As more companies turn to the cloud to provide redundancy and back-up services for mission-critical business functions, connectivity and applications, new research has revealed that a full 70% of cloud backup providers do not inform customers of where the data is being physically kept.
Ever since Defense Secretary Leon Panetta’s claim that the US was facing a digital Pearl Harbor, a growing number of security experts have begun to question the reality of such threats.
ExploitShield has been marketed as offering protection “against all known and unknown 0-day day vulnerability exploits, protecting users where traditional anti-virus and security products fail.” I found this assertion quite extraordinary and exciting! Vulnerabilities in software applications are rea...
One day after Research in Motion’s share price tumbled after damning comments from an analyst, the company announced that it has received FIPS 140-2 security certification allowing the BB10 to be deployed by government agencies.
Call it malicious software on a hill: a new version of Citadel, the crimeware kit, has emerged to inspire hackers everywhere. That is, if they can infiltrate the Russian underground far enough to locate it and pay the $3,000 entry fee.
Y-a-t’il eu des cyber-attaques sur des infrastructures critiques depuis Stuxnet ? Je parle d’attaques capable de détruire des équipements, causer des accidents industriels, voire tuer des gens… par opposition au « simple » vol ou corruption de données.
Oui, si on en [...] Lire la suite
CESG (Communications-Electronics Security Group) and CPNI (Centre for Protection of National Infrastructure), being arms of GCHQ (Government Communications Headquarters) have today launched a new UK Cyber Incident Response Scheme.
Details are emerging of a major hack of Coca-Cola by Chinese criminals in 2009, where internal emails and documents were stolen, and malware compromised access to all Microsoft Windows servers, work stations and laptops on the network .
Pourquoi pas d’article sur les assises 2012 ? (et donc en fait si, cet article court !)
Paradoxalement, alors que la cybersécurité industrielle est un sujet en plein « boum », ce n’était pas au programme des assises – ou plutôt si, [...] Lire la suite
Faced with an age of unprecedented growth and scope of cyberthreats, the Information Security Forum (ISF) has reached an agreement with the (ISC)² to provide its extensive research library for use in development of (ISC)² examinations and official education materials, significantly broadening the re...
In the wake of a massive security breach at the South Carolina tax collection agency, a former South Carolina state senator has expanded a class-action lawsuit over the exposure of millions of state tax returns to include those responsible for providing security: Trustwave and the Division of State...
Lumension announced yesterday that it has completed the acquisition of CoreTrace IP, suggesting that it was prompted by growing concerns over APTs and increasing interest in whitelist defenses.
New malware, backdoor.ADDNEW, has been identified. It is based on the Russian DaRK DDoSer malware and has a surprising link with the Gh0st RAT trojan.
NullCrew remembered the 5th of November by breaking into mod.co.uk and stealing and dumping more than 3400 email addresses and passwords. While the date of the breach cannot be verified, it does look as if it happened on the Guy Fawkes anniversary.
Public sector organizations in the UK are leaking money thanks to a full £2 million in fines that councils, the NHS, police forces and others have seen in response to poor data handling.
Apple has released a new iOS, version 6.0.2, that addresses a handful of vulnerabilities in the system affecting iPhone 3GS and later, the iPod touch fourth generation and later, and the iPad 2 and later devices.
Announcing its Project Hellfire back in August, hacking group Team GhostShell warned, “Two more projects are still scheduled for this fall and winter. It's only the beginning.” Now it introduces Project BlackStar with an initial leak of 2.5 million records stolen from Russian organizations.
Security professional organization ASIS International has released a new edition of its Protection of Assets (POA) reference series, to dovetail with its 35h certification program anniversary and a stepped-up focus on global collaboration.
In a testament to the ever-changing nature of state-sponsored cyber-espionage, the governmental Computer Emergency Response Team (CERT) of the Republic of Georgia has published a breakdown of the so-called “Georbot Botnet,” a campaign carried out against the Georgian government using malware that in...
The Electronic Frontier Foundation (EFF) has warned about US government claims that a Megaupload user lost his property rights by using cloud storage has implications for all data stored by any user or company with any cloud provider, including Amazon’s S3, Google Apps or Apple iCloud.