Data Breaches

March 12, 2010, 10:40AM Threatpost Original

Andy Jaquith on Measuring Meaningful Information Security Metrics

The March issue of Information Security magazine is out this week. The cover story is a look at how security information management systems need to evolve, in particular by integrating identity management with SIM in order to tie policy violations to user activity. Also, expert Andrew Jaquith writes about how to measure meaningful information security metrics. Finally, editor Marcia Savage takes on the HITECH Act's impact on HIPAA and how health care organizations must up their security game. Download the issue here [PDF]

Shorten URL: http://threatpost.com/en_us/3Jy. Click to copy to clipboard or post to Twitter

March 12, 2010, 7:24AM

Another TJX Accomplice Gets Nearly 4-Year Sentence

Humza Zaman, a co-conspirator in the hack of TJX and other companies, was sentenced Thursday in Boston to 46 months in prison and fined $75,000 for his role in the conspiracy. The sentence matches what prosecutors were seeking. Read the full article. [Wired]

Shorten URL: http://threatpost.com/en_us/3JK. Click to copy to clipboard or post to Twitter

March 12, 2010, 6:34AM

ZeuS Botnet Module Gives Total PC Control

New capabilities are strengthening the ZeuS botnet, which criminals use to steal financial credentials and execute unauthorized transactions in online banking, automated clearing house (ACH) networks and payroll systems. The latest version of this cybercrime toolkit offers a $10,000 module that can let attackers completely take control of a compromised PC. Read the full article. [Network World]

Shorten URL: http://threatpost.com/en_us/3JT. Click to copy to clipboard or post to Twitter

March 11, 2010, 12:43PM

VA Investigating Security Breach of Veterans' Medical Data

The Veteran Affairs Department's inspector general has launched a criminal investigation into a physician assistant's alleged downloading of veterans' clinical data at its Atlanta medical center.

The assistant allegedly recorded two sets of patient data on to a personal laptop for research purposes. One set included three years' worth of patient data and another held 18 years of medical information.  Read the full story [nextgov]

Shorten URL: http://threatpost.com/en_us/3uE. Click to copy to clipboard or post to Twitter

March 11, 2010, 11:41AM

Taher Elgamal on Encryption, SSL, The Cloud

In this wide ranging interview, cryptographer, Taher Elgamal, chief security officer of Axway Inc. and  initial driving force behind SSL, explains how applications may be better adapted to defend against attacks and how cloud computing may alter data protection and authentication. Read the full article. [TechTarget]

Shorten URL: http://threatpost.com/en_us/3uU. Click to copy to clipboard or post to Twitter

March 11, 2010, 11:25AM

Win Update Scareware Pushes Drive-By Downloads

Cybercriminals are using a fake Windows Update installation dialogue box to sell a bogus security product called Anti-malware Defender, security researchers have warned. Read the full article. [Computer Weekly]

Shorten URL: http://threatpost.com/en_us/3un. Click to copy to clipboard or post to Twitter

March 10, 2010, 6:31PM Threatpost Original

Exploit Code Published for Latest IE Zero-Day

Using obvious clues from a McAfee blog post, an Israeli hacker was able to pinpoint the latest Internet Explorer zero-day vulnerability and create working exploit code.

The exploit code, which provides a clear roadmap to launch drive-by download attacks against IE 6 and IE 7 users, is being fitted into the Metasploit point-and-click tool.

Shorten URL: http://threatpost.com/en_us/3zA. Click to copy to clipboard or post to Twitter

March 10, 2010, 11:52AM

E-Mail Security Questions Easily Answered

A Cambridge University study has shown how easy it is to guess the answer to common questions, such as someone's mother's maiden name. It found attackers will be able to break into 1 in 80 accounts if they get three chances to guess answers. Read the full article. [BBC]

Shorten URL: http://threatpost.com/en_us/3z9. Click to copy to clipboard or post to Twitter

March 10, 2010, 10:38AM

Monoprice.com Goes Offline, Investigates Fraud

Audio visual cabling giant monoprice.com shut down its Web site – possibly for the next couple of weeks – while it investigates the possible compromise of its customer credit and debit card information. Read the full article. [KrebsonSecurity]

Shorten URL: http://threatpost.com/en_us/3zZ. Click to copy to clipboard or post to Twitter

March 9, 2010, 4:03PM

LifeLock Settles with FTC for $11 Million

LifeLock, an Arizona company promising customers protection from identity theft, has agreed to pay $12 million to settle charges that the company overstated its benefits and used "scare tactics" to gain subscribers. Read the full article. [Computerworld]

Shorten URL: http://threatpost.com/en_us/3td. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy