Click here

Network Security: Archive: November 2011 

Finding Attack Patterns at the Digital Crime Scene

Using scientific methods, Symantec researchers aim to profile the IT threat landscape.

University of California Hit by Security Breach

Credit card numbers, cardholder names, expiration dates, and encrypted debit card PIN numbers may have been accessed.

FBI Warns of Cyber Attacks on Banks

The attackers are using a modified version of the Zeus Trojan called Gameover.

HP Says Hackers Can't Make Printers Catch Fire

The company says its LaserJet printers have a 'thermal breaker' designed specifically to prevent overheating.

E-mail Security Startup Agari Launches

Early customers include Facebook and YouSendIt.

Sourcefire Immunizes 2 Million PCs with Immunet

Leveraging open source ClamAV and the cloud, Sourcefire layers its antivirus tech on top of other vendors solutions.

UK MoD Acknowledges Security Lapse

The Ministry of Defense says the loss of more than 150 laptops was 'almost inevitable.'

Researchers Warn of HP Printer Security Vulnerability

Salvatore Stolfo and Ang Cui say the vulnerability could be exploited to cause a printer to catch fire.

Apache Server Hit by Reverse Proxy

Dangerous flaw puts internal Web servers at risk, but there is a fix in the works.

Security Breach Affects 250,000 Members of Youth Forum

Names, user names, passwords and location information were accessed.

13 Million Gamers Affected by Nexon Security Breach

Names, user names, encrypted resident registration numbers and passwords of players of the game Maple Story may have been accessed.

WineLibrary.com Acknowledges Security Breach

Customers' credit card information may have been compromised.

FBI, DHS Deny Reports of Cyber Attack on Water Utility

According to an e-mailed statement, 'there was no malicious or unauthorized traffic from Russia or any foreign entities.'

Security Spend Outpacing the Rest of IT

High profile breaches and mobile devices are driving IT security spending.

YMCA Members Affected by Security Breach

Names, addresses, phone numbers, bank accounts and credit card information may have been accessed.

Sutter Health Sued Over Massive Security Breach

The lawsuit contends that the health care system was negligent in its security, and took too long to notify victims of the breach.

Google Enhances Security for Gmail, Other Services

The company is enabling 'forward secrecy' for Gmail, Google Docs, SSL Search and Google +.

Centrify Updates Active Directory Integration Solution

Centrify Express 2012 seeks to ease the pain of IT professionals tasked with integrating Unix, Linux and Mac with Active Directory.

ADP Australia Acknowledges Security Breach

A list of customer e-mail addresses was made available online by mistake.

Review: Sophos Endpoint Security

Focused solely on business customers, Sophos is made for small to midsize organizations.

Data Security Analyst Salaries to Rise in 2012

IT salaries overall are expected to increase by 4.5 percent next year, and data security analysts' salaries will rise by 6 percent.

AT&T Wireless Hit by Cyber Attack

The company has warned targeted subscribers of an 'organized attempt' to access their online accounts.

APEC Host Committee Hit by Possible Cyber Attack

Stolen information may have included Social Security numbers, birth dates and other data.

Public Cloud Keys Too Easy to Find

If you put the keys to your cloud infrastructure in plain sight, don't be surprised if you get hacked.

Norway Hit by Widespread Data Theft

At least 10 different cyber attacks were discovered in the last year.

Nasdaq Hack Attributed to Weak Security

Computers had out of date software, missing security patches and misconfigured firewalls.

Reid Plans Debate on Cyber Security Bill

The Senate Majority Leader plans to bring cyber security legislation to the floor of the Senate for debate early next year.

Google Leads in Reported Vulnerabilities

The company led the quarter with 82 reported flaws, followed by Oracle and Microsoft.

Chrome Gets 2nd Critical Fix in a Week

In a rare move, Google is updating Chrome for a single security fix.

Data on 4.2 Million Patients Stolen from Healthcare Company

A stolen computer contained patient names, addresses, dates of birth, phone numbers and more.

Virginia Commonwealth University Hit by Security Breach

Hackers may have accessed 176,567 current and former students' and employees' Social Security numbers, names,  e-mail addresses and more.

Up in the Cloud: Debating How to Secure iOS 5

iOS device level security really isn't an option but cloud-based network monitoring might be the way to go.

Title Insurance Company Sues Bank Over Security Breach

Global Title Services is suing its bank over more than $200,000 in losses.

RSA DLP Suite Upgrade Secures Smartphones, Tablets

Seeking to help organizations control the lifecycle of their sensitive data, RSA introduces enhancements to DLP Suite 9.0 that helps them address smartphones, tablets and social media.

