Fahmida Y. Rashid

Lockheed Martin Shuts Down Remote Network Access After Detecting Intrusion

Lockheed Martin has been battling a “major disruption” to its computer systems after its IT security team detected a network intrusion earlier this week, Reuters reported. The disruption began May 22 when the company detected an intrusion to the network, according to the May 26 Reuters story, which cited technology blogger Robert Cringley. Cringley claimed […]

Congress Considers Government Role in Securing Critical Infrastructure

Security experts and public officials testified at a congressional subcommittee hearing about the role the federal government should play in defending cyberspace and protecting critical infrastructure from attackers. There are more kinds of malware and online threats, and cyber-criminals are becoming more sophisticated, industry experts told congressional lawmakers at the May 25 hearing by the […]

iPhone 4 Encryption Remains Uncracked, but Password Keys Easy to Obtain

Russian security firm ElcomSoft claims to have cracked the AES-256 encryption Apple used to encrypt data on user iPhones. Despite the claim of the company’s CEO, that’s not quite the case. The publicly available ElcomSoft Phone Password Breaker application provides users with the ability to view encrypted data extracted from mobile devices running Apple iOS […]

Damballa CSP Automates Botnet Identification, Removal for ISPs

Damballa updated its cyber-threat monitoring service for internet service providers and telecommunications providers. The appliances detect malware infections affecting any device on the CSP (Communications Service Providers’) networks, including PCs, Macs, tablets and smartphones. Damballa CSP 1.6 passively monitors a carrier’s network activity to identify malicious traffic, the company said May 26. Because it works […]

Prompt Notification: What Sony Didn’t Do

Prompt Notification: What Sony Didn’t Do Companies should disclose the breach swiftly if names and identifying information such as Social Security numbers and passwords are exposed. Disclose What Exactly Was Stolen Customers should be notified to what extent their personal and financial information has been compromised so that they can figure out their risk (phishing, […]

Attachmate Splits Novell Acquisition into NetIQ, SUSE Divisions

Attachmate closed the $2.2 billion Novell acquisition four weeks ago and split up the various Novell products across multiple business units: Novell, SUSE, NetIQ and Attachmate. Each division will be independent with its own go-to-market strategy and will have its own organization structures, Attachmate announced on May 18. Novell’s SUSE Linux will be its own […]

HIPAA, HITECH Compliance Not Improving Health Care Data Security: Survey

Being regulatory-compliant does not necessarily reduce the chances of a data breach, at least for the health care industry, according to a new study. Even more worrisome, organizations appear to be focusing more on compliance and less on security. About 56 percent of IT security professionals in the health care industry said they spend the […]

Sony Ericsson Latest Victim of SQL Injection Attack

In what is becoming a regular occurrence, Sony has shut down another service after another attack. This time, the vulnerability was in the Canadian e-commerce site for Sony Ericsson. More than 2,000 customers have had their personal data stolen from the e-commerce store, including e-mail addresses, passwords, and telephone numbers, Sony told the BBC on […]

Microsoft Patches XSS Flaw in Hotmail

Microsoft patched a cross-site scripting flaw on its Hotmail service that was being exploited by cyber-criminals to read and steal e-mail messages. The flaw allowed the cyber-criminals to target victims with specially crafted phishing e-mails after reading their e-mails, according to Trend Micro researchers. The researchers reported the cross-site scripting issue to Microsoft on May […]

Sony’s PlayStation Network, Qriocity, Sony Online Entertainment

Sony’s PlayStation Network, Qriocity, Sony Online Entertainment Date Reported: April 26Size: 101 million user accountsType of Data: name, home and e-mail addresses, login credentials, some credit card information Sonys three cloud services for PlayStation games, music and video, and online gaming were compromised by attackers while the company was distracted by a distributed denial of […]