
September 3rd, 2010 by lhaas
This article just reiterates the point, once again, that companies need to be more proactive in their security:
A new wave of mass SQL injection attacks seen in mid-August to hit over half a million websites, including parts of Apple’s site serves as a weighty reminder of the growing prevalence of mass injections and of SQL [...]

August 31st, 2010 by lhaas
How to find a verify a computer forensic expert
by Lee Haas
Computer forensics experts are skilled in various techniques used to recover and analyze data for use in a legal investigation. They have the ability to dig deeper and provide more than the average IT technician. When you are in need of a [...]

August 31st, 2010 by lhaas
Departing employees and data theft
New techniques shift power back to companies
By Andrew Hoog and the viaForensics team
Gone are the days when employees kept rolodexes on their desks. According to the How Much Information? study conducted by the University of California Berkeley, 92% of all new information in 2002 was stored electronically. This percentage appears [...]

August 17th, 2010 by teull
This article comes from a company focused on providing news, training and education in the areas of information security, risk mitigation and fraud. Their source is the Identity Theft Resource Center, a nonprofit that tracks this issue.
There have been 41 data breaches involving financial institutions so far in 2010 – well on the [...]

June 10th, 2010 by lhaas
Breaking news…
The FBI said Thursday that it is investigating a data breach at AT&T that exposed the e-mail addresses of more than 114,000 owners of the Apple iPad, including government officials.
The agency said it is looking into “the potential cyber threat” from the breach.
AT&T Inc. said it has no comment. The Dallas-based phone [...]

May 27th, 2010 by ahoog
We will test shortly but this is a very serious flaw:
Security experts Bernd Marienfeldt and Jim Herbeck discovered something really interesting when they hooked up a non-jailbroken, fully up-to-date iPhone 3GS to a PC running Lucid Lynx …
I uncovered a data protection vulnerability [9], which I could reproduce on 3 other non jail broken [...]

May 10th, 2010 by lhaas
Federal agency IT executive at the FedScoop Cybersecurity Leadership Summit reached the conclusion that — in light of the belief that they will never achieve perfect security — they need to focus on risk management.
With so many demands on security — and only limited resources to achieve them — federal agencies are rapidly reaching the [...]

May 6th, 2010 by lhaas
Considering the substantial costs that companies could pay for a data breach, isn’t it worth a little investment up front to make sure that never happens?
A data breach in the United States could cost enterprises twice as much as the same breach costs companies in other countries with less stringent disclosure and notification laws, according [...]

May 5th, 2010 by lhaas
Enterprises and consumers each suffer from different types of malware threats, but both were hit hard by rogue antivirus attacks last year, according to new data released by Microsoft today…
“We’re seeing that the criminals are more professional and organized,” Thomlinson says. “[It's] not the guy in his garage doing this in his spare time. This [...]

May 3rd, 2010 by lhaas
A little plug for viaForensics…
As malware and social engineering attacks become more sophisticated, many companies — especially small and midsize businesses (SMBs) — are arriving at one conclusion: We need help….
The article goes on to describe how attackers are using social networks, cloud services and the like to gain access to companies’ computers. And targeted [...]