Physical Security — News
CS-Cart v3.0.4 has PayPal ‘buy without paying’ glitch
E-commerce merchants using shopping cart software CS-Cart version 3.0.4 and earlier are vulnerable to a flaw that allows fraudsters to buy goods without paying for them.
Oz watchdog eyes whitelisting as “reasonable” privacy measure
Enterprise information security in Australia could come under much greater scrutiny with the nation’s Information Commissioner looking to drill down deeply into the details of an organisation’s security practices after a breach.
Week in security: FreeBSD hacked as Facebook, Adobe redouble security efforts
Smart meters have long been a contentious issue in Australia and elsewhere, but some researchers warn that they're broadcasting unencrypted usage information that could be used to figure out whether you're at home or not.
Social engineer whiz kid Cosmo gets six-year Internet ban
Cosmo, the 15 year-old member of the hacking crew UG Nazi began a six-year Internet lock down this week after striking a plea bargain over a host of crimes, including an international credit card fraud bust led by the FBI last year that extended to Australia.
Aussie drug prescriptions sit pretty for health fraud
Drug dealers that sell prescription steroids, opioids and other “Schedule 8” controlled drugs, are exploiting the lack of consistency in legitimate Australian prescription documents, according to a Queensland Health investigator.
Exactly what is Homeland Security watching for on Facebook, Twitter, YouTube?
The idea that any number of federal institutions are watching your every move on social networks like Facebook, Twitter is unnerving at best. The Department of Homeland Security is one of those agencies and today it testified before a House subcommittee to define and defend its role in social media monitoring.
Researchers crack satellite encryption
Researchers at a university in Bochum, Germany claim to have cracked encryption algorithms of the European Telecommunications Standards Institute (ETSI) that are used to secure certain civilian satellite phone communications.
Security Manager's Journal: Should physical security belong to us?
I've always wanted to be responsible for physical security. I never understood why the security of computers, networks and data is managed by a different department than the security of doors, windows and cameras. The same principles apply in both worlds. And let's face it: Physical security is actually run on computers. So I think it's perfectly natural for information security to own it.
Carrier IQ security risks overblown?
While we wait for the final judgment on the privacy implications of the Carrier IQ fiasco, security pros are asking what the potential security implications of the embattled mobile diagnostic software could be.
Cyber-thieves using DDoS to distract banks and victims from spotting fraud
Cyber-thieves are using distributed denial-of-service (DDoS) attacks in order to distract banks from spotting and reversing fraudulent wire transfers initiated on behalf of their customers.
The typical fraudster - the threat from within.
Speaking in Sydney last week at The Attachmate Group, Inc’s customer briefing “ A Powerful Connection 2011”, Stan Gallo, Associate Director, KMPG Forensic gave an overview of the latest global research into the typical fraudster, the incidence of fraud and identity theft in Australia.
Barack Obama’s security circus arrives in Oz: In Pictures
After jumping through countless hoops to get the required set of security clearances and approval by the US Embassy to photograph the President’s visit CSO can see why these steps were justified.
Our photojournalist Neerav Bhatt was less than 5 metres away from the world’s most heavily secured individual - the President of the United States of America, Barack Obama.
Lethal medical device hack taken to next level
The wireless hacking of a medical device, first demonstrated at the Black Hat 2011 conference in August, has been taken a step further. An insulin pump has been hacked and instructed to deliver a lethal dose without first knowing the device's ID number.
Ex-CIA boss "in awe" of Chinese hackers as RSA boss defends SecurID attack
Despite claims the phishing email that netted RSA’s staff in its SecurID breach was a crude example of social engineering, RSA boss Art Coviello insists it was highly sophisticated and would have fooled even the most skilled PC operator.
Biometrics scares most people
Biometrics — the security method for identifying an individual by making a match of fingerprints, iris, face, voice, DNA and other unique physical traits — scares people, an industry leader in the field acknowledged this week. But enterprise technology managers say there's no doubt biometrics is a boon to enterprise security.
Prototype "Rapid DNA" technology exhibited; could bolster forensic investigations
TAMPA -- Using a portable kit to be able to quickly analyze human DNA collected in the field for investigative and forensics purposes has been a long-time dream for the Federal Bureau of Investigation (FBI), law enforcement and the Department of Defense (DoD).
Will advanced biometrics automate future war machines?
TAMPA -- Biometric security breakthroughs are coming that would let the military capture from a distance an iris and facial scan of an individual and immediately match it to a biometrics-based "Watch List" of suspected terrorists, combatants or criminals.
Facial recognition security, privacy issues grab FTC attention
The Federal Trade Commission the week said it will hold a workshop that examines how burgeoning use of facial recognition technology impacts privacy and security.
Yet another free pass for Aussie spooks
Something doesn't add up. ASIO is doing pretty well. So are our police. Australians sleep safer in their beds than ever before. Yet the government is rushing to pass new laws to "protect" us so fast they're even forgetting the widgets that make them work.
- 1
The new IAM: nailing shut the door on the Trojan horse
- 2
Despite $1.46b furphy, 2013-14 Budget offers slim pickings for cyber security
- 3
VMWare wants software defined data centres for better security
- 4
iiNet’s Web analytics delivers real-time security bonus
- 5
Security a key factor in LogMeIn’s Internet of Things platform
-
Splunk Named a Leader in Gartner Magic Quadrant for SIEM
-
Dell Sets Sights on Cisco, Announces Game-Changing NSA Series That Introduces Powerful Next-Gen Firewall Advances for Mid-sized Businesses and Distributed Enterprises
-
Silver Peak saves Riverbed customers up to 86 per cent with software upgrade program
-
Ovum analysis ranks Orange Business Services ahead of APAC competition for service capability and strategy
-
2013 Brightcove Innovation Award Winners Announced at PLAY 2013 Global Customer Conference
- FTTest Manager - IMMEDIATE STARTNSW
- FTQuality ManagerSA
- FTWeb Developer- Drupal and PHP. Exciting new position- #2 in Dev team.$100k+SuperNSW
- FTSenior E-Commerce PHP Developer- North Sydney- E-commerce Software $110kNSW
- FTR&D EngineerSA
- FTSnr Web Developer PHP/Magento/API integration into E-commerce sites. $100k+SuperNSW
- FTTest EngineerVIC
- FTTest Analyst (MS Environment) .netNSW
- FTLead Software EngineerSA
- FTTest Analyst (MS Environment) .netNSW
- FTSenior Python Web Applications DeveloperNSW
- FTOS Web Applications DeveloperNSW
- FTSenior Projects EngineerNSW
- FTTechnical Account Manager - MSP + CloudVIC
- FTSenior Python DeveloperNSW
- FTSenior Python DeveloperNSW
- FTSenior Field Engineer - MSNSW
- FT.NET - Sitecore Developer - Melbourne - PermNSW
Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).
- Have an incident response plan.
- Pre-define your incident response team
- Define your approach: watch and learn or contain and recover.
- Pre-distribute call cards.
- Forensic and incident response data capture.
- Get your users on-side.
- Know how to report crimes and engage law enforcement.
- Practice makes perfect.
Warning: Tips for secure mobile holiday shopping
I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.










