Data Security
News
- +
CBS website bitten by iFrame hack 02/12/2008 07:30:00
Russian malware distributors have launched another iFrame attack on a sub-domain of the cbs.com site.TV network CBS has become the latest big name to have it website used to host malware, a security company has reported. - +
Symantec takes cybercrime snapshot with new report 25/11/2008 07:31:00
Keystroke loggers going for just US$23The criminal market online for buying and selling stolen credit cards, pirated software and information about financial accounts is thriving, according to a report published Monday by Symantec. - +
Symantec sees spike in dangerous Microsoft attacks 24/11/2008 07:04:00
Symantec is warning of a 'dramatic rise' in attacks exploiting a critical Windows bug.Symantec is warning of a sharp jump in online attacks that appear to be targeting a recently patched bug in Microsoft's Windows operating system, an analysis that some other security companies disputed Friday. - +
Cybersecurity is focus of new start-up incubator 20/11/2008 07:19:00
Texas uni announces the Institute for Cyber Security.The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state. - +
Laid off sysadmin arrested for threatening company's servers 11/11/2008 11:13:00
Epmloyee "not satisfied with the terms" of his severance goes too far, gets arrested.A systems administrator was arrested in New Jersey Monday for allegedly trying to extort money and even good job references out of a New York-based mutual fund company that had just laid him off. - +
Sun exec: IT security should follow business needs 30/10/2008 09:04:00
Proscriptive adoption of information security standards like ISO27001 is bound to fail, Sun's chief technologist says.Proscriptive adoption of information security standards like ISO27001 is bound to fail, according to Joel Weise, principal engineer and chief technologist, Sun client services security program office, Sun Microsystems. - +
Report: Malicious spam spikes in the enterprise 30/10/2008 10:29:00
New survey results from Sophos find the number of spam emails with dangerous attachments have soared. The report reveals the malicious messages rose eight-fold in just three monthsNew survey results from Sophos find the number of spam emails with dangerous attachments have soared. The report reveals the malicious messages rose eight-fold in just three months. - +
Clumsy staff more dangerous than hackers: survey 23/10/2008 11:41:00
Data breaches cost local business up to $1 millionUp to 79 percent of the 156 Australian IT managers and C-level executives responding to a recent survey have suffered IT data breaches. - +
US gov't increasing efforts to fight ID theft, report says 22/10/2008 09:40:00
Many US state and local governments continue to release Social Security numbers (SSNs) in public documents, according to a report.The U.S. government has taken several steps to combat identity theft during the past two years, including increased prosecutions of criminals and decreased use of Social Security numbers to identify constituents, according to a report released Tuesday. - +
Experts: Georgian cyberattacks suggest Russian involvement 20/10/2008 07:37:00
Speed, sophistication of August attacks point to likely government linkThe hackers who launched cyberattacks against the former Soviet republic of Georgia two months ago probably had links to the Russian government, even though no hard evidence has been uncovered of official involvement, a report by an all-volunteer group of experts said Friday. - +
Tough economic climate can heighten insider threat 16/10/2008 07:09:00
As companies downsize, they need to keep an eye out for disgruntled employeesWith a faltering economy resulting in increased jobs cuts and corporate belt tightening, security analysts are warning companies to be especially vigilant about protecting their data and networks against disgruntled employees. - +
IBM, Secret Service, others study identity/cybercrime issues 09/10/2008 10:09:00
Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking. - +
Former State Dept worker pleads guilty in US passport access case 24/09/2008 10:26:00
Details of Senators Barack Obama, John McCain and Hillary Clinton improperly accessed by employee.A former employee at the US Department of State has pleaded guilty to illegally accessing the confidential passport records of hundreds of celebrities, politicians and other public figures. - +
At Adobe's request, hackers nix 'clickjacking' talk 17/09/2008 09:27:00
Two security researchers have cancelled an upcoming talk on clickjacking because it would have disclosed a critical Adobe bug.After Adobe Systems asked them to keep quiet about their findings, two security researchers have pulled out of a technical talk where they were going to demonstrate how they could seize control of a victim's browser using an online attack called 'clickjacking.' - +
Forever 21: Nearly 99,000 cards compromised in data thefts 17/09/2008 08:08:00
The thefts, which date back to 2004, were uncovered by the DOJNearly 99,000 payment cards used by customers at several Forever 21 retail stores may have been compromised in a series of data thefts dating back to August 2004.
