Related Links

Related Stories

  • Identity thief gets nine years
    An identity thief who used victims' credentials to register credit cards fraudulently was sentenced to more than nine years in prison wihout parole late last week.
  • Firms failing on PCI DSS
    A huge 81% of organizations that are subject to the Payment Card Industry’s Data Security Standard (PCI DSS) were found to be non-compliant prior to a data breach, according to a new study.
  • The PCI Paradox - why PCI DSS isn't preventing data breaches
    PCI DSS has been criticized as being both too prescriptive and too vague. The standard’s effectiveness has come under scrutiny once again as PCI compliant organizations have suffered huge data breaches in recent times. Danny Bradbury looks at the standard to find the root of the problem
  • Heartland takes US$12.6m hit for breach
    Heartland Payment Systems has revealed that it lost US$12.6m as a result of its 2008 data breach, in the same week that it finally regained official Payment Card Industry Data Security standard (PCI DSS) compliance.
  • ID theft tops consumer complaint list
    Identity theft continues to be the top consumer complaint in the US, according to the Federal Trade Commission.

News

Weekly brief January 11 2009

11 January 2010

Infosecurity rounds up the week's security news

The TSA is still investigating a former contract worker accused of stealing coworkers' personal information, say officials.

A researcher at SecurityReason has posted proof of concept exploit code to demonstrate a vulnerability in MacOS X 10.5 and 10.6. The code exploits a buffer overflow vulnerability in the operating systems and is based on its OpenBSD kernel. OpenBSD has the same flaw, SecurityReason said.

Heartland Payment Systems is going to pay Visa up to $60 million as part of a settlement program to help card issuers recover losses incurred after the massive data breach that Heartland suffered last year.

Juniper Networks is warning that its gateway routers have a critical flaw that lets attackers crash them by sending small amounts of traffic that can be spoofed.

The Financial Services Information Sharing and Analysis Center (FS-ISAC) is planning a series of simulated cyber attacks to see how well financial institutions and retailers cope with online threats, according to reports.

Two Kansas residents have been accused of identity theft, bank fraud, and conspiracy after allegedly passing stolen checks using misappropriated identities.

Companies have just six months to replace wireless car payment hardware it failed to remain compliant with Payment Card Industry (PCI) standards. The insecure Wired Equivalent Privacy (WEP) protocol becomes noncompliant with the standard in June.

The publisher of the Samy MySpace worm, Samy Kamkar, claims to have found a vulnerability that enables an attacker to identify a victim's geographic location using their home router.

Conficker infections are said to have dropped significantly in late December and over the new year, plummeting by 820 000 to 5.3 million on January 1 alone.

Anti-spyware researcher Ben Edelman is accusing Google of covering advertisers' sites with spyware-delivered pop-ups.

And finally, Sunbelt Software flagged up a story that we wrote, and came back with some interesting responses. Thanks, Tom.

 

This article is featured in:
Compliance and Policy Internet and Network Security Malware and Hardware Security Wireless and Mobile Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.