ZDNet Must Read:
Microsoft confirms 'detailed' Windows 7 exploit
Microsoft has issued a security advisory to acknowledge a crippling denial-of-service flaw affecting its newest operating systems -- Windows 7 and Windows Server 2008 R2.... Continued »
Category: PCI
October 19th, 2009
Commonwealth fined $100k for not mandating antivirus software
According to a recently published SEC cease-and-desist order, the Commission has recently fined Commonwealth Financial Network $100,000, for not mandating antivirus software on the computers of its representatives, leading to a security incident which took place in November 2008, allowing the cybercriminal behind the attack to place eighteen unauthorized purchase orders, resulting in $523,000 of unauthorized purchases.
Despite Commonwealth’s brisk reaction which greatly minimized the financial impact of the compromised accounts, the incident took place shortly after a representative contacted the IT Help Desk indicating a malware infection might have taken place without receiving “follow-up” attention:
August 19th, 2009
Radisson Hotels report significant data breach
Add the Radisson Hotels & Resorts chain to the growing list of businesses reporting significant data breaches that exposed sensitive customer data.
In an open letter to guests, Radisson chief operating officer Fredrik Korallus said the hotel chain’s computer system was hacked between November 2008 and May 2009 and customer data, including credit and debit card numbers, was stolen.
July 20th, 2009
Some important truths about pen-testing
Guest editorial by Alberto Soliño
Penetration testing is a highly scientific, metrics-driven approach to IT security that has been in practice since almost the dawn of the modern computing era when programmers first began conducting organized tests, or “hacks” of their own, or others’ technologies to test their performance and reliability.
From nearly the start, as developers attempted to assess the tolerance levels of their technologies to different forms of input, and some user organizations, including governments, did the same, they realized that this process was helpful not only in terms of allowing them to design more stable products, but also in securing these technologies to prevent them from being broken or improperly accessed.
May 8th, 2009
Heartland says malware breach cost $12.6 million
The data breach at Heartland Payment Systems cost the company a whopping $12.6 million in legal costs and fines from Mastercard and Visa.
Heartland, a publicly traded company that provides bank card payment processing services to merchants in the U.S., made the disclosure less than four months after confirming a malware intrusion that compromised data that crossed its network.
April 29th, 2009
Online broker CommSec criticised for weak passwords, lack of SSL
In times when vendors are vertically integrating by offering virtual keyboards for secure Ebanking, and banks themselves are requiring end users to run antivirus software if they were to file a fraud claim, others are busy fixing security design flaws.
Earlier this month, a Melbourne based computer programmer discovered that the 1.7m customers of Australia’s largest online broker CommSec, have been using the site’s services through outdated password best practices, providing them with the option to use a basic numeric password, which is logically increasing the potential effectiveness of brute forcing attacks.
CommSec introduced password best practices once Australia’s Herald Sun approached the company, following two dismissed calls from the programmer:
January 20th, 2009
Heartland finds malware in bank card payment system
Heartland Payment Systems, a publicly traded company that provides bank card payment processing services to merchants in the U.S., has suffered a malware breach that may be linked to a “widespread global cyber fraud operation.”
In a statement (see Adam O’Donnell’s coverage), the company said its system used to process Visa, MasterCard, American Express and Discover Card transactions was breached last year but insists that customer and merchant data was not affected. From the statement:
Read the rest of this entry »
December 1st, 2008
'Dumbing down' the security profession
* Ryan Naraine is traveling.
Guest editorial by Shyama Rose
The market for the development and implementation of source code analysis (static and dynamic) tools is swelling. Companies are increasingly relying on source code analysis tools to identify security-related vulnerabilities. The demand and reliance upon sophisticated automated solutions is greater than the supply of quality tools. Due to the underdevelopment and immature nature of tools and the nature of the industry, the risk of highly complex vulnerabilities left unidentified and unmitigated is high.
Code analysis tools should be used as guidelines or preliminary benchmarks as opposed to definitive software security solutions.
July 2nd, 2008
PCI-DSS 1.1 points to outdated OWASP Top 10
OK, I’m not going to freak out about this too bad… I’ve already pointed out enough problems with PCI, but I did find it morbidly entertaining. My good friend Jeremiah Grossman (pictured at right) blogged today about the PCI-DSS 1.1 section 6.5, which covers “prevention of common coding vulnerabilities in software development processes”, and noted that it actually is identical to the OWASP Top Ten from 2004. Argh… the latest version is from 2007.
Here’s the PCI-DSS list (which is actually OWASP Top 10 from 2004):
July 1st, 2008
McAfee S.P.A.M. experiment and more ridiculous HackerSafe failures
Stay with me here readers, I’m stringing two stories about McAfee together here, a little out of the ordinary, so I hope it makes sense. If you aren’t interested in the tech details (of which there are very little), please do read for a good laugh.
Network World reported that McAfee conducted an experiment into what would happen if computer users really did respond to all those spam emails and click all those free virus scan popups. The experiment, called S.P.A.M. (Spam Persistently All Month) took 50 volunteers, both male and female, from numerous countries and tried to determine what would really happen. Of course, the end result will be exactly what you’d expect, but hey, I’m game for an experiment, and the volunteers get free computers, so let’s read on!
