News

Google Web History vulnerable to new Firesheep hack

By John E Dunn | 11 September, 2011 02:42

Two researchers have shown how a modded version of the Firesheep Wi-Fi sniffing tool can be used to access most of a victim's Google Web History, a record of everything an individual has searched for.

9/11 Anniversary Spurs Hacker Mischief

By John P. Mello Jr. | 11 September, 2011 02:40

Hackers are using the anniversary of the Sept. 11, 2001, terrorist attacks to create online mischief.

Firms shun e-crime risk insurance

By Antony Savvas | 10 September, 2011 22:12

British businesses are generally not insuring themselves properly against e-crime risks, according to KPMG.

Anonymous supporters claim NBC News Twitter hack

By Robert McMillan | 10 September, 2011 09:10

Hackers calling themselves the Script Kiddies took control of the NBC News Twitter account on Friday afternoon and used it to send out a series of hoax Twitter messages claiming there was a repeat terrorist attack on New York's Ground Zero.

How to Protect Yourself From Certificate Bandits

By John P. Mello Jr. | 10 September, 2011 07:18

There have been two major Certificate Authority (CA) attacks this year. In March, a hacker successfully penetrated one of the largest CA's on the Web--Comodo--and managed to issue bogus certificates to himself (including one for Yahoo). The second incident took place this week when a Dutch CA, Diginotar, was compromised and a number of fake certificates were issued.

Security roundup: How did 9/11 change IT?; Microsoft premature patching; HIPAA gets nasty

By Ellen Messmer | 10 September, 2011 05:49

The 10th anniversary of the infamous Sept. 11, 2001, terrorist attacks on America is prompting reflection on those who died on that day of mass murder, and what changed in our society because of it.

Apple strikes stolen SSL certificates from OS X

By Gregg Keizer | 10 September, 2011 04:37

Apple today released an update to Mac OS X that blocks Safari users from reaching sites secured with certificates stolen from a Dutch company last summer.

Apple releases Security Update to block bad Web certificates

By Lex Friedman | 10 September, 2011 04:07

Apple on Friday released Security Update 2011-005, which addresses fraudulent Web security certificates issued by a recently-hacked Dutch certificate authority DigiNotar.

Whoops! Microsoft leaks patch info four days early

By Gregg Keizer | 10 September, 2011 03:02

Microsoft jumped the gun today by prematurely releasing information on all five of the security updates it plans to ship next Tuesday.

9/11: Top lessons learned for disaster recovery

By Lucas Mearian | 09 September, 2011 23:57

In the decade since the Sept. 11, 2001 terrorist attacks, physical security, human contingency planning and an evolution in technological capabilities have improved the odds that business can carry on during -- and after -- a disaster.

Hacker claims he can exploit Windows Update

By Gregg Keizer | 09 September, 2011 20:30

The hacker who calls himself "Comodohacker" said this week that he could have used digital certificates stolen from a Dutch firm to issue fake updates to Windows PCs.

AVG calls for action on mobile and cloud services security

By Antony Savvas | 09 September, 2011 19:07

Security software firm AVG sought to put some more bones on the launch of the new version of its security software product in Prague this week, with the company focusing on mobility and industry initiatives to collectively tackle security threats.

MD5 password hashes are dead

By Stilgherrian | 09 September, 2011 16:26 | 2 Comments

MD5 hashes, still a common method for securing login passwords, are no longer an adequate defence against hackers, according to Kaspersky Lab analyst Evgeny (Eugene) Aseev.

Understanding PCI compliance auditing

By CIO Staff | 09 September, 2011 15:05

Businesses of all sizes must undertake PCI compliance auditing to ensure that their customers' data is protected during credit or debit card transactions and if stored within any internal business databases.

PCI compliance requirements for Aussie businesses

By CIO Staff | 09 September, 2011 14:37

Payment Card Industry (PCI) Data Security Standards (DSS) refer to a set of standards that must be followed by big and small businesses alike when accepting, storing, processing and transmitting customers’ credit card information. To be compliant with PCI standards, all business owners, including online retailers, should adhere to 12 PCI compliance requirements for best security practices.

PCI compliance checklist

By CIO Staff | 09 September, 2011 13:57

If you're business is obliged to undertake a PCI audit, then following a PCI Compliance checklist will ensure that you're security processes and payment processing meet the compliance standards. To ensure that you are meeting PCI compliance standards, you'll need to start by looking at what exactly PCI compliant means.

Google contacts Iranian users to secure Gmail accounts

By John Ribeiro | 09 September, 2011 13:46

Google is directly contacting users in Iran, who may have been compromised by a rogue SSL certificate, to recommend measures to secure their accounts.

PCI compliance services in Australia

By CIO Staff | 09 September, 2011 13:30

If you operate, own or hold a management role in an Australian business that stores, transmits and processes customer payment data, you may have recently been contacted by your bank regarding your PCI compliance status.

What is PCI compliance?

By CIO Staff | 09 September, 2011 13:09

If you're wondering exactly what is PCI compliance, the chances are you're one of the many business owners in Australia who've asked themselves this same question. Before answering this question, it's useful to begin by looking at what PCI (and its counterpart DSS) stands for.

Nuclear warheads could be next Stuxnet target: Check Point

By Hamish Barwick | 09 September, 2011 12:36

Due to the complexity and sophistication of the code contained within the Stuxnet worm, the possibility of it being used to take control of a nuclear warhead is high, according to a security expert.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Trend Micro Mobile Security

Comprehensive enterprise protection for mobile devices

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.