Infosecurity News
CSO role expands to include organization-wide risk management
That information security is really an aspect of organizational risk management is well known in theory, but is now being mirrored in practice. New research demonstrates that CSOs are increasingly adopting a risk-based rather than tick-box approach to security.
France, Skype go tête-à-tête over lawful intercept
Skype is running into a contretemps, as it were, with the French telecom authority over lawful intercept regulations, with some executives possibly facing criminal charges for non-compliance.
Amid banking DDoS attacks, Obama convenes cybersecurity meeting with CEOs
President Barack Obama is shining yet another light on the rising cybersecurity threat in the US, sitting down with more than a dozen CEOs inside the White House Situation Room to discuss how government and the private sector can work together to better protect the nation’s citizens and critical infrastructure.
Celebrities, politicians lose privacy in doxxing attack
A range of political and celebrity targets have been made victims of a cyber-attack known as “doxxing”, by perpetrators using a Russian website.
Australia's central bank admits it was hacked
The Reserve Bank of Australia has admitted that its been an ongoing target for hackers, although the nation's central bank says no data has been lost as a result of the attacks.
VISA sued over PCI fines levied on retail company
In what is believed to be an industry first, Tennessee-based footwear and sports apparel retail chain Genesco is suing Visa over a $13 million dollar fine imposed following a data breach in 2010.
Another Honeywell ICS vulnerability rears its head in building control
A new vulnerability, CVE-2013-0108, has been discovered in Honeywell industrial control systems (ICS), continuing the growing trend of SCADA and building control issues.
Spam back with a vengeance in February
After a fourth quarter of declining spam levels in 2012, junk emails actually almost doubled in February 2013.
Lack of privacy is not that bad, says Univ. of Chicago – you haven’t got it anyway, says Cambridge
Against a background of the EU likely to water down its privacy proposals, and Harvard university secretly searching the emails of 16 resident deans, two major universities have published two very different papers on privacy in the internet age.
Tripwire acquires nCircle
Tripwire, a Portland Ore security and compliance company, has announced a definitive agreement to acquire nCircle, a San Francisco risk and security performance management company.
China’s next-generation internet is streets ahead of the West
So says an article in the latest issue of New Scientist, commenting on a report published in the Proceedings of the Royal Society last week. The key, apparently, is China’s implementation of Source Address Validation Architecture (SAVA).
Malware developers paying $100 apiece for Google Play accounts
Dovetailing with the ever-escalating glut of Android-based mobile malware, it turns out that a black market for Android developer accounts has sprung up. Google Play accounts are apparently going for $100 a pop in the cyber-underground.
LinkedIn's $5M class-action data breach lawsuit dismissed
A $5 million class-action suit brought against networking site LinkedIn concerning a significant June 2012 data breach has been dismissed after a US District Court judge ruled the breach as “abstract” rather than resulting in actual harm.
March 2013 Patch Tuesday preview
This month’s Patch Tuesday will include seven security bulletins from Microsoft: four are critical and three are important; three require reboots, three may require a reboot, and one does not. Both businesses and consumers will likely be affected.
DARPA says goodbye to hacker-friendly Cyber Fast Track program
The Department of Defense is pulling the plug on Cyber Fast Track, a program aimed at tapping reformed hackers and other security hotshots to solve cyber-defense problems quickly.
Android malware blossoms as PC attacks fade
If there were any doubt that Android malware is becoming an epidemic, look no further than a study showing that the number of new malware programs for the mobile operating system has increased five-fold since the first half of 2012. PC threats, meanwhile, are waning.
RSA 2013: White Hats Need to Play a More Intelligent Game
The information security community must stop giving away the roadmap to its defense, said Art Gilliland, HP, at the RSA conference in San Francisco, February 28 2013.
Phase 3 of the Op Ababil DDoS attacks on US banks commences
al-Qassam Cyber Fighters announced the resumption on Tuesday. By Wednesday, customers of PNC Bank, Wells Fargo, Citibank, Bank of America and a number of other major banks were reporting difficulties to the sitedown.co website.
Raspberry Pi got DDoS’d
Starting late on Tuesday the Raspberry Pi Foundation was taken down by a massive SYN flood attack. The Foundation is behind the credit card-sized Raspberry Pi computer, originally designed to promote the teaching of computer basics in schools.
New botnet found in Latin America
A new botnet, AlbaBotnet, has been discovered in Latin America. It appears to be still in development and has not yet been used in anger. Currently it is designed to target two specific banks in Chile.