Saturday, January 31, 2009
Insider plot to take down Fannie Mae's (a mortgage lender) servers thwarted
Tuesday, January 13, 2009
Israel hacks Arab TV station - Cyberspace becomes battleground in Gaza conflict
2008: A year of cowboys in IT security
Security pundits are fond are characterising personalties in information security with reference to Westerns - hence hackers wear either a "black hat" or a "white hat" like their cowboy counterparts.
Probably the biggest security story of the year was the take-down of infamous cybercrime hosting outfit McColo. The rogue ISP hosted the command and control systems for three botnets - Srizbi, Rustock and Mega-D. Junk mail levels temporarily fell to a third their normal level following the takedown of McColo in November. >> More ..US cybersecurity defences fail to thwart mock cyberattack
Critical US electronic systems have failed to withstand a simulated cyberattack.
Participants in a recent cyber-warfare exercise told Reuters that the exercise highlighted problems in leadership, communications and readiness. The two-day exercise brought together 230 government agencies, private firms and other participants. Participants were split into two groups - attackers and defenders - before each developed tactics for attacking and defending critical infrastructure systems, such as those controlling banking, telecommunications and utilities. >> More ..
London Hospital back online after computer virus shutdown
Computer systems at three major London hospitals are largely back online on Friday morning, three days after a major computer virus outbreak forced staff to disconnect the network.
IT systems at St Bartholomew's (Barts), the Royal London Hospital in Whitechapel and the London Chest Hospital in Bethnal Green were taken down on Tuesday following infection by the Mytob worm. The three hospitals make up the Barts and the London NHS Trust. >> More ..
DDoS attack floors Georgia prez website
A denial of service attack hit government websites in the former Soviet republic of Georgia over the weekend amid growing diplomatic tensions between the country and Russia.
The DDoS assault on the website of Georgian President Mikhail Saakashvili rendered it unavailable over the weekend. The attack was run via botnet networks of compromised PCs. Shadowserver charts the command and control servers used in the attack, in an analysis here. >> More ..
Saturday, November 1, 2008
Hack Turns Application Code Against Itself ... New attack uses application flaws to force good code to go rogue
Turns out you don't need malware to exploit a security flaw in an application: A pair of researchers has found a way to automatically make good code do bad things.
Researchers from the University of California at San Diego (UCSD) have devised a technique that basically lets an attacker bypass built-in system defenses aimed at blocking malware, and then execute instructions from inside the application. The process uses an application's vulnerability to turn it against the system on which it runs.
An attacker could take advantage of a flaw in a Web browser, for instance, to force the browser to spam the user's address book using only the browser's own code, according to the researchers. .. More >>
Auditors rap IRS for weak information security
The Internal Revenue Service has failed to secure sensitive electronic taxpayer information properly, increasing the potential for identity theft, according to an audit report released on Thursday.
The inspector general review of three computer systems at the IRS Office of Research, Analysis and Statistics showed several weaknesses in control over access to applications containing sensitive information.
"Managers and system administrators had not placed sufficient emphasis on maintaining the security and privacy of the taxpayer data they are charged with protecting," the report stated. Furthermore, officials failed to provide guidance or monitor compliance with IRS information security policies, and did not supply software to scan for security weaknesses, the IG found. .. More >>
IRS finds unauthorized Web servers connected to its networks
The Internal Revenue Service found more than 1,000 unauthorized Web servers connected to its networks, leaving the agency's systems open to hackers, according to a report released on Thursday by the IRS inspector general.
In September 2007, the IRS Computer Security Incident Response Center scanned the agency's Web servers and identified 2,093 that had at least one security vulnerability. When the center matched those servers to the IRS database of registered Web sites and servers, an inventory of systems that the agency uses to perform security maintenance and apply patches, it found 1,811, or 87 percent, were not listed in the database.
Of the unregistered servers, the IRS identified 661 that were used for legitimate agency business, leaving 1,150 servers being used for potentially unauthorized activity, according to the report. .. More ..
Sunday, September 21, 2008
Revealed: The Internet's Biggest Security Hole
Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency.
The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let an attacker surreptitiously monitor unencrypted internet traffic anywhere in the world, and even modify it before it reaches its destination.
The demonstration is only the latest attack to highlight fundamental security weaknesses in some of the internet's core protocols. Those protocols were largely developed in the 1970s with the assumption that every node on the then-nascent network would be trustworthy. The world was reminded of the quaintness of that assumption in July, when researcher Dan Kaminsky disclosed a serious vulnerability in the DNS system. Experts say the new demonstration targets a potentially larger weakness. .. More ..
European companies forced to own up to data losses
The data breach notification provision is part of the ePrivacy Directive that is currently being debated by the EU. ... More ..
Hacked Texas National Guard site serves up malware
GAO Report Slams US Cybersecurity, US-CERT, and DHS
Wednesday, May 28, 2008
Hacker Shuts Down Government Computers
And the court heard the Government could still be at risk of another cyber attack.
David Anthony McIntosh, 27, allegedly hacked in and shut down several NT Government databases on May 5, including servers for the Health Department, Royal Darwin Hospital, Berrimah Prison and Supreme Court using his laptop at a Palmerston home. >> More ..
Sunday, May 11, 2008
Homeland Security reveals threats and the plans to counter the threats and attacks
India Cites Ongoing Chinese Cyber Attacks
Botnets, keyloggers, and network mapping all plague India on a regular basis, as its gigantic rival in Asia seeks weaknesses within the country's information infrastructure. >> More ..
Wednesday, April 23, 2008
CNN Site Hit by China Attack
At its peak, the attack has sucked up 100MB/S in bandwidth, enough to slow the news Web site for some visitors. >> More ..
Thursday, March 20, 2008
Hackers find a way to crack popular smartcard in minutes
These are a particular type of processor-embedded cards, and are different from credit cards. The actual decryption work by the researchers was done on the widely deployed Mifare Classic wireless smartcard, now manufactured by a Philips spinoff, NXP Semiconductors. Decrypted, the cards can be counterfeited, and users' personal and bank data is exposed. >> More ..
US Law makers voice concerns over cybersecurity plan
Known as the Cyber Initiative, the Bush Administration project would dramatically reduce the number of interconnections between federal government networks and the Internet and put more advanced network security in place to monitor data traffic for signs of malicious attacks. While the 5- to 7-year project could dramatically improve the network defenses of government agencies, law makers questioned whether the initiative will be too little, too late, and whether the resulting network monitoring could undermine privacy.
"It's hard to believe that this Administration now believes it has the answers to secure our federal networks and critical infrastructure," Representative Bennie Thompson (D-MS), chairman of the House Committee on Homeland Security, said in prepared remarks at the opening of the hearing on Thursday. "I believe cybersecurity is a serious problem -- maybe the most complicated national security issue in terms of threat and jurisdiction. This problem will be with us for decades to come." >> More ...
Trend Micro Hit by Massive Web Hack
A Trend Micro spokesman confirmed that the company’s site had been hacked Thursday, saying that the attack took place earlier in the week. "A portion of our site -- some pages were attacked," said Mike Sweeny, a Trend Micro spokesman. "We took the pages down overnight Tuesday night -- and took corrective action." >> More ..