RSA, Sony Breach News, Wireless Outages Lead Week’s Security News

Published: Oct 16, 2011
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The week was marked by several service outages. BlackBerry users in Europe, Asia and North America were unable to check their messages over the week as Research In Motion worked to bring all its servers online.

RIM claimed it was aware of the problem and was working to resolve it, but didn’t explain what was going on, leading many to wonder if the company was under attack. RIM explained later it was a problem with its network infrastructure, but it came under fire for not communicating the problems better.

No one thought Apple was under attack, but it was also plagued with unavailable servers and sluggish traffic. The company launched iCloud last week and released massiveupdates to Mac OS X, iOS and iTunes in order to allow users to upgrade their devices to access the new service.

The week began withRSA Security executives disclosing more details about the attack that compromised the EMC subsidiary’s networks earlier this year and resulted in thieves stealing information related to the SecurID two-factor authentication technology. RSA said the attacks had been traced back to two separate groups who had not been known to work together in the past and that the evidence points strongly at some kind of nation-state involvement. RSA did not mention the suspect country by name.

Speaking of companies who had been breached earlier in the year, Sony was back in the news last week. This time, attackers had obtained a list of email addresses and passwords from a different source and had launched a mass log-in attack to try to accessSony services, including the PlayStation Network and Sony Online Entertainment.

Sony locked out approximately 93,000 users because the attackers succeeded logging in to those accounts, but the company pointed out that the attack succeeded on only a small fraction of users. Sony reminded users to not reuse passwords across sites and encouraged all users to select strong passwords for their accounts.

As Congress continues to debate and negotiate the details for what needs to go in the cyber-security bill, the Securities and Exchange Commission took action, issuing a guidance recommending that public companies disclose all cyber-risks and incidents that may have material impact on the organization’s operations or financial results. Since the guidance doesn’t carry any enforcement power, there’s no way for the SEC to enforce it, but it is still a first step because it will encourage organizations to reveal information that investors should know about.

On the same day that Microsoft issued a sizablePatch Tuesday release for October, it released its latestSecurity Intelligence Report. SIR volume 11 identified some of the ways Web services and organizations are being compromised, and found that less than 1 percent were the result of a zero-day vulnerability.

Advertisement

Even so, Microsoft Trustworthy Computing researchers did not dismiss the seriousness of zero-days. The goal of the study was to point out that IT departments should not ignore zero-days, but not worry about it to the extent of skipping all the other security measures that would detect and block the 99 percent of more common attacks.

TheUnited States Air Force finally issued a statement after the recent news about a mysterious keylogger that had allegedly infected the systems that control its fleet of unmanned surveillance and attack aircraft. It turned out it wasn’t a keylogger, but “credential stealing” malware. It’s a little unclear exactly what that means, since keyloggers are often used to steal credentials.

It’s possible that the malware intercepts credentials saved in a file or a cookie instead of actually intercepting the keystrokes, Belkin’s Cliff Unger told eWEEK. Either way, the Air Force tried to downplay the whole infection, calling it a “nuisance” rather than a serious threat and saying it infected an isolated system and had no access to confidential data. Unger noted that it was still a matter of concern that a siloed system got infected in the first place.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。