Features
- +
International Challenges in PCI Security 20/11/2008 09:15:00
In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective. - +
A sneaky security problem, ignored by the bad guys 17/11/2008 08:51:00
Rootkits are sneaky, but are they a major threat?Frank Boldewin had seen a lot of malicious software in his time, but never anything like Rustock.C. - +
Social Engineering: Eight Common Tactics 13/11/2008 12:00:00
A refresher course on some of the most prevalent social engineering tricks used by phone, email and Web.A refresher course on some of the most prevalent social engineering tricks used by phone, email and Web. - +
How to Use Network Behavior Analysis Tools 13/11/2008 12:42:00
Network behavior analysis tools can help tune operations as well as improve security. Here are five tips for getting the job done.Network behavior analysis tools can help tune operations as well as improve security. Here are five tips for getting the job done. - +
Outsourcing/Offshoring: An IT Security Expert's View 13/11/2008 11:49:00
Offshore outsourcing may save you money, but it also creates new risks. Here's a guide to necessary IT security measuresOffshore outsourcing may save you money, but it also creates new risks. Here's a guide to necessary IT security measures. - +
Three Ways Internet Crime Has Changed 06/11/2008 10:17:00
Malware and botnets and phishing, oh my! Symantec's latest report on the Internet threat landscape highlights trends in cybercrime.Malware and botnets and phishing, oh my! Symantec's latest report on the Internet threat landscape highlights trends in cybercrime. - +
PCI's Post-Audit Pain Points 06/11/2008 10:01:00
Passed your first PCI compliance audit? You've only just begun! Veterans say ongoing challenges with log management, database encryption and upper management buy-in mean the task is never finishedPassed your first PCI compliance audit? You've only just begun! Veterans say ongoing challenges with log management, database encryption and upper management buy-in mean the task is never finished. - +
A tale of two PCI security audits 06/11/2008 09:35:00
Robert Duran of Time and Allan Kintigh of National Card Services share their PCI auditing experiences. Why one's experience was unpleasant and the other fared better.Robert Duran of Time and Allan Kintigh of National Card Services share their PCI auditing experiences. Why one's experience was unpleasant and the other fared better. - +
Morris worm turns 20: Look what it's done 03/11/2008 07:57:00
First Internet attack spawned panic, public awareness and security researchThe Internet will mark an infamous anniversary on Sunday, when the Morris worm turns 20. - +
Where is Robert Morris now? 03/11/2008 07:57:00
Internet's first attacker is respected MIT professorRobert Tappan Morris, the 21-year-old Cornell University student who unleashed the first worm attack on the Internet in 1988, has fully rehabilitated his reputation in the computer science community. Today, he is a respected associate professor of computer science at MIT. - +
Five ways to bulk up your network for telecommuters 23/10/2008 07:41:00
Tips for adapting your corporate network for people working from homeWhether they're in branch offices or home offices, workers are increasingly telecommuting instead of working in a traditional centralized office environment. - +
Up next: Cellular botnets, cyber militias 20/10/2008 07:30:00
More troubles ahead to keep security pros up at nightThe ability of malware writers to consistently stay ahead of those seeking to stop them has been a constant factor in the security industry over the past several years. - +
Inside Symantec's Security Operations Center 16/10/2008 07:38:00
For Symantec clients, the Symantec Security Operations Center is the front line in the fight against network attacks. CSO toured the facility for an overview of how the services work, and for a look at some of the latest threats on the internet todayThe inside of the Symantec Security Operations Center looks like a scene out of the movie "War Games," and in many ways, the connection is fitting. The SOC, as it is known by Symantec employees, is in the business of detecting and analyzing network threats. And as malicious activity online gets increasingly more sophisticated, the war against cybercrime is definitely on. - +
Cyber security threats grow in sophistication, subtlety 16/10/2008 08:26:00
Researchers say malware, botnets, cyber warfare, threats to VoIP and mobile devices, and the "evolving cyber crime economy" are ever-more sophisticated threatsThe annual report from Georgia Tech Information Security Center identifies five evolving cyber security threats, and the news is not good. - +
Four security lessons from the World Bank breach 15/10/2008 07:39:00
The World Bank is making headlines after a disputed report claims hackers managed to access their secure network for over a year. One security pro offers takeaways that everyone can learn from the breachAccording to a report from Fox News, several servers at the World Bank Group, an organization that offers economic assistance to developing countries around the globe, were repeatedly compromised and breached over the course of the last year.
Case Studies
- +
Employment firm trains staff in compliance with network management kit 05/03/2008 12:03:13
Console keeps 350 Windows machines in checkEmployment and training firm CVGT has installed a network management toolkit to enforce compliance and protect the financial and personal data of its 40,000-plus apprentices and trainees. - +
Uni fortifies Western Front with IDS 22/02/2008 20:11:00
Nurtured NAC keeps malware outThe University of Western Sydney (UWS) has today gone live with a managed Intrusion Detection System (IDS) for its 5000 users.