Review: 3 Free Bootable Rescue Discs

Any one of these discs can get your computer back on track.

The Pros and Cons of Advanced Authentication

Isn't it time to move beyond the infinitely-hackable name and password combo?

How to Prevent Employees from Stealing Your Intellectual Property

It's the employee with the sticky hands that is the easiest and cheapest to thwart.

Former CTO Charged with Hacking into Hoboken Mayor's E-mail

Patrick Ricciardi faces up to 15 years in prison and a $750,000 fine.

Lockheed Martin Plans Australian Cyber Security Center

The NextGen Cyber Innovation and Technology Center is expected to open in March 2012.

Healthcare Organizations Increase Cyber Security Spending

Still, most spend less than 3 percent of their IT budgets on information security.

Security Researchers Warn of Identity Theft Calling Service

The service offers to extract sensitive information for $10 a call.

LANDesk Updates Management, Security Suites

Management Suite 9 and Security Suite 9 are designed to support a broad range of platforms.

Seven Charged with Involvement in $14 Million Fraud Scheme

The group is accused of infecting more than four million machines with malware.

Fake Kaspersky Anti-Virus Used as Phishing Lure

Victims are asked for their credit card info and e-mail address in order to 'receive further instructions.'

Researchers: Hackers Could Enable Mass Jailbreaks

Vulnerabilities in federal prison control systems could allow hackers to open prison doors and crash CCTV or prison intercom systems.

Enterprises Need Better Security Strategies Now

Security threats are too pervasive, persistent and costly to think about IT security after the fact, according to Ernst & Young.

Computershare Acknowledges Massive Security Breach

A lost USB drive could put the 'privacy and financial record of millions of shareholders' at risk, according to the company.

Brazilian ISPs Hit by Massive Cyber Attack

Police have already made at least one arrest in connection with the attack.

Security Breach Hits 16,000 in Finland

Social security numbers, home addresses, phone numbers and e-mail address were published online.

Adidas Hacked

The company says the attack was detected on November 3rd.

Attachmate Beefs Up Security

Attachmate's terminal emulation family, Reflection 2011 R2, gets upgrades to make users' sessions more secure.

Microsoft Partly to Blame for Spread of Duqu

The TrueType font parsing engine is to blame but Microsoft views the risk as low ... for now.

KPN Finds Cyber Attack Tool on Server

The Dutch certificate authority says it's stopped issuing certificates as a precautionary measure.

Massive Security Breach at UK Council

An unencrypted memory stick containing personal information on more than 18,000 people was lost.

EU, US Conduct Cyber Security Exercises

Security experts from the US and 27 European Union member states participated.

Australian Government Suffers Security Lapse

Files belonging to Major-General John Cantwell were likely stolen during transit through Kuwait.

Stanford University Researchers Defeat CAPTCHAs

The researchers found that 13 out of 15 CAPTCHA methods from leading Web sites were vulnerable to automated attacks.

Zeus (Still) Wants Your Wallet

The antivirus community has failed to figure out this able and persistent piece of malware. It's as simple as that. 

Secunia Jumps Into Vulnerability Disclosure Market

Security research firm provides another option for researchers looking to co-ordinate vulnerability disclosure.

UK Government Warns of Surge in Cyber Attacks

GCHQ director Iain Lobban says major IT systems throughout the UK are facing increasing numbers of attacks.

Secunia Offers Non-Financial Rewards for Security Flaws

The Secunia Vulnerability Coordination Reward Program promises merchandise and access to a security conference.

French Nuclear Power Company Hit by Cyber Attack

Local news reports are unclear, but some systems were left out of action for three days.

Cyber Attacks Take Down Phones, Internet in Palestine

Palestinian Communications Minister Mashur Abu Daqqa said the attacks appeared to be state-sponsored.

Phishing E-mails Mimic Apple Notifications

The legitimate-looking e-mails ask victims to provide their ID and password.

Is Your Free AV a System Hog?

Antivirus software is a necessity these days but some solutions are a bigger drain on system resources than others. See how AVG, Microsoft, Avast and Comodo compare.

Canadian Children's Ministry Acknowledges Security Lapse

Documents containing clients' names, addresses, birth dates and health card numbers were recently found in a dumpster.

Major Security Flaw Found in NJStar Translation Software

Dillon Beresford says the vulnerability could be used to take control of systems running the software.

WordPress Security Flaw Hits 1 Million Web Pages

A vulnerability in the TimThumb image resizing utility for WordPress sites has had an enormous impact.

College Student Arrested for Identity Theft

Simon Van Neste used forged ID cards to access secure areas of the Whitman College campus.