- Seven technology predictions for 2014
- Hacker-built drone can hunt, hijack other drones
- The week in security: Microsoft fights NSA as shadow IT bites business
- French Treasury accidentally signs SSL certificate for Google.com domains
- Information Commissioner received no eHealth privacy complaints in 2012-13
The maker of a popular flashlight app for Android phones has agreed to settle charges brought by the Federal Trade Commission that it left consumers in the dark about its data-sharing practices.
Thirteen people, including the creator of Blackhole, a popular exploit tool used to infect computers with malware, were arrested and charged in Russia with creating and participating in a criminal organization.
Anonymous members, charged with a distributed denial-of-service attack on PayPal, entered a plea Thursday that could see some of them walk free at sentencing next December.
Microsoft and law enforcement agencies said Thursday that they disrupted a botnet that defrauded online advertisers of US$2.7 million a month but that the malicious network hasn't been completely eliminated.
German police have arrested two persons they accuse of hacking computers and using them to generate bitcoins police valued at more than €700,000 (US$954,000). A third suspect was not taken into custody, police said.
It may be difficult to remember now, but not too long ago, cyberattacks rarely made headlines in mainstream news. That's not to say that these advanced persistent threats, sometimes state-sponsored or the product of organized crime, were uncommon. On the contrary, they were booming. It was just that few people liked to talk about them.
It's a common belief in the information security world that the Chinese government is behind many of the advanced persistent threats that target companies around the world in an effort to steal their IP and trade secrets. Now one security firm has come forward with years of evidence to link a prolific APT group to a unit inside the Chinese government.
We are standing in a parking lot in the city of Malmö, southern Sweden, one of the many places Peter Sunde now calls home. The sky above us is grey, as usual at this time of year. Just as the parking meter spits out our ticket, a young man driving much too fast on a motorcycle roars up behind us. He is followed by a police car, sirens blaring and blue lights flashing.
They're security myths, oft-repeated and generally accepted notions about IT security that ... simply aren't true. As we did a year ago, we've asked security professionals to share their favorite "security myths" with us. Here are 13 of them.
For years, information security experts have predicted a spike in mobile malware. Will 2013 be the year of mobile attacks? And what other security threats are on the horizon?
Sign up now »
Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).
- Have an incident response plan.
- Pre-define your incident response team
- Define your approach: watch and learn or contain and recover.
- Pre-distribute call cards.
- Forensic and incident response data capture.
- Get your users on-side.
- Know how to report crimes and engage law enforcement.
- Practice makes perfect.
I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.