News

Android app vetting is still weak, says security developer

By John E Dunn | 13 July, 2011 23:14

Google should urgently overhaul the weak application vetting that has allowed a clutch of bogus apps to sneak onto user's phones through the Market and third-party sites, the CEO of banking security specialist Trusteer has warned.

Intego releases malware scanner for iOS devices

By Michael Burns | 13 July, 2011 21:16

Intego has released VirusBarrier iOS, a malware scanner for the iPhone, iPad and iPod touch. VirusBarrier iOS allows users of iOS devices to scan files attached to e-mail messages in the cloud for malware that could affect Macs or Windows PCs.

London Grid signs identity management deal with Atos

By Anh Nguyen | 13 July, 2011 21:16

London Grid Ltd, a London Grid for Learning subsidiary, has signed a framework contract with Atos for identity management services.

Consumer device use grows, but IT and security can't keep up

By Joan Goodchild | 13 July, 2011 08:44

IT and security managers are slowly embracing the growing number of consumer devices, such as iPhones and iPads, that are being used by workers within their organizations, but many enterprises are still overwhelmed by the need to mitigate risk and support the devices. That is the finding of new research released Tuesday by Unisys Corporation. The study was conducted for Unisys by International Data Corp.

Symantec will drop RSA support altogether

By Liam Tung | 13 July, 2011 08:30

Symantec's decision to migrate its managed security services (MSS) customers off RSA’s SecurID tokens is the beginning of a complete phase out, Grant Geyer, Symantec's vice president of global managed security services told CSO.com.au.

DeWalt departs McAfee, replaced by two

By Liam Tung | 13 July, 2011 07:34

Outgoing president of Intel-owned security vendor McAfee, Dave DeWalt, will be replaced by two co-presidents drawn from McAfee's ranks.

Patch Tuesday Fixes Critical Bluetooth Flaw in Windows 7

By Tony Bradley | 13 July, 2011 06:27

Patch Tuesday has arrived. As expected, Microsoft released a relatively small number of patches for July, but that is no reason for IT admins to let their guard down--especially when one of the patches is a Critical update for Windows 7 and Windows Vista.

Cyberwar and cyber-isolationism

By Scott Bradner | 13 July, 2011 04:44

There has been a bit of a splash in the press recently about a mention by former CIA Director Gen. Michael Hayden of the idea of creating new, extra secure internets for government or commerce. Users would have to give up their privacy to use these versions of the Internet, with a requirement for the use of real names and all their traffic subject to deep packet inspection. The vision seems to be that government would use one such network and services such as banking would use another.

Mac security firm ships first-ever iPhone malware scanner

By Gregg Keizer | 13 July, 2011 02:33

A French security company known for its Mac OS X antivirus software today released the first malware-scanning app for the iPhone and iPad and iPod touch.

David Beckham's website defaced with image of dog

By John E Dunn | 12 July, 2011 23:55

Former Manchester United and Real Madrid football player David Beckham has become the latest celebrity to find himself on the receiving end of a website defacement.

Free ID Theft Protection Offers Grow: Are They Any Good?

By David Daw | 12 July, 2011 23:38

If you use the Internet or own a credit card, the threat of having your identity stolen is omnipresent. Now, leading Internet service providers, financial institutions, and companies such as Sony are offering customers peace of mind with free identity theft protection. Other companies such as Debix are offering a free bare-bones version of ID theft protection to anyone online.

Anonymous hacks Booz Allen Hamilton, steals 90,000 military emails

By Tim Greene | 12 July, 2011 23:23

The hacker group Anonymous claims it has stolen information from government contractor Booz Allen Hamilton that it says will help it hack into resources of other contractors and security consultants.

Assange attorneys argue Swedish arrest warrant is invalid

By Jeremy Kirk | 12 July, 2011 22:24

Lawyers for Julian Assange argued on Tuesday that a district judge erred when approving an invalid extradition order that would send the WikiLeaks founder to Sweden to face questioning over molestation and rape allegations.

Anonymous Releases 90,000 Military Email Addresses

By Paul Suarez | 12 July, 2011 20:11

Hacker group Anonymous continued an assault on government contractors Monday as it released 90,0000 military email addresses, passwords and some other data from military contractor Booz Allen Hamilton.

Lulzsec: the rise and fall of a hacking collective

By Liam Tung | 12 July, 2011 19:26

The curtain has fallen on the 50 day performance by hacker group LulzSec. Its campaign of mayhem and destruction, peppered with witty commentary captivated the world. In an alternate universe where Lulzcats reign and anti-security is the norm, it might have even earned a spot on its first target, The X-Factor. But on this earth its members may still be captured by its later targets: the CIA, US law enforcement and the FBI.

Investment management firm RJIS targets identity and access management

By Antony Savvas | 12 July, 2011 18:05

Raymond James Investment Services is targeting improved identity and access management for its trading platform for independent investment practices.

Online crime under-reported, under-researched

By Stilgherrian | 12 July, 2011 14:31

Most statistical information about online crime comes from vendors trying to flog products and governments eager for new police powers. We need something better. A lot better.

Anonymous breaks into Booz Allen network

By Nancy Gohring | 12 July, 2011 09:39

The Anonymous hacking group said Monday it had broken into military contractor Booz Allen Hamilton's network and posted 90,000 military e-mail addresses and passwords online.

iPhone and iPad Security: 4 Tips to Stay Safe

By Tom Kaneshige | 12 July, 2011 07:12

Are you worried about all the ruckus over the Jailbreakme.com 3.0 vulnerability for your iPhone and iPad? While you're waiting for Apple to come out with a fix, there are a few safety precautions you can take.

Researchers uncover more Android malware on Google's Market

By Gregg Keizer | 12 July, 2011 06:02

Security researchers have found more malicious Android apps on Google's official download site and being spread through Chinese app stores.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Fraud Management Solutions

Reduce fraud losses regardless of channel by preventing cybercrime, identity theft, and other threats targeting your customers.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.