Infosecurity News
South Carolina county takes nine month to notify thousands of data breach victims
Officials with York County, South Carolina, took nine months to notify close to 17,000 job applicants and vendors that their social security numbers were exposed by an intrusion into a web application server.
Mozilla’s objection to IE-only Windows on ARM: a major row in the making
Windows is not Apple’s iOS, says Mozilla's top lawyer after the organization complained that Firefox and other browsers would be excluded from Windows RT running on ARM systems.
BeyondTrust acquires vulnerability management company eEye Digital Security
BeyondTrust, a company that provides privilege delegation and authorization systems with its PowerBroker suite of products, has acquired eEye Digital Security, developer of the Blink and Retina vulnerability management tools.

Drowning in data: Security professionals look to metrics for a lifeline
Security professionals are experiencing an information overload and want better metrics to analyze the data so they can take action, according to a survey conducted by Dimensional Research on behalf of RedSeal Networks.

K-State receives Air Force contract to examine network "moving target" defense
Kansas State University (KSU) has received a five-year, $1 million US Air Force (USAF) contract to study "moving target" defense for networks.
DigiNinja analyzes the Twitter hack, and offers password advice to web services
Yesterday we reported that 55,000 Twitter accounts have been leaked on Pastebin. Security researchers Anders Nilsson and Robin Wood have separately analyzed the dump.
Net neutrality becomes law in The Netherlands
The net neutrality provisions approved by the Dutch Parliament last June as part of its implementation of the European telecommunications package became law yesterday.

Natural gas pipelines targeted by cyber attack
A spear-phishing campaign aimed at US natural gas pipeline companies has been underway since December of last year, according to the US Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).
Syrian activists targeted with RATs
There have been several recent examples of Syrian activists being tricked into downloading and installing remote access tools (RATs) that secretly hand control of their computers to a third party.

Encryption passwords exposed by Apple's Lion OS X update
Apple exposed encryption passwords of FileVault users in its Lion OS X 10.7 security update, says researcher.
South African ISPs team with Australian colleagues on cybersecurity code
South Africa’s Internet Service Providers’ Association (ISPA) has teamed with Australia’s Internet Industry Association to develop a new voluntary industry code of practice to improve cybersecurity for end users.

PandaLabs malware report – and the balance between law enforcement and user
Almost one-in-four computers in the UK is infected – and the UK is one of the least infected countries in the world, says the new PandaLabs report released today.

Federal prosecutors charge Irish, British suspects in Stratfor breach
US federal prosecutors in Manhattan have charged four Irish and British men for helping with the breach of the US security analysis firm Stratfor last year.

MoD admits hackers have breached top secret systems
Hackers have breached some of the top secret UK Ministry of Defence computer systems, the military's head of cybersecurity has revealed.

OpBayBack announced by Anonymous look-alike: TheWikiBoat
It was only a matter of time before one hacktivist group or another would react to the UK court-ordered ISP block on The Pirate Bay.

The UK Protection of Freedoms Bill this week; telecommunications surveillance next week?
A major plank of both the Conservative and LibDem election campaigns was to ‘roll back the database state’ and curtail invasive bureaucratic surveillance. But has the Coalition achieved this? And what about the proposed communications monitoring bill?
LOIC DDoS tool – is it 'safe' for the user?
The DDoS weapon of choice for Anonymous activists, the Low Orbit Ion Canon (LOIC), was downloaded from the internet 381,961 times during 2011. That number has already been exceeded in 2012, with daily downloads averaging more than 3400.

Security firm finds dodgy Android apps that offer "free" stuff to get information
GFI Software researchers have identified 20 Android applications on the Google Play marketplace that lure users with offers of “free” products or money to fill out surveys.

New NIST protocol enables secure biometric data access
The US National Institute of Standards and Technology (NIST) has published a new protocol for securely communicating with biometric sensors over wired and wireless networks using web services.
SOCA knocked off the web by DDoS – again
The UK’s Serious Organised Crime Agency has today confirmed that a DDoS attack forced it take its website off-line at 22:00 Wednesday. As of writing, 14:30 Thursday, it is still down.



