Infosecurity News

Mozilla plugs eight holes with latest version of its Firefox browser
Mozilla has fixed eight vulnerabilities, a majority of them “critical”, with the release of the latest version of its web browser, Firefox 11.
Quis custodiet ipsos custodes – Who watches the watchmen?
The Dutch Big Brother Awards for 2011 have been announced. There are three prize categories: People, Companies and Government.

HHS fines Blue Cross of Tennessee for theft of 57 hard drives
The US Department of Health and Human Services (HHS) is fining Blue Cross Blue Shield of Tennessee $1.5 million related to the 2009 theft of 57 unencrypted computer hard drives containing protected health information on over one million patients.
Performance comparison between Bit9, Symantec and McAfee
The Tolly Group has published a new report: 'Comparison of Bit9 Advanced Threat Solution versus McAfee Endpoint Protection Suite and Symantec Endpoint Protection 12.1'. But are they apples and oranges?
New Zealand breach affects 9,000 insurance claims
New Zealand’s Accident Compensation Corporation (ACC), which provides personal injury insurance to New Zealand residents, admitted that a spreadsheet containing 9,000 claims with personal details on 6,000 individuals was inadvertently sent to a client.
SafeNet acquires Cryptocard
SafeNet buys Cryptocard to offer the best of both worlds (local and cloud) in user authentication.
Framesniffing with Chrome, Safari and Internet Explorer
Security consultancy Context has produced an analysis of framesniffing, an attack technique that can data mine sensitive data through web browsers and iFrames.
DHS improves classified information sharing with state and local police
The US Department of Homeland (DHS) has strengthened the sharing of federal classified information with state, local, tribal, and private sector partners.

China suspected in Facebook attack using bogus NATO commander account
China is suspected of being behind social engineering attacks using a bogus Facebook account of the NATO commander to steal secrets from colleagues, friends, and family.
The return of Kelihos
Recent reports on the return of the Kelihos demonstrate the difficulty in keeping a good bot down.

Telecom execs warn Congress about excessive regulation in cyber bills
US telecom executives came out strongly against government regulation of cybersecurity in the private sector during a House hearing this week.

Vupen strikes again: French team cracks IE 9 in Pwn2Own hack contest
A team from the French security firm Vupen has cracked a second browser during the Pwn2Own hacking contest at CanSecWest – Internet Explorer 9 – after compromising Chrome on the first day of the competition.
SFIA Foundation maps ISACA certifications to IT skills framework
The Skills Framework for the Information Age (SFIA) Foundation has recognized two ISACA information security certifications as part of its IT skills framework.

McGill shuts down website that published confidential donor data
Canada’s McGill University has shut down a website that published confidential data on school donors, including names, addresses, phone numbers, and the amount they donated.
Rogue anti-virus up and Kelihos botnet is back
GFI Software’s report for February highlights two main issues: the incidence of rogue anti-virus is continuing to increase; and the Kelihos botnet ‘taken down’ last year is resurgent.
Today's #FFF hack by Anonymous is a police equipment store
Anonymous has vowed to do a hack every Friday, calling it the #FFF campaign. Today AntiSec defaced the New York Ironworks, a police equipment supplier that describes itself as ‘NYC's finest police equipment & tactical op’s gear store.’

Kaspersky perplexed by Duqu code
Kaspersky Lab researcher Igor Soumenkov is asking for help in identifying a mystery code in the Duqu virus, the follow-on to Stuxnet uncovered last year.

Heat wave: US administration tries to 'simulate' support for Senate cybersecurity bill
The Obama administration on Wednesday simulated a cyber attack on the New York City power grid during a summer heat wave in an effort to convince US senators to pass comprehensive cybersecurity legislation.
CPA may help local authorities reduce data loss
Becrypt’s DISK Protect full-disk encryption product is the first commercial product to be granted CPA certification. By encrypting local authority laptops, it may help prevent the continuous leakage of personal data.
Trustwave to acquire M86 Security
Trustwave, a Chicago-based security company with offices around the world, has signed a definitive agreement to acquire M86 Security, which is based in Irvine California and has international headquarters in London and R&D in California, Israel and New Zealand.



