Click here

Network Security: Archive: January 2012 

Fifteen Companies Announce E-mail Security Standard

The DMARC framework is intended to protect e-mail at the domain level.

Scottish Council Faces Record Fine for Security Breaches

The Midlothian Council has been fined £140,000 for five separate data breaches.

Cisco Warns of Vulnerability in Security Appliances

Users are advised to deactivate telnet services in order to mitigate the vulnerability.

MetaFlows Intros SaaS Security System

The solution combines local software with a cloud-based service.

Cyber Security Market to Exceed $61 Billion in 2012

Visiongain anticipates an increase in public-private partnerships across several cyber security sectors.

Alleged Kelihos Botnet Creator Proclaims Innocence

Andrey Sabelnikov has posted a statement online saying he has no connection to Kelihos or spam.

University of Hawaii Settles Security Breach Lawsuit

As part of the agreement, the university will provide victims with two years of credit and fraud protection services.

Google Updates Privacy Policy

Users will not be able to opt out of the new policy.

Security Flaws Found in WordPress Setup

Because the flaws are in an installation script, WordPress claims there's very little risk of their being exploited.

New European Privacy Rules Introduced

Under the new rules, fines can be as much as two percent of a company's global annual turnover.

O2 Acknowledges Security Lapse

For the past two weeks, the carrier provided its users' phone numbers to every Web site they visited.

Zappos Sued Over Security Breach

Texas resident Theresa Stevens has filed a class action lawsuit claiming the company failed to protect customers' personal information.

NY Public Service Commission Acknowledges Security Breach

Almost two million customers' personal information was exposed.

Sourcefire Intros FireAMP Anti-Malware Solution

The technology behind FireAMP came from Sourcefire's acquisition of Immunet in January of 2011.

Microsoft IDs Alleged Kelihos Botnet Creator

The company says Andrey Sabelnikov was running the botnet.

Twitter Buys Anti-Malware Company Dasient

The acquisition follows Twitter's purchase of Whisper Systems in November of last year.

Researchers Demo SCADA Security Flaws

The flaws range from privilege escalation bugs to denial of service vulnerabilities.

DreamHost Hacked

The Web host says customers' billing and personal information were not exposed.

Researchers Hack Into Corporate Conference Rooms

The researchers were able to listen in on meetings and control a camera remotely to read information on documents.

SafeNet Intros eToken 3500 for Online Banking Security

The device uses an optical sensor to read transaction details from the user's screen, then generate an electronic signature.

Phishing Campaign Targets Seattle Government Employees

Hundreds of people with seattle.gov e-mail addresses recently received phishing e-mails.

AnchorFree Adds Malware Protection to HotSpot Shield

A recent update to the VPN client added a malware site guard.

Security Expert Warns of Online Banking Vulnerability

Yash K.S. has published a video demonstrating a man-in-the-browser attack capable of manipulating HSBC Bank transactions in real time.

U.S. DOJ: The Cloud Provides No Legal Cover for Criminals

Crooks and their data cannot hide from the long arm of the law, even in the cloud.

UAE Central Bank Site Hacked

The bank's Web site was taken down by a group calling itself 'IDF Team.'

Symantec: Cyber Attacks May Be Costing Your Business $470,000 Annually

As the average cost of recovering from cyber attacks approaches half a million dollars per year, Symantec says it's time to beef up your defenses.

Secunia Shortens Deadline for Vulnerability Disclosures

The research firm has reduced its deadline from one year to six months.

Information Security Masters Program Launched

The new program at City University London is intended to help security professionals bridge the gap between security and business.

RSA Chief: Conventional Security Defenses Are Inadequate

Speaking from recent experience, RSA's Art Coviello says the question now is not whether your defenses will be breached -- it's whether you are equipped to respond when it happens.

Symantec Admits Its Own Network Was Hacked

The company had initially blamed a third party for the security breach.

Security Flaw Found in McAfee SaaS Endpoint Protection

The problem was reported by McAfee customers, who found that their IP addresses were being blacklisted for sending spam.

CoveritLive Hacked

The company says no financial information was compromised.

Fortinet Announces New Security Appliances

The company has also introduced several enhancements to the FortiWeb 4.0 MR3 operating system.

Zappos Security Breach Affects 24 Million

Names, e-mail addresses, phone numbers and password hashes were exposed.

WEF: Cyber Attacks Lead Global Risks

The World Economic Forum says cyber attacks are among the most likely global risks to occur over the next decade.

Kaspersky Warns of New Facebook Chat Phishing Attack

The messages contain a link to an external phishing page that asks for the victim's name, e-mail, password and more.

Netherlands Announces National Cyber Security Center

The center, based in The Hague, is intended to coordinate information and expertise between government agencies.

FTC, Upromise Settle Over Security Concerns

Customer data was transmitted unencrypted.

Vermont Department of Taxes Acknowledges Security Lapse

Social security numbers and federal ID numbers were posted online.

STRATFOR Admits Credit Card Data Wasn't Encrypted

Company CEO George Friedman attributed the oversight to the company's rapid growth.

NYU, Banks to Establish Cyber Security Center

The plan is for banks to share information with the center, which will then analyze the data to look for suspicious activity.

Department of Energy to Examine Power Grid Cyber Security

The DOE recently unveiled the Electric Sector Cybersecurity Risk Management Maturity project.

Restaurant Sues Bank, Processor Over Fines from Alleged Breach

Cisero's was forced to pay fines for a possible security breach that was never actually confirmed.

U.S. Expels Venezuelan Diplomat for Planning Cyber Attacks

Livia Antonieta Acosta Noguera was given 72 hours to leave the country.

ICS-CERT Warns of Security Flaws in Siemens FactoryLink

The company has released a security update to patch the vulnerabilities.

Israel Says Cyber Attacks Are Terrorism

The country's deputy foreign minister said cyber attacks are 'a breach of sovereignty comparable to a terrorist operation.'

Protecting Against SQL Injection Attacks with Oracle Database Firewall

New release gains support for MySQL, helps shield enterprise databases from attack.

Researchers Warn of Smart Meter Security Flaws

Dario Carluccio and Stephan Brinkhaus were able to change a meter's consumption information to -106610 kWh.

Pastebin Hit by Second Cyber Attack

The site had already been taken down by another DDoS attack earlier this week.

Singapore University Acknowledges Security Breach

Members of the hacker group Team Intra accessed staff user names, domain information, and hashed passwords.

IBM Warns of Security Flaws in Rational Rhapsody

The company says 'multiple high risk security vulnerabilities' could allow an attacker to execute arbitrary code.

Lilupophilupop Attack Infects Over a Million URLs

The SQL injection attack was first identified and disclosed in early December.

EFF Warns of New AIM Privacy Issues

The latest version of the chat client logs all user conversations by default.

California Hospital Acknowledges Security Breach

More than a thousand patients' private medical records were accessed.

Pastebin Taken Down by Cyber Attack

The denial of service attack was confirmed via Pastebin's official Twitter account.

Kaspersky: India Leads in Spam

Almost 15 percent of all spam in the third quarter of 2011 was sent from India.

Paladion Networks Plans Cybercrime Center in Oman

The center will focus on monitoring and responding to cybercrime in the country.

Telstra Suffers New Privacy Breach

Customer data, including contact information and dates of birth, was posted to Editgrid.com.

Care2 Acknowledges Security Breach

The site's approximately 18 million users were recently notified that their passwords were being reset.