<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Security by Eric Jacksch</title>
	<atom:link href="http://jacksch.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://jacksch.com</link>
	<description>Infosec and cyber security news and viewpoints from a security professional with over 15 years in the trenches.</description>
	<lastBuildDate>Fri, 03 Feb 2012 13:59:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>InfoSec News 2012-02-03</title>
		<link>http://jacksch.com/2012/02/infosec-news-2012-02-03/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-02-03</link>
		<comments>http://jacksch.com/2012/02/infosec-news-2012-02-03/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 13:59:08 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4576</guid>
		<description><![CDATA[InfoSec News for Friday February 3, 2012. Half of Fortune 500s, US Govt. Still Infected with DNSChanger TrojanMore than two months after authorities shut down a massive Internet traffic hijacking scheme, the malicious software that powered the criminal network is still running on computers at half of the Fortune 500 companies, and on PCs at [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Friday February 3, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/ExkREHGaiUI/">Half of Fortune 500s, US Govt. Still Infected with DNSChanger Trojan</a><br />More than two months after authorities shut down a massive Internet traffic hijacking scheme, the malicious software that powered the criminal network is still running on computers at half of the Fortune 500 companies, and on PCs at nearly 50 percent of all federal government agencies, new research shows.
<p>The malware, known as the &#8220;DNSChanger Trojan,&#8221; quietly alters the host computer&#8217;s Internet settings to hijack search results and to block victims from visiting security sites that might help scrub the infections. DNSChanger frequently was bundled with other types of malware, meaning that systems infected with the Trojan often also host other, more nefarious digital parasites.</p>
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/03/satellite_phone_hack/">Satellite phones lift skirt, flash cipher secrets at boffins</a><br />Security though obscurity fails yet again: Researchers at the Ruhr-University Bochum have managed to extract the secret encryption algorithmns used by satellite phones, and discovered that it&#8217;s a lot less secure than one might hope.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/03/quotw_ending_february_3/">&#8216;We&#8217;re totally in LA pissing people off&#8217;</a><br />Plus &#8216;The horror!&#8217;: Quotw This was the week when Facebook finally filed for its IPO.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/TGVCW7-bxiQ/Tiff_over_LightSquared_reveals_odd_partnership">Tiff over LightSquared reveals odd partnership</a><br />LightSquared founder Philip Falcone&#8217;s response to ethics allegations by a U.S. senator sheds some light on a strange chapter in the carrier&#8217;s ongoing bid to build a controversial cellular data network.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/glHlmDaTDpM/Half_of_Fortune_500_firms_infected_with_DNS_Changer">Half of Fortune 500 firms infected with DNS Changer</a><br />Half of all Fortune 500 companies and major U.S. government agencies own computers infected with the &#8220;DNS Changer&#8221; malware that redirects users to fake websites and puts organizations at risk of data theft, a security company said today.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/jOe4ro9DljM/VeriSign_admits_multiple_hacks_in_2010_keeps_details_under_wraps">VeriSign admits multiple hacks in 2010, keeps details under wraps</a><br />VeriSign, the company responsible for guiding most of the world&#8217;s Internet users to the correct websites and once the largest encryption certificate issuing authority, was successfully hacked several times in 2010.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/02/verisign_hacking_attack/">Verisign admits 2010 hack attack, mum on what was nicked</a><br />SEC filing shows BOFH cover-up: Verisign has admitted in an SEC filing that it suffered numerous data breaches in 2010, but that management wasnt informed by staff for nearly a year after they occurred.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/02/pcanywhere_source_code_leak_sheanigans/">Symantec: We&#8217;ve plugged up pcAnywhere holes</a><br />Security giant tries to draw line under source code soap opera: Symantec has said its pcAnywhere remote control software is once again safe to use, following the release of its latest security patch.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/02/kelihos_botnet_returns/">Kelihos botnet BACK FROM THE DEAD</a><br />Bloodied spam-spewing zombie staggers in: The spam-spewing Kelihos botnet has returned from the dead.