Stories by Liam Tung

Anti-spam Spamhaus up again after 75Gbps DDoS attack

By Liam Tung | 21 March, 2013 15:45 | 1 Comment

The website of non-profit spam fighter Spamhaus is online again after a huge DDoS attack knocked it offline on Sunday, but attackers are continue to target another anti-spam sites that help ISPs combat spam from infected IP addresses.

Apple credits jailbreak team Evad3rs in iOS 6.1.3 security update

By Liam Tung | 20 March, 2013 09:38 | 1 Comment

Apple released iOS 6.1.3 on Tuesday that fixes six flaws, including four it credited iOS jailbreak developers “Evad3rs” with finding.

Could a US Government monopsony on zero days tackle grey exploit market?

By Liam Tung | 19 March, 2013 12:06

A researcher has proposed the US Government buy the world’s supply of zero day exploits to bring the grey market for software weapons under control.

New Chinese premier: a “presumption of guilt” in US hacker accusations

By Liam Tung | 18 March, 2013 11:43

Newly-elected Chinese Premier Li Keqiang has rejected accusations that the nation is behind cyber attacks against the US.

BlackBerry extends BB10’s ‘work-life’ wall to iOS, Android

By Liam Tung | 15 March, 2013 12:18

BlackBerry on Thursday announced Secure Work Spaces for iOS and Android, a security feature available on BlackBerry 10 devices which puts a wall between personal and work data.

Mandiant: ‘advanced attackers’ exploiting trusted supplier-client VPN

By Liam Tung | 14 March, 2013 10:54

Advanced attackers are increasingly exploiting the privileged communication channels that targets give their suppliers to launch attacks, according to US security firm, Mandiant.

Burning down the house with an RF hacking watch

By Liam Tung | 13 March, 2013 14:39

Google’s Glass and Apple’s rumoured iWatch are attracting interest in wearable technology, but security researchers have found another application -- hacking the wireless home.

DHS CERT: HP LaserJet Printer exposed to remote attack

By Liam Tung | 12 March, 2013 09:34

The US Department of Homeland Security’s CERT has urged HP LaserJet printer customers to apply a firmware update that closes a remote execution vulnerability affecting 10 models.

Pricey crime kit adds ‘McRAT’ Java zero-day four days after patch

By Liam Tung | 11 March, 2013 10:03

In less than one week, the high-priced commercial exploit kit known as “Cool” has added an exploit for the Java zero-day flaw affecting Web browser plugins that Oracle patched last Tuesday.

Java browser plugin is cheaper to exploit than Flash

By Liam Tung | 08 March, 2013 13:29

A French company that mines and sells zero-day exploits to governments says the lower cost of exploiting Java is attracting hackers towards it over Adobe’s Flash.

Galaxy SIII open to full lockscreen bypass

By Liam Tung | 07 March, 2013 11:48 | 1 Comment

Days after a mobile enthusiast discovered a partial lockscreen bypass on a Galaxy Note II, another user has found a way to bypass the lock on a Galaxy S3 and gain full access.

Samsung Galaxy Note II, S3 exposed to partial "Emergency Call" lock-screen bypasses

By Liam Tung | 05 March, 2013 09:08

Two of Samsung’s flagship smartphones running Android 4.1.2 appear to be vulnerable to separate partial screen lock bypasses via the “Emergency Call” screen.

Oracle patches latest Java 0-day, knew about flaw on Feb 1

By Liam Tung | 05 March, 2013 09:06

Oracle has released a “security alert” to address a Java SE zero day flaw that is now being used in targeted attacks, but that the company was aware of on February 1 -- over three weeks ahead of its previous critical patch update.

Zero-day exploit hits Java 7 and end-of-life Java 6

By Liam Tung | 04 March, 2013 09:03 | 1 Comment

Just two weeks after Oracle released its latest critical patch updates, attackers have found a previously unseen flaw in Java 6 and 7 to compromise computers.

FBI director: Forget firewalls, Sabu proves attribution wins domestic cyber war

By Liam Tung | 01 March, 2013 16:56

In a call to arms aimed at the private sector, the FBI’s director of 11 years Robert S. Mueller has declared that war on the new 'terror', cyber, will be won not by improved defence but by attribution.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Cloud Security and Compliance Solutions

Manage and visualize the security and compliance of VMware, physical, and hybrid-cloud infrastructure from the RSA Archer eGRC Platform.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.