Stories by Grant Gross

FTC reaches privacy settlement with Path app

By Grant Gross | 01 February, 2013 17:16

The maker of the Path social networking app will pay a US$800,000 civil penalty to settle U.S. Federal Trade Commission charges that it illegally collected personal information from children without parental consent, the agency said Friday.

FTC: App developers, stores should take new privacy steps

By Grant Gross | 01 February, 2013 16:50

Mobile app developers should provide real-time disclosures to users on the personal information they collect and get permission to collect sensitive information, the U.S. Federal Trade Commission has recommended.

Groups raise questions about privacy on Skype

By Grant Gross | 24 January, 2013 16:50

Skype owner Microsoft should release information about how much user data it gives to third parties, including government agencies, several organisations and individuals said in a letter to company officials.

Three charged with distributing Gozi virus

By Grant Gross | 23 January, 2013 16:19

Three people allegedly involved for years in cybercriminal activities in Eastern Europe have been charged in a U.S. court for creating and distributing the Gozi virus that infected more than 1 million computers and allowed cybercriminals to steal millions of dollars over a five-year period.

US lawmaker: Mobile users should be able to delete data

By Grant Gross | 17 January, 2013 21:51

A U.S. lawmaker has proposed legislation that would allow mobile phone users to ask apps to stop collecting their personal data and to delete information collected in the past.

Malware infects US power facilities through USB drives

By Grant Gross | 15 January, 2013 21:38

Two U.S. power companies reported infections of malware during the past three months, with the bad software apparently brought in through tainted USB drives, according to the U.S. Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).

US-CERT: Disable Java in browsers because of exploit

By Grant Gross | 11 January, 2013 18:13

Internet users should consider disabling Java in their browsers because of an exploit that can allow remote attackers to execute code on a vulnerable system, the U.S. Computer Emergency Readiness Team (US-CERT) recommended late Thursday.

California AG: Mobile apps should limit data collection

By Grant Gross | 10 January, 2013 20:56

Mobile application developers should minimize privacy surprises for their customers by limiting their data collection and retention and giving users access to the data collected, California Attorney General Kamala Harris has recommended.

Banks crack down on cyber-based account takeovers

By Grant Gross | 09 January, 2013 21:51

U.S. banks and their customers are doing a better job of protecting themselves against cyberattacks that result in thieves taking over commercial accounts, according to a survey released by the Financial Services-Information Sharing and Analysis Center.

EU organized crime makes €1.5 billion a year on credit card fraud

By Grant Gross | 07 January, 2013 17:17

Organized crime groups in Europe make about €1.5 billion (US$2 billion) a year from payment card fraud, according to a new report from the European Police Office (Europol).

Imation buys solid-state storage vendor Nexsan

By Grant Gross | 02 January, 2013 15:36

Imation, a storage and data security company, has acquired Nexsan, a vendor of disk-based storage systems, in a deal worth about US$120 million, the company announced.

Digital Citizens group focuses on Internet safety

By Grant Gross | 20 December, 2012 21:56

An Internet safety education campaign will point out scams and other online dangers with an initial target audience of children and seniors.

US FTC strengthens online children's privacy rules

By Grant Gross | 19 December, 2012 19:43

Websites, mobile apps and online advertising networks targeting children will be required to follow new privacy regulations, including getting a parent's permission before collecting geolocation information and photographs from kids, under new rules announced Wednesday by the U.S. Federal Trade Commission.

SANS NetWars tests cybersecurity pros against peers

By Grant Gross | 18 December, 2012 20:10

Organizers played "Eye of the Tiger" and "We are the Champions" over the loudspeakers as participants in the SANS Institute's NetWars Tournament of Champions sat down at their laptops and prepared for action.

Group says Nickelodeon app violates kids' privacy

By Grant Gross | 17 December, 2012 15:58

Smartphone app SpongeBob Diner Dash violates U.S. law by collecting a "wide range" of personal information from children, including full names and email addresses, according to a complaint filed by the Center for Digital Democracy, an advocacy group.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Web Malware Protection System (MPS)

Web Malware Protection System (MPS) stops Web-based attacks that traditional and next-generation firewalls, IPS, AV, and Web gateways miss.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.