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/01/smart_meters_yesno/">OFFICIAL: Smart meters won&#8217;t be compulsory</a><br />No offence to refuse in Blighty: Vid So-called &#8216;smart meters&#8217; will not be mandatory, the energy minister has confirmed. The pledge was made by Charles Hendry last Thursday, and confirmed to us by the Department of Energy and Climate Change today.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Yygb8JQRZNY/secworld.php">Concerned about online privacy? FBI says you might be a terrorist</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/020212-microsoft-anonymous-255667.html?source=nww_rss">Microsoft researchers say anonymized data isn&#8217;t so anonymous</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/020312-google-finally-scans-malware-ridden-android-255688.html?source=nww_rss">Google finally scans malware-ridden Android Market</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/rpoQv_GmUnQ/malware_news.php">Google reveals it is already scanning Android apps for malware</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/eQ-oOo1wcF4/">Iran is an urgent nuclear threat: CSIS</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/AOR9bo1GEaM/">VeriSign Management was &#8216;Out of the Loop&#8217; About 2010 Data Breach</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=5f4d5ff13db4c6152d2a382ffad86788">VeriSign Hacked: What We Don&#8217;t Know Might Hurt Us</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/02/02/peter-foster-two-faced-book/">Peter Foster: Two-faced book</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/xl86F3SP5OE/">Attacks could steal HTC Wi-Fi codes with malicious app</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/02/pre-owned-music-lawsuit/">Online Market for Pre-Owned Digital Music Hangs in the Balance</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Ryj4ERqnPOM/">Google using custom malware scanner for Android apps</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/jkanLnp3B2E/">Oracle Patches DoS Flaw in Database 10g, WebLogic, iPlanet</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/g7bWGxT-8QI/">Apple Fixes 52 Bugs in OS X Snow Leopard, Lion in Security Update</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/AI7ia2VsQiw/at-long-last-malware-scanning-comes-to-googles-android-market.ars">At long last, malware scanning comes to Google&#8217;s Android Market</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/eptVilXu1Z0/eff-ready-to-sue-if-innocent-customers-cant-get-megaupload-data-back.ars">EFF ready to sue if &#8220;innocent customers&#8221; can&#8217;t get Megaupload data back</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/8KQA5jrIICU/">Donald Trump endorses Mitt Romney</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/DjYyQgyIjUI/">WikiLeaks Julian Assange extradition ruling over alleged sex crimes may jeopardize other cases: lawyer</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/lIo-nX7rj9Q/verisign-maintainter-of-nets-dns-was-repeatedly-hacked.ars">VeriSign, maintainter of net&#8217;s DNS, warns it was repeatedly hacked</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=1c6216af7dd793ff6d3b19576bcd9746">VeriSign 2010 Hack: DNS Data Theft A Possibility</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c5adbda/l/0Lnews0Btechworld0N0Csecurity0C33348160Cverisign0Eadmits0Eit0Ewas0Ehacked0Ein0E20A10A0Ebut0Emanagers0Enot0Etold0C0Dolo0Frss/story01.htm">VeriSign admits it was hacked in 2010 but managers not told</a>
</li>
<li><a href="http://datalossdb.org/incidents/5581-contact-details-crime-tips-by-citizens-and-other-personal-information-acquired-by-hackers-additionally-1-073-employees-names-usernames-e-mail-addresses-md5-passwords-job-titles-or-position-and-phone-numbers-dumped-on-the-internet">Contact details, crime tips by citizens, and other personal information acquired by hackers; additionally, 1,073 employees&#8217; names, usernames, e-mail addresses, MD5 passwords, job titles or position, and phone numbers dumped on the Internet</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c5aae1e/l/0Lnews0Btechworld0N0Csecurity0C33347990Cbogus0Efacebook0Eaccounts0Ealways0Efemale0Enew0Estudy0Efinds0C0Dolo0Frss/story01.htm">Bogus Facebook accounts always female, new study finds</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/8jkA4et6cqs/">Security breaches impacting VeriSign emerge in filing</a>
</li>
<li><a href="http://datalossdb.org/incidents/5580-employee-skimmed-and-sold-50-customers-credit-card-numbers">Employee skimmed and sold 50 customers&#8217; credit card numbers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5579-names-dates-of-birth-sickness-information-and-work-contact-numbers-of-employees-were-published-on-the-internet">Names, dates of birth, sickness information and work contact numbers of employees were published on the internet.</a>
