Click here

Network Security: Archive: June 2012 

Stratfor Settles Lawsuit over Security Breach

Long-suffering customers will be rewarded with a free month of a service  and a free e-book.

Bank Agrees to Pay Cybercrime Victim $600,000

Professional Business Bank has settled a lawsuit alleging that it failed to maintain  a reasonable level of security.

KeePass Security Flaw Found

The vulnerability could potentially enable attackers to steal password lists.

Top 20 Android Security Apps

Protect your Android device against malicious apps, mobile malware, and theft with these essential security solutions.

Cunard Cruise Line Suffers Security Breach

Customer names, e-mail addresses and booking reference numbers were exposed.

State of Alaska Fined $1.7 Million for Security Breach

In addition to paying the fine, the state's Department of Health and Social Services has agreed to improve its security practices.

NICT Intros Daedalus Network Monitoring System

The new system visualizes a network and any cyber attacks in 3D.

McAfee: New Attacks Automate Online Banking Fraud

The security firm says the attacks have attempted to steal a total of $2.5 billion.

Commodity Futures Trading Commission Suffers Security Breach

Employee names and Social Security numbers were accessed.

MI5 Warns of 'Astonishing' Cyber Attacks

In a recent speech, Jonathan Evans described 'industrial-scale processes' backing both cyber espionage and cyber crime.

FTC Sues Wyndham Hotels Over Data Breaches

The lawsuit claims that data security failures on Wyndham's part led to three breaches in less than two years.

Several Security Flaws Found in Menshn Social Network

Hackers easily hijacked user accounts and promoted posts to the front page of the site.

Top 3 Insecure Password Management Practices

Even good admins sometimes do bad things with passwords. Spotting these risky IT practices in your organization is a first step to a more secure password management strategy.

New Mexico's PERA Suffers Security Breach

Names, addresses, bank routing numbers, account types, account numbers and more may have been exposed.

PayPal Intros Bug Bounty Program

There's no stated limit to the amount the company will pay researchers for reporting vulnerabilities.

Memorial Sloan-Kettering Cancer Center Suffers Security Breach

Patient names, birthdates, medical record numbers, dates of treatment and some Social Security numbers were exposed.

Belfast Health Trust Fined £225,000 for Security Breach

Thousands of documents, including medical records, x-rays and lab results, were found in a disused hospital.

Google Finds 9,500 Malicious Web Sites Every Day

In response, the  company recommends that Web site owners register their sites with Google Webmaster Tools.

Imperva Warns of Flaws in CAPTCHA Security

The company says new methods need to be explored to better balance complexity with user-friendliness.

LinkedIn Sued Over Security Breach

The lawsuit contends that LinkedIn's security measures were outdated and insufficient.

US-CERT Warns of Software Security Flaw Affecting Intel Chips

An attacker would need valid login credentials and local system access to exploit the vulnerability.

Kayak.com Investigates Security Breach

Customers' home addresses, phone numbers, e-mail addresses and credit card expiration dates were exposed.

Report: Government Should Spend More on Fighting Cybercrime

The researchers suggest that too much is being spent on anti-virus solutions and not enough on policing.

RailCorp Stops Selling Used USB Drives Due to Privacy Concerns

A 2011 Sophos study found user data and malware infections on the used drives.

Former ZDI Execs Launch New Vulnerability Intelligence Firm

Exodus Intelligence is led by former Zero Day Initiative researchers Aaron Portnoy and Brandon Edwards.

Hacked Companies Start Fighting Back

The countermeasures range from retaliatory cyber attacks on hackers to simply placing fake data on servers.

Qualys Brings Security, Compliance Platform to Private Clouds

The QualysGuard Private Cloud Platform is sold on an annual subscription basis.

City of Glasgow Suffers Security Breach

An unencrypted laptop was stolen that contained the bank account details of 6,069 people and 10,382 companies.

Medical Device Software Update Site Infected with Malware

The Department of Homeland Security is now investigating.

New Cyber Security Research Center Opens in California

Sandia National Laboratories' Cybersecurity Technologies Research Laboratory is located on the grounds of the Livermore Valley Open Campus.

Critical Security Flaw Found in Tumblr

Researchers Aditya Gupta and Subho Halder say Tumblr has ignored their findings.

Users Block LinkedIn E-mail Alerts as Spam

According to Cloudmark, more than 4 percent of people who received official e-mails from LinkedIn alerting them to the site's recent breach marked those e-mails as spam.

How to Run Your Own Certificate Authority

Your business can save money by issuing its own digital certificates for internal corporate resources such as intranets and VPNs.

MySQL, MariaDB Security Flaw Found

According to Sergei Golubchik, the flaw makes password protection 'as good as nonexistent.'

Survey Finds CEOs, CISOs Aren't Communicating on Security

Thirty-six percent of CEOs say the CISO never reports to them on the state of IT infrastructure security.

EU Watchdog Warns of Smart Meter Privacy Risks

Giovanni Buttarelli says legislation is needed at the European level to ensure the protection of personal data.

Spokeo Fined $800,000 for Privacy Violations

The FTC says Spokeo operated as a consumer reporting agency in violation of the Fair Credit Reporting Act.

Survey: Small Businesses Don't Fear Data Breaches

A recent survey found that 85 percent of small business owners think a data breach is 'unlikely.'

German Defense Ministry Announces Cyber Warfare Unit

The unit has apparently been in existence since 2006.

VUPEN Security Denies Breach Allegations

Company CEO Chaouki Bekrar says the story is 'just bullsh*t.'

Sandia Labs Scientist Charged with Data Theft

Jianyu Huang is accused of sharing lab research with Chinese universities.

LinkedIn Confirms Security Breach

The company says users whose accounts were compromised will find that their passwords are no longer valid.

Google Launches Alerts on State-Sponsored Attacks

Users will receive a warning if Google believes a state-sponsored attacker is trying to compromise their computer or account.

World IPv6 Launch Day: A Security Risk?

Make sure your network has visibility and controls for IPv6 in place before enabling the protocol by default, experts say.

Fake Facebook Privacy Notice Going Viral

Simply posting a disclaimer on your Facebook page won't alter your acceptance of the site's terms of service.

Microsoft Touts Cloud Security in Office 365 for Government Launch

Betting on security and privacy, Microsoft hopes to avoid the issues that tripped up Google's cloud deal for Los Angeles.

South Korean Man Arrested Over Airport Cyber Attacks

The man allegedly bought and distributed malware-infected gaming software from North Korean agents.

Microsemi Denies Claims of Backdoors in Chips

The company says there's no 'designed feature' in the chips that would enable circumvention of security.

Study Finds Older Users Pick Better Passwords

German speakers over the age of 55 use the strongest passwords, according to a Cambridge University study.

Intrusion Deception: The 'Tar Trap' Approach to Web Application Security

Juniper's Mykonos Software goes on the offense with a novel approach against brute force authentication and directory traversal attacks.