Click here

Security News: Archive: June 2011 

Joomla Gets Security Update

Version 1.6.4 of the open source CMS patches four vulnerabilities.

WordPress Updates for Security

Critical security update issued for open source WordPress blog as next generation release nears completion.

Fijian Activists Seek Help from Hackers

A group of pro-democracy activists is asking hackers worldwide to help them expose government corruption.

Gannett Government Media Hacked

The compromised data includes names, user IDs, passwords, e-mail addresses, and more.

Kaspersky Warns of 'Indestructible' Botnet

TDL-4, the researchers say, is a vast improvement over previous versions.

Anonymous Hackers Target Orlando

The attacks are in response to the arrests of members of a charity that feeds homeless people.

FBI Raids Suspected LulzSec Hacker's Home

No arrests were made, according to local media reports.

Smartphone Security: Android vs. iOS

A Symantec report entitled 'A Window Into Mobile Device Security' looks at the security approaches of both operating systems.

Anonymous Hackers Target Zimbabwe

The hackers uploaded a file called Zimbabwe .gov SQL Dump to Megaupload.com.

Dropbox Sued Over Security Flaw

The lawsuit accuses Dropbox of violating the California Unfair Competition Law, as well as invasion of privacy and negligence.

Phishing Attacks Target Tumblr Users

According to GFI Software, the attacks were first launched on June 23.

Accused Hacker Ryan Cleary Freed on Bail

The teenager was diagnosed with Asperger's syndrome while in custody.

Hackers Publish PayPal, MySpace Credentials

D3V29 stole user names, passwords and account balances via open wireless networks.

Pidgin IM Client Gets Security Update

Version 2.9.0 addresses a vulnerability caused by corrupt buddy icons.

Groupon India Acknowledges Security Lapse

A database of 300,000 usernames and passwords was accidentally published online.

Simon Pegg Hacked

Hackers posted a link to a banking Trojan on the actor's Twitter account.

Facebook Hires Hacker Geohot

George Hotz apparently began working at the company on May 17.

MasterCard.com Hit by Cyber Attack

Twitter user @ibomhacktivist has claimed responsibility.

Los Angeles Man Gets 13 Years for Phishing Attacks

Kenneth Joseph Lucas II was one of 100 people arrested as part of Operation Phish Phry in 2009.

Data Breaches Running Rampant

And these are just the ones we hear about.

Dropbox Security Flaw Was Actively Exploited

Approximately 100 users' accounts were accessed.

LulzSec Hackers Say Goodbye

After 50 days of high-profile hacking, the group is calling it quits.

Hackers Publish Tony Blair's Address Book

TeaMp0isoN released the information in response to Blair's support for the war in Iraq.

PBS Hacked Again

Hacker Warv0x says he exploited an SQL injection vulnerability.

John The Ripper Expedites Password Auditing

Password cracking tool gets a big boost from a pair of security industry vendors.

EA Confirms Security Breach

The company has updated a Q&A to confirm the attack.

Citigroup Hackers Stole Approximately $2.7 Million

The bank says its customers will not be liable for the losses.

ChronoPay's Vrublevsky Arrested for Cyber Attack

The company's co-founder is accused of hiring a hacker to attack rival payment processing firms.

NATO Web Site Hacked

The customer database for the E-Bookshop service may have been stolen.

Romanian Police Arrest Phishing Gang

Authorities say the ring was being run by three men in the city of Braila.

Apple Releases Massive OS X Security Update

The update patches 39 vulnerabilities, including five in QuickTime.

Sony Sued Over PSN Security Breach

The lawsuit alleges that Sony knew its security was inadequate prior to the attack.

LulzSec Hackers Publish Arizona Police Data

The Arizona Department of Public Safety has acknowledged that its computer systems were compromised.

UCM Hacker Admits Data Theft

Daniel J. Fowler faces up to 15 years in federal prison and a fine of up to $500,000.

iPad Hacker Pleads Guilty

Daniel Spitler faces up to five years in prison and a $250,000 fine.

DARPA Plans Virtual Internet as Security Testbed

The National Cyber Range will enable testing of possible cyber attack situations that could happen on the real Internet.

