News

Phishing gang jailed for plundering woman's £1 million life savings

By John E Dunn | 13 May, 2013 18:23

A heartless phishing gang that stole and frittered a British woman's entire £1 million ($1.6 million) life savings on items including "gold and cheeseburgers" have been handed heavy sentences by a judge at London's Southwark Crown Court.

Labor Department hackers more sophisticated than most

By Antone Gonsalves | 13 May, 2013 17:15

Security pro says attacks designed for further breaches, noting, 'They're not gathering this information and sending it home for no reason'

Using security skills for charitable cause

By Lauren Gibbons Paul | 13 May, 2013 16:14

Back in 2007 Johnny Long came to a fork in the road. An accomplished IT security pro with 13 years working at one of the big names, he had a great career and family, but he didn't feel fulfilled. And he had no idea why not.

Lookout will intercept privacy-invading mobile ad networks, apps

By Lucian Constantin | 13 May, 2013 14:14

Mobile security vendor Lookout plans to start flagging as adware mobile apps that use aggressive ad networks if they don't obtain explicit consent from users before engaging in behavior that potentially invades privacy.

In legal fog, Kim Dotcom removes 3D gun design

By Jeremy Kirk | 13 May, 2013 05:53

Kim Dotcom has ordered the removal from his Mega file-storage service design plans for a controversial one-bullet plastic gun.

Survey: Risk to organisational data an ongoing cloud security concern

By T.C. Seow | 10 May, 2013 21:38

While companies have become more comfortable with the security of third-party cloud service providers, data security--particularly at the end user level--as well as concerns over meeting compliance requirements, remain top-of-mind among cloud adopters. This is the conclusion of a cloud security survey commissioned by NetIQ.

MasterCard helps rolls out national ID cards in Nigeria

By Olusegun Abolaji Ogundeji | 10 May, 2013 21:34

The Nigerian National Identity Management Commission (NIMC) and MasterCard are teaming up to roll out 13 million multipurpose national identity smart cards.

BYOD policy: Employee right to social media privacy is paramount

By Tom Kaneshige | 10 May, 2013 20:33

BYOD guidelines are just being defined, but one warning must rise above the din: never, ever, try to gain unauthorized access to an employee's private social networking site.

What's old is new again: Spammers revived old schemes in March quarter

By John P. Mello Jr. | 10 May, 2013 17:42

Volumes remain steady as junkmeisters return to old spam scams

Space station springs a leak; NASA preps spacewalk to fix it

By Sharon Gaudin | 10 May, 2013 17:13

Astronauts on board the International Space Station are preparing for a possible spacewalk tomorrow to repair an ammonia leak.

Academic institutions urged to take steps to prevent DNS amplification attacks

By Lucian Constantin | 10 May, 2013 16:42

Colleges and universities are being encouraged to scrutinize their systems to keep them from being hijacked in DDoS (distributed denial-of-service) attacks.

Gang arrested for £500,000 'Rolex rampage' using pwned Amex Black card

By John E Dunn | 10 May, 2013 13:33

Five men have been arrested by British police after allegedly going on an extravagant £500,000 ($775,000) spending spree using a compromised American Express Black card.

Google's five-year plan for authentication: It's complicated

By Antone Gonsalves | 10 May, 2013 13:33

Some of the technology has to be deployed together for maximum security, making the process complicated, said one security expert

Bill would put mobile app vendors on the hook for privacy

By Jaikumar Vijayan | 10 May, 2013 10:12

The mobile industry's efforts to convince lawmakers that self-regulation alone is the best way to address growing concerns over privacy-invading mobile applications appears to be running into some headwind.

Malware authors’ hard-fought “professionalism” impressive, frightening: researcher

By David Braue | 10 May, 2013 09:50

Malware authors have become so good at seeding exploits en masse that their monitoring, customer service, marketing and Australian localisation strategies have come to resemble professional business operations, a senior Trend Micro security researcher has observed.

iiNet’s Web analytics delivers real-time security bonus

By David Braue | 10 May, 2013 09:40

A Website analytics tool, originally implemented by Internet service provider iiNet to gauge customer reaction to changes to its online applications, has delivered an unexpected bonus by allowing the company’s technical staff to detect and monitor hacking attempts in real time.

With viruses passé and money involved, malware’s just no fun anymore: Genes

By David Braue | 10 May, 2013 09:31

The idea of computer viruses persists in the popular memory but actually died a decade ago as commercially driven exploits increasingly pushed companies onto the back foot, Trend Micro chief technology officer Raimund Genes argued during a review of the evolution of malware over the past two decades.

IT grads ambitious, but lack the security skills companies need: panel

By David Braue | 10 May, 2013 09:25

Growing demand for IT security skills may have some CSOs worried about finding enough staff, yet some security executives believe the problem isn’t only with the universities – but with ambitious IT graduates that expect senior positions without first doing the hard work to deepen their knowledge.

Payment card processors hacked in $45 million fraud

By Jeremy Kirk | 10 May, 2013 02:28

A vast debit card fraud scheme that allegedly netted $US45 million has been linked to the hacking of credit card processors in the US and India.

The Onion explains how its Twitter account was hacked

By Jeremy Kirk | 10 May, 2013 01:19

Hackers who commandeered The Onion's Twitter account used simple but effective phishing attacks to obtain passwords, according to a writeup by the publisher's technology team.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Authentication

RSA offers a wide range of strong two-factor authentication solutions to help organizations assure user identities and meet compliance requirements.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.