Stories by Ellen Messmer

Trend Micro package protects against unpatched exploits

By Ellen Messmer | 06 August, 2012 23:21

Trend Micro today broadened its cloud-based security infrastructure so that its products can receive actionable threat intelligence that lets the security software act like a "virtual shield" against many Web-based threats.

Heated debate over stalled cybersecurity bill pits pro-defense Democrats vs. hands-off Republicans

By Ellen Messmer | 03 August, 2012 01:40

The cybersecurity bill that went down Thursday to legislative defeat shows the deep schism in Congress that had Democrats siding with traditional national-security defense hawks, and Senate Republicans, who toppled the bill, largely siding with businesses that didn't want government foisting new regulations on them.

French T-shirt company relenting in face of Anonymous threats

By Ellen Messmer | 02 August, 2012 14:33

Shadowy hacktivist group Anonymous last night issued a call to its members to attack an online T-shirt company based in France that had registered the Anonymous slogan and logo under French law. That small company, Early Flicker, now seems to be caving to demands from Anonymous.

IBM attempts to redefine the IPS

By Ellen Messmer | 31 July, 2012 17:38

IBM has introduced what it's calling a "next generation" intrusion-prevention system (IPS), an offering that not only is designed to stifle network-based attacks, but adds application-level controls and URL filtering capabilities typically found in separate products such as Web security gateways.

In Pictures: Security soiree. Microsoft's BlueHat Prize contest

By Ellen Messmer | 31 July, 2012 08:31

Microsoft's Trustworthy Computing Group recognizes securityresearchers for work on ROP

In Pictures: Quirkiest moments at 2012 Black Hat security conference

By Ellen Messmer | 31 July, 2012 08:27

From half-naked booth reps to colorful robots, it wasn't all about security on the exhibit floor and around the conference

Possible Anonymous network attack could target Olympics partners BT, GlaxoSmithKline

By Ellen Messmer | 30 July, 2012 21:24

Security firm Radware claims to have spotted evidence online that suggests hactivist group Anonymous is gearing up to target denial-of-service attacks on the websites of British companies BT and GlaxoSmithKline during the Olympics, and maybe do much more.

Global Payments: data breach cost a whopping $84.4 million

By Ellen Messmer | 27 July, 2012 03:43

Global Payments, which back in the spring reported a data breach in which information associated with an estimated 1.4 million payment cards was stolen, has revealed that expenses associated with investigations, fines and remediation has hit $84.4 million.

Black Hat: Shark-bitten security researcher takes another chomp out of Oracle database

By Ellen Messmer | 27 July, 2012 02:31

A researcher scored again against Oracle’s database by demonstrating at the Black Hat security conference Thursday an exploit that would allow him to take control as an administrator.

Apple security guru lays out iPad, iPhone crypto architecture at Black Hat

By Ellen Messmer | 26 July, 2012 22:34

A top Apple security guru Thursday presented an in-depth view into the security architecture for iOS, the basis of iPhones and iPad tablets, underscoring the complex certificate-based encryption framework Apple has adopted.

Researcher wows Black Hat with NFC-based smartphone hacking demo

By Ellen Messmer | 26 July, 2012 02:21

At the Black Hat Conference in Las Vegas Wednesday, Accuvant Labs researcher Charlie Miller showed how he figured out a way to break into both the Google/Samsung Nexus S and Nokia N9 by means of the Near Field Communication (NFC) capability in the smartphones.

Black Hat panel: Which do you trust less with your data, the U.S. government or Google?

By Ellen Messmer | 26 July, 2012 02:21

To celebrate the 15th anniversary of the Black Hat Conference here, a panel of experts got together to expound on what they see as the privacy and security mess of our times, and they had plenty to say about the U.S. government, cyberwar and Google.

Black Hat: Cyber-espionage operations vast yet highly focused, researcher claims

By Ellen Messmer | 25 July, 2012 21:27

Cyber-espionage operations across the Internet are extensive yet highly targeted, says a malware researcher speaking this week at the Black Hat Conference in Las Vegas. And it's not just governments targeting other governments or trying to steal corporate secrets -- private security companies also are involved in these break-ins even while claiming to offer "ethical hacking services."

P2P 'Gameover ZeuS' seen as largest bank-theft botnet

By Ellen Messmer | 25 July, 2012 21:26

It's the largest bank-theft botnet out there, and its peer-to-peer (P2P) design, credited to cybercrime gangs in Eastern Europe, is going to make it hugely difficult to take down, according to research put forward at the Black Hat Conference.

Black Hat: RSA service to zap apps pretending to be from your company

By Ellen Messmer | 25 July, 2012 13:43

RSA Wednesday introduced a service at the Black Hat Conference to monitor far and wide for signs of phony corporate mobile apps, and to work with Google Play, Apple iTunes and other major app stores to remove them quickly.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

AVG Internet Security 2011 Business Edition

Ultimate protection for your small or medium-sized business

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.