WhiteHat Buys Infrared Security

The acquisition will add static code analysis technology to WhiteHat's offering.

Australia Intros New Cybercrime Laws

The Cybercrime Legislation Amendment Bill 2011 brings the country in line with the Council of Europe Convention on Cybercrime.

Travelodge UK Hacked

Several customers have been spammed after e-mail addresses were stolen from the hotel chain.

90 Percent of Companies Were Hacked in Past Year

A Ponemon Research survey found that 60 percent reported two or more breaches in the last 12 months.

Hackers Put Backdoors in WordPress Plug-ins

Backdoors were found in AddThis, WPtouch and 3 Total Cache.

AdaptiveMobile Buys Sentry Wireless for Mobile Security

Sentry's tech will be integrated into AdaptiveMobile's Network Protection Platform.

Researcher Finds Android NFC Security Flaw

The vulnerability could allow a malicious NFC tag to send incorrect information to a Nexus S device.

Bromium Targets Cloud Security

The startup's tech is designed to secure application clouds and virtual desktops as well as rich client devices.

NetSol Back Online After Cyber Attacks

The Web host and registrar was hit by two denial of service attacks earlier this week.

Panda Security Updates Cloud Anti-Virus

Many of the enhancements in the new release were suggested by users.

Lookout Warns of New Android Trojan

GGTracker signs victims up to premium SMS subscription services without their consent.

U.K. Police Arrest Suspected LulzSec Hacker

The unnamed 19-year-old was arrested following an investigation by several intelligence agencies, including the FBI.

New Facebook App Protects Users from Spam and Malware

MyPageKeeper was designed by students at the University of California at Riverside.

Israeli Certificate Authority Hit by Cyber Attack

In response, StartSSL has temporarily suspended all certification services.

Firefox, Thunderbird Get Security Updates

The updates patch several bugs in the open source browser and e-mail client.

LulzSec, Anonymous Hackers Unite

The groups are working together to target banks, government agencies and other high-profile organizations.

ADP Investigates Workscape Security Breach

The company says the breach did not involve payroll data and only affected a single client.

Malware Targets Android Devices with Custom ROMs

The malware, jSMSHider, targets a vulnerability that was closed in version 7.0.3 of CyanogenMod.

Sony Pictures France Hacked

Hackers Idahc and Auth3ntiq claim to have accessed 177,172 e-mails.

Indian Hacker Charged with Extortion

Chetan S. Bendale is accused of taking over oDesk's domain name registration account, then demanding $1 million from the company.

Dropbox Acknowledges Major Security Flaw

For almost four hours yesterday, users were able to log into any account without a password.

Lulzsec Hackers Take Down Australian Web Host

Thousands of e-mail addresses and passwords for Distribute.IT were published online.

Virgin Media Warns of Malware Infections

The company has warned approximately 1,500 customers that their computers are infected with the SpyEye Trojan.

Hackers Sentenced for Attacks on Lady Gaga, Others

Both men were convicted of copyright theft and computer intrusion, and one was also convicted of extortion.

Support.com Buys Anti-Spyware Solution for $8.5 Million

SUPERAntiSpyware's 10 employees will join Support.com full-time.

U.S. Warns of Security Flaws in Chinese SCADA Software

The vulnerabilities were found in two products from Beijing-based Sunway ForceControl Technology.

SEGA Hacked

E-mail addresses, dates of birth and encrypted passwords were stolen from the SEGA Pass user database.

LulzSec Hackers Take Down CIA.gov

The Web site was taken down for several hours on Wednesday evening.

SpyEye Trojan Targets European Airline Sites

A new variant specifically targets Air Berlin and AirPlus customers.

New Trojan Steals Bitcoin Virtual Currency

The malware, Infostealer.Coinbit, specifically targets Bitcoin wallets.

BioWare Hacked

At least 18,000 user account credentials were stolen.

WordPress Security Scanner Launched

WPScan is designed to help admins assess the security of their WordPress installations.

Germany Launches Cyber Security Center

The Cyber-Abwehrzentrum in Bonn is intended to help defend the country's critical infrastructure.

Lookout Mobile Security Adds Safe Browsing

The premium version of the Android app will check links for phishing scams or malware.

