Infosecurity News

'Operation Hackerazzi' – No, it's not a new Lady Gaga song
The FBI has arrested a Florida man in an email hacking probe, codenamed "Operation Hackerazzi", that involved disclosure of personal information and photos of Hollywood celebrities, including Mila Kunis, Christina Aguilera, and Scarlett Johansson.

ATM skimmer spotted, powered by mini-MP3 player
The ingenuity of cybercriminals has reached a new level, with a leading IT security researcher reporting on the re-tasking of a mini-MP3 player as the mainstay of an ATM skimmer.

Fake Android Netflix app hoovering up user credentials
It appears that hackers are taking advantage of the interest in Netflix – the California-based IP streaming firm that offers services on specific smartphones in North and South America – by releasing a general Android edition of the software that runs – or so it claims – on any Android-powered smartphone or tablet computer.

Infosecurity writers take home more hardware
Continuing our own brand of a ‘commitment to excellence’, Infosecurity writers took home two awards at this year’s BT Information Security Journalism Awards in London.
Ministry of Defence drops another Adobe PDF blunder; reveals radar defense secrets
The UK's Ministry of Defence has once again demonstrated its lack of understanding of how Adobe PDF format files function as, according the Daily Star tabloid newspaper, anyone with a simple knowledge of page formatting can 'unblack' apparently censored data from a release on radar defense issues on its website.
ATM industry association issues anti-reverse engineering recommendations
The ATM industry association – the ATMIA – has published a best practice manual on cash machine security. And a new feature of its recommendations is for developers to help prevent reverse engineering of cash machine software.
Security researcher claims ID theft now more profitable than car theft
A leading IT security researcher claims that hackers are now electronically breaking into US car dealerships – not to steal cars, but the IDs and other credentials of car purchasers, most of whom buy on finance.
Low-cost kit for sale on eBay could hand national infrastructure secrets to terrorists
Reports that air traffic control data has been found on network kits sold on eBay comes as no surprise, says Philip Lieberman, president of Lieberman Software.
Chaos Computer Club warns on “German government” communications trojan
Rumors of a series of German government-developed spyware trojans have been bouncing around for several years, but now the Chaos Computer Club (CCC) claims to spotted one in the wild.
ISACA publishes COBIT process assessment model
Now into its 15th year, the COBIT 5 framework is in the final stages of ratification by ISACA and, as part of this evolution of the GRC (governance, risk and compliance) framework, the association has issued a new process assessment model.
Context discovers reverse web proxy security loophole; advises on remediation
Context Information Security has warned of a back door threat to the Apache platform that could allow unauthorized access to internal or DMZ systems.
Stanford Hospital faces $20 million lawsuit over patient data breach
A class-action lawsuit for $20 million has been filed against Stanford Hospital & Clinics over a patient data breach in which personal information on 20,000 emergency room patients was posted on a public website for a year.
Check Point introduces blades to tackle botnets
Check Point has taken the wraps off its 33rd software blade technology, which is an anti-botnet platform designed to counter the problems of botnets and advanced persistent threats (APTs).
£30 graphics card can brute-force crack any eight character password in just four hours
A £30 graphics card can now process as many as 158 million passwords a second
Plusnet migrates anti-spam systems to Cloudmark
Plusnet, the Sheffield-based ISP, has announced it is migrating its several million customers from their existing IronPort based anti-spam / anti-virus email security platform and over to a new solution provided by Cloudmark.
Weather report: Cloudy, with a chance of data leakage
Almost half of organizations said their IT staffs are not ready to adopt the cloud, with data security cited as a top concern, according to survey sponsored by Symantec.
Betfair security chief leaves in wake of data breach publicity
Hard on the heels of reports that data on Betfair's 3m-plus customer base had been hacked by cybercriminals in the Far East, reports are now saying that the the betting exchange's security chief has left the company.
Vodafone New Zealand's international net access hit by DDoS attack
The interconnected nature of the global internet was highlighted earlier this week when a DDoS attack on a Californian company also downed Vodafone New Zealand's international web access.
Earl Eugene Schultz: 10 September 1946 – 2 October 2011
It it with deep regret that Infosecurity has to report that Eugene Schultz – arguably one of the founding figures of the IT security industry – passed away on Sunday after a short illness.
McAfee joins SIEM buying spree by snapping up NitroSecurity
Another primarily SIEM firm is about to fall off the radar, as McAfee announced plans to purchase security information and event management (SIEM) provider NitroSecurity.