Interviews
- +
Why Cybercrime is Thriving 27/11/2008 11:52:00
A new Symantec report reveals just how large and sophisticated the online underground economy has grownA new Symantec report reveals just how large and sophisticated the online underground economy has grown. - +
Chris Hoff on Virtualization and Cloud Computing 20/11/2008 10:55:00
Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly. - +
How IT Helped Catch the Jewellery Thief 13/11/2008 11:52:00
A jewellery store chain is having much better luck catching burglars in real time, thanks to a little help from the IT side of the house.A jewellery store chain is having much better luck catching burglars in real time, thanks to a little help from the IT side of the house. Loss Prevention Manager Dennis Thomas explains how the company built its high-tech command center from scratch. - +
Cisco CSO says security is growing up 07/08/2008 07:51:10
Interview: CSO John Stewart admits Cisco made mistakes in suing a researcher for exposing router flaws three years ago at Black HatJohn Stewart doesn't talk like your typical corporate executive. He said that his company, Cisco Systems, has been lucky when it comes to security and that his company's Self-Defending Network marketing push has painted "a big bull's-eye" on its products. - +
Cybercrime Convention will benefit Australia, says proponent 19/05/2008 09:36:30
Countries that have complied with the Convention have considerably strengthened their cybercrime legislation.The Convention on Cybercrime is the work of the Council of Europe and is aimed at facilitating international cooperation in the investigation and prosecution of computer crimes. Since the Convention came into being in 2001, the COE has been working to address the growing international concern over the threats posed by hacking and other computer-related crimes. - +
Head of PCI council sees security standard as solid 17/04/2008 10:40:46
GM Bob Russo defends payment card rules but acknowledges that 'interpretation issues' remainThe PCI Security Standards Council was established in the US by the major credit card companies in September 2006 as an independent organization to manage the Payment Card Industry Data Security Standard. In an interview, general manager Bob Russo talks about the council's efforts to administer the PCI standard amid continuing concerns about credit and debit card security. And he defends the standard, despite the recent data breaches at Hannaford Bros. and Okemo Mountain Resort.
Opinions
- +
Hard times mean more problems with insider security 05/11/2008 09:07:00
Given stressful situations, people are more likely to partake in risky activity, malicious, criminal or otherwise.Does my company need to be more proactive about insiders during hard times? - +
How to prevent cyber espionage 23/10/2008 11:06:00
Security expert Gadi Evron has plenty of experience helping governments fight cyber attacks. In this column, he offers a roadmap companies can use to prevent computer espionageSecurity expert Gadi Evron has plenty of experience helping governments fight cyber attacks. In this column, he offers a roadmap companies can use to prevent computer espionage. - +
How to minimize the impact of a data breach 01/10/2008 08:54:00
ID Experts' Rick Kam describes a customer-centric action planThirty-one percent of customers--nearly one-third of a company's client base and revenue source--are terminating their relationship with organizations following a data breach, according to a recent study by the Ponemon Institute. - +
Sarah Palin demonstrates the peril of webmail 18/09/2008 12:35:00
A hacked webmail account highlights the risk of trusting too much information to a service that may not be as secure as you.If you needed any more reminders about why it isn't a good idea to use external mail services to conduct critical business, the recent break-in to US Republican Vice-Presidential candidate Sarah Palin's gov.palin@yahoo.com Yahoo inbox should be it. Of note is that following the disclosure of the inboxes the compromised address and another address, gov.sarah@yahoo.com, have been suspended. - +
'Whaling' threats target the big fish of the corporate world 10/09/2008 14:50:00
Whaling has increasingly been in the news thanks to the ingenious ways a new breed of phishermen collect data to carry out scams and the move towards targeting business networking sites.The proliferation and popularity of collaborative Web 2.0 sites – there are around 250,000 new registrations to Facebook everyday – has changed the threat landscape and the way businesses need to think about security. Each year, newer technologies and weapons are being unleashed to leave Web users surprised, annoyed and at greater risk.‘Whaling’ or ‘spear phishing’, is one such threat and refers to phishing scams which specifically target high-worth individuals. - +
Information security governance: Centralized vs. distributed 05/09/2008 10:15:00
Should security policies, procedures and processes be managed within a central body, or distributed at an individual level? You need to find the middle ground.The management of information risk has become a significant topic for all organizations, small and large alike. But for the large, multi-divisional organization, it poses the additional challenge of determining how to deploy an information security governance program among what are often disparate business units. Should the policies, procedures, and processes that define the program be developed and managed within a central, corporate body? Or perhaps responsibility would be better placed at the individual unit level? Is there a workable middle-ground? - +