Man Convicted for World Cup Cyber Attack Threats

The man threatened online betting sites with DDoS attacks during the World Cup.

Creditsafe Hacked

Malicious code was planted on the company's Web site.

Massive Security Breach at NHS

A laptop containing 8.63 million people's unencrypted medical records has gone missing.

Microsoft Office for Mac Gets Security Updates

The updates patch a flaw in Microsoft Excel that could enable remote code execution.

New Zealand Labour Party Hacked

Blogger Cameron Slater has refused to destroy the data he accessed.

Hundreds Arrested in Asian Cybercrime Crackdown

Online fraudsters were detained in China, Taiwan, Cambodia, Indonesia, Malaysia and Thailand.

Anonymous Hackers Hit Spanish Police Web Site

The denial of service attack was launched in response to the recent arrest of three hackers linked to the group.

NATO Plans Cyber Security Task Force

The Cyber Red Team will be focused on helping to detect and respond to cyber attacks.

Epic Games Hacked

E-mail addresses and encrypted passwords were stolen.

U.S. Senate Hacked

An analysis of the posted data suggests that no sensitive information was compromised.

Microsoft Patches 34 Security Flaws

Fifteen of the vulnerabilities are rated critical.

Microsoft Puts Out 16 Patches, 9 Critical, for June

Security pros have plenty of demands on their time when it comes to installing June's Patch Tuesday patches.

Application Security Enhances DbProtect Platform

Version 6.3 of the database security, risk and compliance platform will incorporate new blocking functionality.

Siemens Patches SCADA Security Flaw

The company says the vulnerability could have allowed attackers to capture and replay management commands.

LulzSec Hackers Hit Pron.com

The group released 26,000 e-mail addresses and passwords from members of the porn site, including .gov and .mil users.

RSS Security Issue Found in Nissan LEAF

The GET request for an RSS feed includes the driver's latitude, longitude, speed, direction and destination.

IMF Hit by Sophisticated Cyber Attack

A significant amount of data was stolen, including documents and e-mails.

Anonymous Hackers Arrested in Turkey

Eight of the 32 people detained were under 18 years old.

Rogue Anti-Virus Mimics Microsoft Update

The scam uses a copy of the Microsoft Update site -- but only works on Firefox.

ViaForensics Warns of Widespread App Security Flaws

According to the security firm, several popular iPhone and Android apps have significant security issues.

Cyber Attack Steals $139,000 from Pittsford, N.Y.

The money was stolen from the Town of Pittsford's online commercial banking account.

Security Vendor Zeus Buys Art of Defence

Zeus said it made the acquisition in response to increased demand for Web application security.

PC Technician Arrested for Installing Spyware

Trevor Harwell surreptitiously captured hundreds of webcam images of Mac repair customers.

Three Anonymous Hackers Arrested in Spain

The suspects were arrested in Barcelona, Almeria and Valencia.

Bank Not at Fault for Massive Security Breach

Judge John Rich ruled that Ocean Bank is not responsible for covering the theft of almost $300,000 from a customer's account.

New School Webcam Privacy Lawsuit Filed

According to the lawsuit, the student's parents were shown 4,404 webcam photos and 3,978 screenshots taken via his MacBook.

Teen Interpol Hacker Arrested in Greece

The 18-year-old, known online as 'nsplitter,' is accused of hacking into Interpol, the Pentagon, the FBI and the NSA.

ePlus Buys Security VAR NCC Networks

NCC's Chicago office will become a new regional office for ePlus.

RSA Hires Chief Security Officer

Eddie Schwartz was formerly the CSO of NetWitness.

Citigroup Hacked

The company says hundreds of thousands of customers' personal data may have been accessed.

VMware Releases Security Updates

Some of the vulnerabilities patched could lead to arbitrary code execution.

Apple's iOS 5 Hacked

Members of the iPhone Dev Team claim to have jailbroken the OS using limera1n.

Cigital Buys Security Consultancy Consciere

Cigital says the acquisition will help it expand its scope in the hospitality and retail industries.

ISF Warns of Security Threat from Mobile Apps

The Information Security Forum recommends that enterprises implement a strong acceptable use policy for personal devices in the workplace.

