Stories by Jon Brodkin

Hackers could reverse-engineer Microsoft patches to create DoS attacks

By Jon Brodkin | 25 August, 2011 04:36

The security company Qualys this week demonstrated how to reverse-engineer a Microsoft patch in order to launch a denial-of-service attack on Windows DNS Server.

Microsoft incorrectly claims drop in vulnerabilities that allow remote code execution

By Jon Brodkin | 03 August, 2011 23:43

In its latest annual security report, Microsoft claimed some progress in fending off vulnerabilities that allow remote code execution.

Former Citrix CTO says virtualization will solve security problems

By Jon Brodkin | 01 July, 2011 19:36

While IT shops and vendors struggle to apply security practices to virtualized systems, a startup called virtualization to secure all types of devices.

Want to stop cybercrime? Follow the money

By Jon Brodkin | 16 June, 2011 06:49

Five dollars for control over 1,000 compromised email accounts. Eight dollars for a distributed denial-of-service attack that takes down a website for an hour. And just a buck to solve 1,000 captchas.

Mac OS X more vulnerable than Windows in some ways, security expert says

By Jon Brodkin | 07 June, 2011 04:47

Although Mac users are more likely to experience virus-free computing than Windows PC owners, there is nothing inherently more secure about Apple's operating system, and in certain respects Mac OS X is more vulnerable than Windows, a security expert tells Network World.

Google crushes, shreds old hard drives to prevent data leakage

By Jon Brodkin | 26 April, 2011 03:56

Google is shedding some of the secrecy around its data center practices, with a new video that shows extensive security measures and the destruction of old hard drives to prevent leakage of customer data.

Microsoft denies intentionally shutting off Hotmail encryption in Arab countries

By Jon Brodkin | 29 March, 2011 02:42

Microsoft says it did not "intentionally limit" access to Hotmail's HTTPS encryption service in foreign countries where freedom of expression is under attack.

Facebook security more important as e-mail spam levels drop

By Jon Brodkin | 02 March, 2011 03:45

Spammers are moving on from mass e-mail blasts to targeted attacks using social networking sites like Facebook and LinkedIn, Cisco security executive Tom Gillis said Monday.

Microsoft fixes cookie security bug in Windows Azure

By Jon Brodkin | 05 February, 2011 04:30

Microsoft has refreshed the Windows Azure software development kit to fix a bug that can expose cookie information to clients who have built applications on top of the cloud platform.

Burning question: How can security risks be mitigated in virtualised systems?

By Jon Brodkin | 26 October, 2010 00:52

"Virtualisation is not inherently insecure. However, most virtualised workloads are being deployed insecurely."

Google, YouTube received 10,000 government requests for user data

By Jon Brodkin | 21 April, 2010 08:57

Google and the Google-owned YouTube received more than 10,000 requests for user data from government agencies in the six months ending Dec. 31, 2009, according to newly released data.

60% of virtual servers less secure than physical machines, Gartner says

By Jon Brodkin | 16 March, 2010 07:47

Sixty percent of virtual servers are less secure than the physical servers they replace, the analyst firm Gartner said in new research Monday.

Enterprise cloud use on agenda for new Open Group committee

By Jon Brodkin | 17 August, 2009 13:14

The Open Group is forming a new cloud computing committee that brings vendors and end-user organizations together to develop a common understanding about how cloud services should be deployed safely and effectively.

Theft of Twitter documents from Google Apps raises cloud security concerns

By Jon Brodkin | 16 July, 2009 08:51

A hacker has reportedly obtained and distributed more than 300 confidential documents pertaining to Twitter's business affairs. The documents were reportedly stored on Google Apps.

VMware partners demonstrate VMsafe security prototypes

By Jon Brodkin | 18 September, 2008 08:53

A major VMware security initiative announced more than six months ago has still not resulted in any new products, but VMware and partners this week are demonstrating several prototypes of technology that will better secure virtual machines.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Imprivata OneSign®

Get identity and password proliferation under control, reduce helpdesk costs and extend secure, single sign-on access to any enterprise application with a single solution.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.