Security ROI: Fact or Fiction? 03/09/2008 08:32:00
Bruce Schneier says ROI is a big deal in business, but it's a misnomer in security. Make sure your financial calculations are based on good data and sound methodologies.Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable. - +
Information Security and the Importance of Context 01/09/2008 10:00:00
Those entrusted with information security must raise their contextual awarenessWhen the US Transportation Security Administration (TSA) was first created, it created a sudden need for tens of thousands of screeners. Getting a job as an airport screener was a pretty easy process. It seemed as though if you had a pulse, you were in. Jump forward to 2008 and becoming a screener is a bit harder as the TSA has instituted background checks, has upped the educational requirement to include a high school diploma or GED, and added other significant requirements. - +
Separation of duties and IT security 28/08/2008 09:40:00
Muddied responsibilities create unwanted risk. Kevin Coleman says auditors may start labeling poorly defined IT duties as a material deficiency.Separation of duties is a key concept of internal controls and is the most difficult and sometimes the most costly one to achieve. This objective is achieved by disseminating the tasks and associated privileges for a specific security process among multiple people. - +
Reflections on a new internal data theft study 13/08/2008 08:38:28
Who steals data, and what do they do with it? Cooper Bachman of ID Analytics scrutinizes research from a dozen data thefts resulting in 1,300 attempted instances of data misuse.While external data breaches involving household brand names such as TJX tend to grab more headlines, insider data thefts are emerging as compliance and reputational risks for organizations. Recent studies suggest that over 60 per cent of data breaches originate from an internal source or event. One reason for this is that in today's data-rich environment organizations continue to struggle with the 'human element' at the heart of data security. It can be extremely difficult to balance the protection of sensitive data with granting access to employees who need it to complete their daily job requirements. To that end, organizations have implemented several new security measures including employee education programs, data access monitoring, and strict policies regarding USB ports and portable devices. Although these are steps in a positive direction, little has been done to study and understand how the data is exploited once it leaves an organization. - +
Lessons learned from the Kaminsky DNS vulnerability 18/07/2008 10:25:47
What do we know about the Kaminsky DNS vulnerability, and what has come to light in the time since the initial announcement?There has been a lot of speculation devoted to the impending release of information about a DNS vulnerability discovered and initially announced by Dan Kaminsky almost two weeks ago. A lot of the coverage has been back and forth arguing about whether what has been discovered is relevant or not but the best thing to have done in the intervening period is to have sat on your hands and waited. - +
Selling zero-day exploits has a down side 07/07/2008 10:16:36
There is an ongoing argument about the ethics of selling 0-day exploits on the open market: It helps if you don't sell exploits targeting the company you work for.Information Security can sometimes be a funny field to work in. Some days it seems as if anybody with their hands on unpublished exploit code can sell it for all they're worth, and others it seems that they are set to become the target of law enforcement and the companies the code affects. It does help if you don't work for one of the companies that is set to be affected by the exploits you are trying to sell and aren't trying to bootstrap a competing company in the process. - +
How your cold explains network intrusion 01/07/2008 14:50:29
It's Cold and Flu season, but did you know your pounding sinuses can be used to explain system and network compromises?With the cold an flu season most definitely upon us, there is much that the common cold can show us about network intrusion and what can happen once a single compromise has taken place. - +
'I have a lost laptop horror story for you' 30/06/2008 10:08:14
The devil of identity theft is in the details that follow...The devil of identity theft is in the details that follow: Russ Jones tells a tale of woe that isn't particularly dramatic -- or rare -- and yet it's exactly the kind of story that worries me enough to ignore my better judgment and buy identity-theft protection from my insurance provider. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
BackTrack is the quickest way to get access to hundreds of (legal) hacking toolsVersion 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools.
Additional Resources
CSO Online Member Login
EXCOM scores back-to-back award trifecta 2008-12-01 10:46:00+11
“Just Graphics” isn’t enough any more 2008-11-28 15:02:00+11
Why Sealy’s management sleep soundly at nights... 2008-11-28 11:18:00+11
Capture and Digitize Your Treasure Moments ~ Compro VideoMate C200 USB A/V Capture Stick 2008-11-26 12:37:00+11
Net 24 slashes backup window by two-thirds 2008-11-26 10:28:00+11
Sponsored Links
PC World
Buying Guides
Good Gear Guide
Buying Guides
Computerworld
ARN