Canada's Conservative Party Hacked

The hackers planted a press release saying Stephen Harper had been flown to a hospital after choking on breakfast.

Google Debuts Chrome 12, Advances Security

Chrome 12 debuts as Google ups the ante in the battle against malware.

Comcast Expands Home Security Service

The Xfinity Home Security service will be made available in six new cities across the U.S.

RSA to Replace Security Tokens

The move was announced in a letter to customers on Monday.

Kaspersky Warns of Malware Hosted on AWS

The malware attempts to disable anti-virus programs and steal financial information.

Symantec Warns of New Android Malware

According to researcher Irfan Asrar, Android.Lightdd doesn't require any complex steps to restore a device back to its pre-infection state.

1 in 4 U.S. Hackers Is an FBI Informant

According to an article in The Guardian, hackers are easy to break when faced with threats of long prison sentences.

VLC Media Player Gets Security Update

Version 1.1.10 addresses several issues found in the previous update from two months ago.

Chrome Update Patches 15 Security Flaws

Version 12.0.742.91 also gives users the ability to delete Flash cookies.

Pharma Spammers Leverage Fake YouTube E-mails

E-mails claiming to come from YouTube link instead to a Web site selling Viagra, Cialis, Levitra and other drugs.

Android App Simplifies Data Theft

FaceNiff can be used to steal unencrypted cookies over Wi-Fi networks.

Oracle Plans Java SE Security Update

On Tuesday, the company will release an update to patch 17 vulnerabilities.

U.K. Facebook Hacker Arrested

Although no user data was compromised, Facebook is working with Scotland Yard and the FBI to investigate the attack.

InfraGard Hacked

The LulzSec hacker group recently defaced the infragardatlanta.org Web site.

Hacker Arrested for Stealing Nude Photos

Joseph B. Campbell hacked into between 350 and 500 webmail accounts.

MI6 Hackers Replaced Bombs with Cakes

The hackers inserted a cake recipe to replace bomb-making instructions in an Al Qaida magazine.

G Data Launches Android Security App

MobileSecurity is designed to protect Android devices from viruses, malware and spyware.

Apple Continues to Battle New Mac Malware

The company recently released its third security update in as many days.

Microsoft Enhances Wireless Keyboard Security

The new Wireless Desktop 2000 incorporates 128-bit AES encryption.

Acer Hacked

The Pakistan Cyber Army says it stole personal data on 40,000 customers, along with several pieces of source code.

Zeus Malware Targets LinkedIn Users

A new campaign targets users of the social network with fake invitations to connect to other members.

Microsoft Releases Free Anti-Virus Solution

Standalone System Sweeper Beta is designed for use when a PC can't be started due to a malware infection.

Security Flaws Found in Cisco AnyConnect VPN Client

Both vulnerabilities can be leveraged to compromise a user's system.

SF Utilities Commission Warns of Possible Security Breach

An unsecured server contained a file with customer names, account numbers, address, phone numbers and some e-mail addresses.

Second Cyber Security Challenge Launched

The biggest difference between this challenge and last year's is the increased frequency of competitions.

Comcast Intros Identity Theft Protection

The service is free with an Xfinity Internet service subscription.

Panda Security Launches 2012 Anti Virus Solutions

Panda's new anti virus product line provides enhanced protection for social media as well as encryption and shredding for more complete protection.

Is China Hacking Gmail?

Google points the finger at China for email hack.

Sony Pictures Hacked

The hackers claim to have accessed unencrypted personal data on over 1 million people, along with admin details, music codes, and music coupons.

Security Updates Released for Wireshark

Versions 1.2.17 and 1.4.7 address multiple vulnerabilities.

L-3 Hit by Cyber Attacks

The attacks leverage information gained from a breach at RSA.

Hackers Continue Attacks on Sony

LulzSec says its attacks are the "beginning of the end" for the company.

New Malware Sidesteps Mac Security Update

A new variant of MacDefender avoids detection by Apple's new security protections.

Pentagon Says Cyber Attacks Are an Act of War

The Defense Department report is its first official document on cyber strategy.

Eucalyptus Security Flaw Found

The critical vulnerability was discovered by researchers at Ruhr-University Bochum.