reports. The court ruled that the wh... More >

Mozilla Patches 10 Firefox Security Bugs

Computerworld reports that Mozilla has fixed 10 vulnerabilities with the release of Firefox 3.5.6. Five of the flaws are rated critical by Mozilla, one is considered high, three are tagged as mode... More >

Scammers Target Google's Doodle

On Tuesday, scammers exploited the illustration on Google's front page to redirected users to malicious advertisements or pages that tried to trick visitors into buying rogue antivirus software, re... More >

Detroit Medical Information Missing Following Two Security Breaches

According to Freep.com , two security breaches have put the personal medical information of an estimated 10,000 Detroit citizens at risk.   The first theft occurred in October when a flash d... More >

December 15, 2009

Adobe Looking Into Zero-Day Exploit

Hackers are after Adobe Reader and Acrobat again. Adobe is looking into the exploitation of a vulnerability in the most up-to-date versions of the applications, according to Computerworld .  ... More >

December 14, 2009

FBI Says Scareware Peddlers Have Raked in $150 Million

According to the FBI, rogue anti-virus programs have raked in more than $150 million , reports Computerworld . As a result, the FBI's Internet Crime Complaint Center is warning Web surfers to be wa... More >

Gartner Warns of Two-Factor Authentication Vulnerabilities

According to Gartner, businesses need to take new approaches to counter attacks on strong authentication factors . Hackers' persistence has led to attacks that can now circumvent two-factor authenti... More >

December 11, 2009

Kaspersky Offers New Encryption Tool

When you take a step back, the list of data breaches can seem almost never ending. The problem is such that the government has gotten involved in enacting the HITECH Act , the nation's first federal... More >

December 10, 2009

Hacker Gonzalez Pleads Guilty in New Jersey

Hacking mastermind Albert Gonzalez has agreed to plead guilty to federal charges he faces in New Jersey. Reuters reports. Gonzalez has been linked to electronic break-ins at New England grocer H... More >

Verizon Profiles 15 Most Common Security Attacks

In its ‘An Anatomy of a Data Breach' report, Verizon details the 15 most common attacks in 2009 , reports SC Magazine . According to this press release , the top five attacks are: Keylogging and... More >

Adobe Patches Seven Flash Vulnerabilities

Adobe has patched seven vulnerabilities in its Flash Player. According to Computerworld , six of the seven are considered critical and could be used to hijack Windows, Mac or Linux machines.  ... More >

Security Breach Exposes Notre Dame Employees' Info

A University of Notre Dame employee accidentally posted files containing the names, Social Security numbers and ZIP codes of employees on a publicly accessible university Web site. According to Com... More >

Judge Dismisses Heartland Lawsuit

SC Magazine reports that a U.S. District Court judge in New Jersey has dismissed a shareholder lawsuit "with prejudice" against Heartland Payment Systems . U.S. District Court Judge Anne E. Thompso... More >

December 9, 2009

TSA Employees Put on Leave After Manual Posted Online

According to The Washington Post , Homeland Security Secretary Janet Napolitano told the Senate Judiciary Committee at an oversight hearing that the Department of Homeland Security has initiated pe... More >

SSL Vulnerability Leaves VPN Open to Attack

The U.S. computer emergency readiness team (US-CERT) has reported on a vulnerability that applies to SSL products that use the SSL URL rewriting technique.   SC Magazine reports that the vuln... More >

Researcher Demos Pentagon XSS Vulnerability

A researcher, going by the alias "Ne0h," has posted two proof-of-concept scripts for a months-old cross-site scripting (XSS) vulnerability affecting the Web site for the Pentagon, reports SC Magaz... More >

Trend Micro Warns Cyber Crooks Will Get Bolder

According to Trend Micro's annual Future Threat Report, an increasingly crowded underground market could push cyber criminals to try new and more aggressive tactics, reports V3.co.uk .   Incr... More >

Microsoft Says BitLocker Threat Exaggerated

Following reports from German security researchers that PCs and laptops protected with BitLocker could be compromised in certain circumstances, Microsoft has come to BitLocker's defense , reports I... More >

Microsoft Patches Critical IE Bug

InformationWeek reports that Microsoft addressed 12 vulnerabilities in Windows, Internet Explorer, Windows Server and Microsoft Office in this month's Patch Tuesday.   Among the seven "critic... More >

December 8, 2009

TSA Accidentally Releases Sensitive Info

The Transportation Security Administration is scrambling to figure out how a 2008 copy of its airport screening procedures manual was released in its entirety on the Internet, reports U.S News and... More >

Phishing Attack Goes After Hosting Services

Security firm Trusteer says a new phishing attack is going after webmasters in an effort to gain access to site credentials.   According to V3.co.uk , the attack is targeting cPanel, a popula... More >

MessageLabs Report Finds Malicious Web Sites, Botnets Dominating

According to a MessageLabs report, malicious Web sites and botnet activity dominated the cyber security landscape over the past 12 months, reports V3.co.uk .   The MessageLabs Intelligence 20... More >

New Service Cracks Wi-Fi Passwords

Computerworld reports that for the low price of $34, anyone looking to test the security of WPA networks can try a new cloud-based hacking service that can crack a WPA  network password in just 20... More >

