News

The Latest Security Tool for Your Arsenal: Whitelisting

By Jim Buchanan | 08 July, 2011 05:12

Phishing, spear phishing, trojan horse and other attacks are growing in number and sophistication, seemingly by the day. There can be little disputing that notion after RSA, Sony, Lockheed and Citicorp were embarrassed by breaches this year.

PDFs that exploit iPhone, iPad zero-day available on the Web

By Gregg Keizer | 08 July, 2011 04:15

Hours after developers revealed they had exploited bugs in Apple's iOS to "jailbreak" iPhones and iPads, German government security authorities warned that one of the flaws could be put to malicious use.

Apple developing fixes for dangerous iOS vulnerabilities

By Jeremy Kirk | 08 July, 2011 00:42

Apple said on Thursday that it is developing a fix for vulnerabilities that affect its iPhone, iPad and some iPod touch models, a problem that the German government warned could be used to steal confidential data.

Washington Post reports data breach on job ads section

By Jeremy Kirk | 07 July, 2011 23:09

The Washington Post has alerted job seekers who use its employment pages of a data breach that compromised up to 1.27 million accounts.

Morgan Stanley warns 34,000 customers of data breach

By Anh Nguyen | 07 July, 2011 18:11

Morgan Stanley has warned 34,000 investment clients that their personal data may have been stolen while in transit to a government tax office.

Civil servants concerned about consumer device security

By Antony Savvas | 07 July, 2011 18:11

Seven in 10 senior civil servants think the use of personal laptops in the workplace increases data security risks, and 80 percent also believe smartphones worsen the potential problem.

Sea Eagles fly with Kaspersky sponsorship

By CIO Staff | 07 July, 2011 15:43

The Manly Sea Eagles announced a new major sponsor, IT security company, Kaspersky Lab.

Anonymous launches Operation Turkey

By Tim Lohman | 07 July, 2011 09:32

Hacktivist group Anonymous appears to have taken ownership of the Turkish domain of International Center for Human Development as part of its latest protest action, Operation Turkey.

Analyst: Jailbroken iPhones more secure than normal ones

By Liam Tung | 07 July, 2011 08:52

Apple’s latest version of iOS 4.3.3 shipped with a PDF vulnerability that can only be patched in jailbroken iPhones.

Kaspersky reports new Mac Trojan

By Liam Tung | 07 July, 2011 08:21 | 1 Comment

Antivirus company Kaspersky has reported the discovery of another backdoor trojan for Mac OS X, providing further evidence the days of flying under the radar are over for Mac users.

DHS tests show security's people problem

By Lucas Mearian | 07 July, 2011 06:19

It was widely reported last week that as part of a study, the U.S. Department of Homeland Security (DHS) randomly dropped USB and optical drives in government and private contractor parking lots -- and more than half of those who picked one up readily plugged it into their work computer.

Second DOE lab is likely victim of spear-phishing attack

By Jaikumar Vijayan | 07 July, 2011 05:15

The Department of Energy's Pacific Northwest National Laboratory (PNNL) is working on restoring Internet connectivity and email services after being hit by a "sophisticated cyberattack" five days ago.

Google+ privacy

By Kristin Burnham | 07 July, 2011 03:30

While Google's new social network, Google+, is barely a week old, it's already received a lot of attention from tech pundits and the social media community. And as with any new online service, understanding how to control your information is essential.

Italian police raid Italian branch of Anonymous

By Philip Willan | 07 July, 2011 02:05

Italian police have reported 15 suspected members of the Italian branch of the Anonymous hacker group to the judiciary for investigation on charges of illegally accessing IT systems, damaging IT systems and interrupting a public service, Italian media reported Wednesday.

Google dealing with privacy bugs in Google+

By Juan Carlos Perez | 07 July, 2011 01:38

Google's new social networking site Google+, built to beat Facebook primarily on privacy features, has several privacy bugs the company is working to fix.

Hacking team claims NATO server compromised

By Jeremy Kirk | 06 July, 2011 23:22

A group of hackers going by the name of the "Inj3ct0r Team" are claiming they've compromised a server belonging to the North Atlantic Treaty Organization (NATO).

DDoS attack in March likely North Korean work, says McAfee

By Martyn Williams | 06 July, 2011 15:53

The cyber attacks that paralyzed a handful of major South Korean websites earlier this year were almost certainly carried out by North Korea or parties allied with the country, computer security company McAfee said in a report.

Twitter account of PayPal UK hacked

By John Ribeiro | 06 July, 2011 14:05

The Twitter account of PayPal U.K. was hacked late Tuesday and used to post messages attacking the online payment processing company.

Rustock botnet was busy in Australia

By Liam Tung | 06 July, 2011 09:00

While Microsoft observed a larger than 60 per cent fall in the number of Asian and Europen IP addresses contacting its Rustock sinkhole, the number for Australia dropped between 30 to 40 per cent, according to Microsoft’s Malware Protection Center figures. Australian reductions were similar to figures recorded for the US.

If Disaster Strikes Will Critical Enterprise Apps Be Ready

By Todd R. Weiss | 06 July, 2011 06:59

It's summer across the U.S., and that means that hurricanes, tornadoes, floods, wildfires, powerful thunderstorms and other natural disasters can take out your company's IT systems in a flash.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Web Security and Control

Protect your users on the web

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.