Share

Related Links

Related Stories

  • Infosecurity Weekly Brief - March 16 2009
    Palin, patches and Mac hack. This week in brief.
  • Microsoft Admits Excel Zero-Day Flaw
    Microsoft has warned customers about a zero-day flaw in Excel that could allow for remote code execution if specially-crafted files are opened in the spreadsheet program.
  • Microsoft patches critical Internet Explorer flaw
    Microsoft has posted an emergency security patch for Internet Explorer after a critical zero-day flaw was discovered in the browser. Users have been advised to download the patch via Windows Automated Updated.
  • Congress concerns over China cyberwarefare program
    A Congressional Panel of six Democrats and six Republicans has concluded that China has developed a highly sophisticated cyberwarfare program and is ramping up its capacity to penetrate US computer networks.
  • The battle of the internet browsers
    Browsers are the hackers’ window into your PC – but how are they compromised, and what are vendors doing to harden them? Danny Bradbury examines the techniques vendors are employing, and why user education is one of the primary solutions for increased security

Top 5 Stories

News

Weekly Brief - May 26 2009

26 May 2009

Information security attacks, defenses, vulnerabilities, and losses

Attacks

Large swathes of the Chinese portion of the internet were taken offline by a massive DDoS attack. The US military is working on cyber-attack devices that could be used by non-experts to automatically hack a network. In the meantime, investigators in Europe used an old Nokia 1100 to demonstrate how a bank account could be hacked. They programmed the phone to receive other cellular users' text messages.

Defenses

Lawyers working for David Kernell, the hacker charged with hacking Sarah Palin's webmail account, said that he couldn't have violated her privacy because the judge had already declared the emails a matter of public record.

Adobe is following in Microsoft's footsteps (several years later) by starting a code hardening process and implementing regular security patches.

Vulnerabilities

A researcher posted details on how to exploit a security flaw in Apple's version of Java. The company has known about the security problem for six months but has been slow to patch it, he said. And Microsoft has found a zero-day vulnerability in IIS which could give attackers control over the server. Researchers at Cambridge University found that the majority of social networking sites fail to delete photos from their web servers after users removed them in a test.

Losses

An official at the Department of Homeland Security confirmed to FederalComputerWeek that a system containing sensitive information had been hacked. And there were red faces at the National Archives and Records Administration after a hard drive containing 1Tb of highly sensitive information from the Clinton administration was discovered missing. The drive was moved from a secure storage area to a workspace while its contents were being transferred to a digital records system, and up to 100 badge holders had access to it, said reports.

This article is featured in:
Application Security • Data Loss  • Internet and Network Security • Public Sector

 

Comment on this article

You must be registered and logged in to leave a comment about this article.