Stories by Lucian Constantin

Researchers uncover new global cyberespionage operation dubbed SafeNet

By Lucian Constantin | 17 May, 2013 16:44

Security researchers from Trend Micro have uncovered an active cyberespionage operation that so far has compromised computers belonging to government ministries, technology companies, media outlets, academic research institutions and nongovernmental organizations from over 100 countries.

New Mac spyware found on Angolan activist's computer

By Lucian Constantin | 17 May, 2013 12:04

Previously unknown Mac OS X spyware, signed with a valid Apple Developer ID, has turned up on the laptop of an activist from Angola at a human rights conference in Norway.

Four former LulzSec members sentenced to prison in the UK

By Lucian Constantin | 16 May, 2013 18:11

Four British men associated with the LulzSec hacker collective received prison sentences Thursday for their roles in cyberattacks launched by the group against corporate and government websites in 2011.

Pushdo botnet is evolving, becomes more resilient to takedown attempts

By Lucian Constantin | 16 May, 2013 14:41

Security researchers from Damballa have found a new variant of the Pushdo malware that's better at hiding its malicious network traffic and is more resilient to coordinated takedown efforts.

Researchers uncover large cyberfraud operation targeting Australian bank customers

By Lucian Constantin | 15 May, 2013 15:48

Security researchers from Russian cybercrime investigations firm Group-IB have uncovered a cyberfraud operation that uses specialized financial malware to target the customers of several major Australian banks.

Adobe releases critical security updates for Reader, Flash Player and ColdFusion

By Lucian Constantin | 14 May, 2013 17:27

Adobe has released scheduled security updates for its Reader, Acrobat, Flash Player and ColdFusion products on Tuesday in order to fix many critical vulnerabilities, including one that is already actively exploited by attackers.

Android threats growing in number and complexity, report says

By Lucian Constantin | 14 May, 2013 14:44

The Android threat landscape is growing in both size and complexity with cybercriminals adopting new distribution methods and building Android-focused malware services, according to a report from Finnish security vendor F-Secure.

Lookout will intercept privacy-invading mobile ad networks, apps

By Lucian Constantin | 13 May, 2013 14:14

Mobile security vendor Lookout plans to start flagging as adware mobile apps that use aggressive ad networks if they don't obtain explicit consent from users before engaging in behavior that potentially invades privacy.

Academic institutions urged to take steps to prevent DNS amplification attacks

By Lucian Constantin | 10 May, 2013 16:42

Colleges and universities are being encouraged to scrutinize their systems to keep them from being hijacked in DDoS (distributed denial-of-service) attacks.

Adobe warns customers of unpatched critical flaw in ColdFusion

By Lucian Constantin | 09 May, 2013 14:50

Adobe has warned users of its ColdFusion application server platform of a critical vulnerability that could give unauthorized users access to sensitive files stored on their servers.

Name.com forces customers to reset passwords following security breach

By Lucian Constantin | 09 May, 2013 11:55

Domain registrar Name.com forced its customers to reset their account passwords on Wednesday following a security breach on the company's servers that might have resulted in customer information being compromised.

Highly critical vulnerability fixed in Nginx Web server software

By Lucian Constantin | 08 May, 2013 11:19

The development team behind the popular Nginx open-source Web server software released security updates on Tuesday to address a highly critical vulnerability that could be exploited by remote attackers to execute arbitrary code on susceptible servers.

AutoIt scripting increasingly used by malware developers

By Lucian Constantin | 07 May, 2013 12:35

AutoIt, a scripting language for automating Windows interface interactions, is increasingly being used by malware developers thanks to its flexibility and low learning curve, according to security researchers from Trend Micro and Bitdefender.

Dutchman arrested in connection with large DDoS attack on Spamhaus

By Lucian Constantin | 26 April, 2013 18:07

A 35-year-old Dutchman was arrested Thursday in Spain, as part of an investigation into a large-scale DDoS (distributed denial-of-service) attack that targeted a spam-fighting organization called the Spamhaus Project in March

Hackers increasingly target shared Web hosting servers for use in mass phishing attacks

By Lucian Constantin | 26 April, 2013 14:43

Cybercriminals increasingly hack into shared Web hosting servers in order to use the domains hosted on them in large phishing campaigns, according to a report from the Anti-Phishing Working Group (APWG).

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

SECURE Web Gateway

Balancing the requirement for strong network security with the need to harness collaborative web technologies is essential for business growth.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.