Adobe Illustrator Fix Due by Jan. 8

Computerworld reports that Adobe has confirmed that a flaw in its Illustrator software could give hackers a way to run unauthorized software on a victim's computer. The company says it will issue ... More >

December 7, 2009

Virus Compromises Student Data

A security breach at Eastern Illinois University may have exposed personal information from about 9,000 current and former students and applicants, according to jg-tc Online . The Chicago Tribune ... More >

Novell to Bring Identity Management to the Cloud

Computerworld reports that over the coming year, Novell has plans to release eight new products or upgrades to address what it calls "intelligent workload management."   Among those products ... More >

Apple Issues Pair of Java Updates

Apple has released two Java software updates for Mac OS X .   According to PCWorld.com , the two updates, Java for Mac OS X 10.6 Update 1 and Java for Mac OS X 10.5 Update 6 include a number o... More >

December 4, 2009

Express Scripts Class-Action Suit Dismissed

A consumer class-action lawsuit against pharmacy benefits company Express Scripts over a 2008 data breach has been thrown out by a Missouri federal court.   According to Computerworld , Magis... More >

Report Calls for Change in U.S. Cyber Security

A new study by the Internet Security Alliance warns that the U.S. government and private businesses need to change the way they look at cyber security , suggesting that the government offer business... More >

Two Men Charged with Selling Phony Cisco Gear

Christopher Myers and Timothy Weatherly have been charged with raking in $1 million by buying computer networking gear in China and then claiming the products were from Cisco Systems, reports The Re... More >

Prevx: 'Black Screen of Death' Affecting 50,000 PCs

Prevx says its fix for the so-called "black screen of death" affecting Windows PCs has been downloaded more than 50,000 times in just five days, according to InformationWeek .   Although it h... More >

Six Bulletins in Next Patch Tuesday

TopNews reports that Microsoft will release six security bulletins on its next Patch Tuesday, scheduled for Dec. 8. Three are rated as "critical," while the other three are considered "important."... More >

December 3, 2009

Hacker McKinnon Granted Short Extension to Fight Extradition

British hacker Gary McKinnon has been grant a short extention to challenge an extradition order to face trial in the United States, reports Computerworld . McKinnon's attorneys had requested an ex... More >

Researcher Calls H1N1 Spam Campaign the Biggest E-Mail Threat

A massive H1N1 spam campaign that leads unwary users to a convincing-looking Centers for Disease Control site is "the most predominant virus/phishing campaign right now," says Troy Gill, a security ... More >

PDF Flaw Threatens BlackBerrys

Research In Motion has issued a critical security advisory for a flaw in its BlackBerry Enterprise Server (BES) software that could allow hackers to execute malicious code and hijack infrastructure... More >

December 2, 2009

Koobface Begins New Festive Scam

Hackers behind the Koobface worm are hoping to trick Facebook users with fake messages relating to Christmas, reports SC Magazine .   This latest campaign involves posting messages on Faceboo... More >

McAfee Report Names Riskiest Domains

McAfee's third annual State of the Mal Web report finds that more than 5 percent  of Web sites could cause security risks , reports V3.co.uk .   The report not only looked at 27 million Web si... More >

Security Tips for Retailers During Holiday Season

It's important for retailers that hire temporary workers to keep a watchful eye in order to reduce the risk of data compromises, says Bob Russo, general manager of the PCI Security Standards Council.... More >

Louisiana Restaurants Sue POS Vendors After Hack

Several Louisiana restaurants are suing the makers of their point-of-sale system , claiming that the companies that made and resold the systems should be responsible for fines levied by payment proce... More >

Microsoft Says 'Black Screen of Death' Has Nothing to Do With Patches

Microsoft says the so-called Black Screen of Death condition affecting some Windows users has nothing to do with any bugs in November's Patch Tuesday updates, reports eWEEK .   Earlier this w... More >

December 1, 2009

Black Box Eases Security Complexity

As CTO Edge blogger Mike Vizard points out, the odds of making a mistake when configuring network security appliances goes up with each type of appliance added.   Enter the Veri-NAC from Blac... More >

Northrop Gruman Forms Cyber Security Research Consortium

According to PCWorld.com , government security contractor Northrop Grumman is forming a research consortium with Carnegie Mellon University, Purdue University and the Massachusetts Institute of Tech... More >

Webroot Service Now Protects Outbound Traffic

According to NetworkWorld , Webroot has added to its cloud-based Web security service . Not only will the service monitor inbound Web traffic, but also outbound traffic.   There is no addition... More >

Eight Tips for Staying Safe When Shopping Online

Although online shopping may be a great time saver, a lack of basic online shopping smarts could put you at risk, says Washington Post blogger Brian Krebs. He offers eight online shopping tips to... More >

Bit.ly Partners with Security Firms to Protect Users

The URL-shortening Web site bit.ly is partnering with VeriSign, Sophos and Websense to protect users from spam and malware.   According to SC Magazine , the Sophos agreement will assist bit.l... More >

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.

Business Intelligence

Best-practice tools, strategies and technologies for determining and managing the data you need to make better business decisions.

Applications for Mid-size Businesses

Applications that mid-sized businesses can use to improve operational efficiency, accelerate growth, and maintain profitability.

Decision Management

Applications, management tools and industry advice on how to optimize your data for better business decisions.