Infosecurity News
Commuter matching website highly vulnerable to SQL injections
RideMatch.info, a website used by several California-based companies and transportation boards to match commuters on similar routes, has been found to be potentially vulnerable to massive SQL injections that could result in the disclosure of users' personal data.
Apple under fire over anti-phishing feature
Apple has come in for criticism on user forums for a new anti-fraud and anti-phishing warning system seen in its Safari Mobile web browser for the iPhone. Forum users report that the feature - seen in v3.1 of the iPhone's operating system - is less than consistent.
Gemalto acquires Trusted Logic
Gemalto, the French digital security firm, has acquired Trusted Logic, a provider of security software for mobile devices.
Quocirca publishes report on strong authentication
Fran Howarth, a principal analyst with Quocirca, the business and IT analysis research firm, has penned a report on strong authentication.
One third of businesses failing to protect sensitive data transfers
Research just released by Computerlinks, a UK distributor of IT security and internet technology products, shows that a sizeable number of businesses are failing to protect their most sensitive data.
UFO hacker Gary McKinnon to learn of Supreme Court appeal
Self-confessed hacker Gary McKinnon, who gained unauthorised access to multiple Pentagon computer systems, will learn this week whether an application for an appeal in his case will be heard by the Supreme Court, the new highest court in the UK.
Only one week left: Virtual Conference on Information Security 2009
Infosecurity Magazine’s Virtual Conference on Information Security 2009 is only a week away – sign up now!

Fake anti-virus team exploits September 11 anniversary
Online scams related to holidays, global events, and popular news stories are common, but September 11 scammers really scraped the bottom of the moral barrel last week. Scareware scammers are using the eighth anniversary of the September 11 attacks to sell their fake anti-virus software to unsuspecting users.
Low-cost security tag for mobile phones
An Edinburgh-based company has developed a relatively low-cost security tag that alerts users when a linked mobile phone moves more than 25 metres away. The Bluetooth-enabled keyring tab - known as Nio - comes with its own USB-rechargeable battery and sells for around £40.
Wigan council lost personal data on children and teenagers
Wigan Council has been been forced to sign an undertaking with the Information Commissioner's Office (ICO) following the theft of a laptop, which resulted into the personal data on around 43 000 children and teenagers being potentially open to abuse.
Security software spending up 4% in 2010
Security software budgets are expected to grow 4% in 2010, and security services budgets could grow almost 3%, according to Gartner.
Home Gateway broadband and networking hub reaches fruition
After four years in gestation, the Home Gateway (HG) - an intelligent broadband/networking interface device designed to act as a hub for homes and small offices - is reaching fruition.
Barclays fined £2.45m after IT errors
Barclays' investment arm has been fined £2.45m by the Financial Services Authority (FSA) for failing to report its investment details correctly.
Card spending research reveals UK electronic fraud hotspots
Research by the 3rd Man, an electronic fraud and security specialist, has uncovered some interesting statistics about cardholder-not-present transactions, as well as fraudulent mail order plus online card purchases in the UK.
Delphi programming tool hit by virus
A ‘proof of concept’ virus called Win32/Induc.A is causing problems for programmers – including malware writers, according to this month’s ESET ThreatSense Report.
O2 and Plusnet respond to potential XSS modem security issues
O2 - as well as BT subsidiary internet service provider Plusnet - have both responded to a potential XSS security flaw identified in the Thomson TG565 and TG565n wireless broadband routers they issue to their internet users.
Bloxx warns on anonymous proxies
Bloxx, a web filtering firm, has issued a warning that anonymous proxies - which are now being used by students to bypass campus blocks on inappropriate content - pose a serious information security threat to young people.
Cross-site scripting (XSS) security problem hits broadband routers
The problem of cross-site scripting (XSS) security flaws - which have affected hundreds of websites this year - has spread to broadband routers, as a security researcher claims that the Thomson wireless box III supplied by O2 leaves internet users "wide open" to the issue.
Toll-free PBX hack highlights need for code auditing
Reports that a North Carolina business has been left with a US$2500 phone bill after phone phreakers hacked its PBX via the firm's toll-free number shows the danger of failing to audit all aspects of a systems' software, said Fortify, the application vulnerability specialist.
Learn about how to keep security and IT ready for a pandemic
With the recent scares about the swine flu, more and more businesses feel the need to plan for a pandemic, but are their security and IT up to the challenge?