May 30th, 2008
Obama looking for help thwarting Web site hackers
On the heels of last month’s embarrassing site breach that allowed a hacker to redirect traffic from BarackObama.com to Hillary Clinton’s Web site, the Obama campaign is looking to hire a network security expert to lock down its online operations.
According to this job listing, the campaign is offering a salaried position on its Boston, Mass.-based development team to work through the election in November to handle all aspects of online security.
[ SEE: Obama site hacked; redirected to HillaryClinton.com ]
Some responsibilities:
- Analyzing the network architecture for the My.BarackObama website
- Leading an overhaul of existing security systems and architecture, including policy, firewall, VPN, and networking equipment
- Developing a strategy for responding to hack attempts, DDoS attacks, and other potential threats
- Establishing and managing the security posture of the online campaign My.BarackObama
The Obama campaign is looking for someone with a deep understanding of the LAMP (Linux, Apache, MySQL and Perl/Python/PHP) stack, experience with firewall and VPN products and knowledge of the state of the Internet security landscape.
Last month, hackers exposed several cross-site scripting and script injection flaws on the BarackObama.com site to HillaryClinton.com. Some examples of the vulnerabilities have been posted to the xssed.com portal.
Ryan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.
For daily updates on Ryan's activities, follow him on Twitter.
Subscribe to Zero Day via Email alerts or RSS.
SponsoredWhite Papers, Webcasts, and Downloads
- Five Steps to Determine When to Virtualize YourServers VMware Server virtualization isn't just for big companies. Entry-level ... Download Now
- Why Isn't Server Virtualization Saving Us More? A Few Small Changes May Dramatically Increase Your Efficiency VMware Companies have rapidly adopted server virtualization over the past few ... Download Now
- Reducing Server Total Cost of Ownership with VMware Virtualization Software VMware VMware virtualization enables customers to reduce their server TCO and ... Download Now
Recent Entries
- Opera patches ‘extremely severe’ security hole
- Exploit published for critical IE 7 zero-day flaw
- Inside the Google Chrome OS security model
- Microsoft finds security hole in Google Chrome Frame
- Mozilla locks out rogue Firefox add-ons
Blogs From Our Sponsors
Most Popular Posts
- Microsoft confirms 'detailed' Windows 7 exploit
- Thousands of web sites compromised, redirect to scareware
- Windows 7's default UAC bypassed by 8 out of 10 malware samples
- Which antivirus is best at removing malware?
- Mac OS X mega patch covers 58 security vulnerabilities
- Microsoft patches Windows worm holes, drive-by download flaws
Top Rated
- Facebook password-reset spam is Bredolab botnet attack+46 votes
- Thousands of web sites compromised, redirect to scareware+43 votes
- Microsoft confirms 'detailed' Windows 7 exploit+43 votes
- Firefox hit by multiple drive-by download flaws+41 votes
- Which antivirus is best at removing malware?+39 votes
- iHacked: jailbroken iPhones compromised, $5 ransom demanded+32 votes
- New LoroBot ransomware encrypts files, demands $100 for decryption+28 votes
- Mac OS X mega patch covers 58 security vulnerabilities+26 votes
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer>>
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
- Learn more >>
- Keep Up With The Latest In Document Management with The DocuMentor.
-
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- The more you simplify, the more you save
-
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
- Learn more >>
Archives
Favorite Links
ZDNet Blogs
- All About Microsoft
- The Apple Core
- Between the Lines
- BriefingsDirect
- Collaboration 2.0
- Dev Connection
- Digital Cameras & Camcorders
- Ed Bott's Microsoft Report
- Emerging Tech
- Enterprise Web 2.0
- Forrester Research
- Googling Google
- GreenTech Pastures
- Hardware 2.0
- Home Theater
- iGeneration
- Irregular Enterprise
- IT Project Failures
- Laptops & Desktops
- Lawgarithms
- Linux and Open Source
- Managing L'unix
- The Mobile Gadgeteer
- On Sustainability
- Rational Rants
- The Semantic Web
- Service Oriented
- Smartphones and Cell Phones
- Social Business
- Social CRM: The Conversation
- Software & Services Safari
- Software as Services
- Storage Bits
- Team Think
- Tech Broiler
- Technology and the Global Supply Chain
- Tom Foremski: IMHO
- The ToyBox
- Virtually Speaking
- The Web Life
- ZDNet Education
- ZDNet Government
- ZDNet Healthcare
- Zero Day
White Papers, Webcasts, and Downloads
- Three Steps You Need to Know to Stop Data Loss Varonis Sensitive data exposed to misuse or loss... it is the stuff of nightmares ... Download Now
- Reducing Server Total Cost of Ownership with VMware Virtualization Software VMware VMware virtualization enables customers to reduce their server TCO and ... Download Now
- The True Costs of Virtual Server Solutions VMware In an economic environment that is repeatedly heralding the message "do ... Download Now