</li>
<li><a href="http://datalossdb.org/incidents/5578-lost-memory-stick-contained-personal-details-of-young-children-attending-schools-in-the-dunbar-area">Lost memory stick contained personal details of young children attending schools in the Dunbar area</a>
</li>
<li><a href="http://datalossdb.org/incidents/5577-customers-personal-details-and-encrypted-credit-card-numbers-with-expiration-dates-may-have-been-accessed-by-hacker">Customers&#8217; personal details and encrypted credit card numbers with expiration dates may have been accessed by hacker</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c5aaa2e/l/0Lnews0Btechworld0N0Csecurity0C33347990Cbogus0Efacebook0Eaccounts0Eeasy0Espot0Enew0Estudy0Efinds0C0Dolo0Frss/story01.htm">Bogus Facebook accounts easy to spot, new study finds</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=8e2ef2e867ab501aa5a9b8118899e87a">Symantec Shouldn&#8217;t Backpedal on Android &#8216;Malware&#8217;</a>
</li>
<li><a href="http://datalossdb.org/incidents/5573-more-than-50-customers-credit-card-numbers-exfiltrated-by-virus-incurred-fraudulent-charges">More than 50 customers&#8217; credit card numbers exfiltrated by virus incurred fraudulent charges</a>
</li>
<li><a href="http://datalossdb.org/incidents/5572-county-s-web-portal-for-public-hacked-250-residents-email-addresses-user-names-and-passwords-accessed">County&#8217;s web portal for public hacked; 250 residents&#8217; email addresses, user names and passwords accessed</a>
</li>
<li><a href="http://business.financialpost.com/2012/02/02/facebooks-looming-mobile-conundrum/">Facebooks looming mobile conundrum</a>
</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232600132/yubico-and-cloudpassage-bring-easy-secure-two-factor-authentication-to-cloud-servers.html">Yubico And CloudPassage Bring Easy, Secure Two-Factor Authentication To Cloud Servers</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232600134/socialshield-releases-the-top-social-networking-terms-kids-don-t-want-their-parents-to-know.html">SocialShield Releases the Top Social Networking Terms Kids Don&#8217;t Want Their Parents To Know</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/02/verisign-hacked-in-2010/">VeriSign Hit by Hackers in 2010</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/H7ZCj-KcjeM/">Palin hacker appeal rejected</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/02/supreme-court-of-sweden-upholds-pirate-bay-prison-sentences/">Supreme Court of Sweden Upholds Pirate Bay Prison Sentences</a>
</li>
<li><a href="http://datalossdb.org/incidents/5559-1-219-patients-notified-that-flash-drive-stolen-from-pathologist-s-car">1,219 patients notified that flash drive stolen from pathologist&#8217;s car</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/GCh2lHNhm_c/malware_news.php">Detecting the DNS Changer malware</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/jFHpx7MU6Bc/malware_news.php">Malware redirects bank phone calls to attackers</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/02/infosec-news-2012-02-03/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-02-02</title>
		<link>http://jacksch.com/2012/02/infosec-news-2012-02-02/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-02-02</link>
		<comments>http://jacksch.com/2012/02/infosec-news-2012-02-02/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 13:59:05 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4574</guid>
		<description><![CDATA[InfoSec News for Thursday February 2, 2012. Whos Behind the Worlds Largest Spam Botnet?A Wikileaks-style war of attrition between two competing rogue Internet pharmacy gangs has exposed some of the biggest spammers on the planet. The latest casualties? Several individuals likely responsible for running Grum, currently the world&#8217;s most active spam botnet. Demand for safety [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Thursday February 2, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/TON3aIUS6N4/">Whos Behind the Worlds Largest Spam Botnet?</a><br />A Wikileaks-style war of attrition between two competing rogue Internet pharmacy gangs has exposed some of the biggest spammers on the planet. The latest casualties? Several individuals likely responsible for running Grum, currently the world&#8217;s most active spam botnet.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/02/mps_cyber_security_report/">Demand for safety kitemark on software stepped up</a><br />MPs want new standard plus web security schooling: The government and industry ought to do more to promote online safety, according to an influential panel of MPs.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/02/email_hack_allegations_times/">Met&#8217;s email hack probe turns spotlight on <cite>The Times</cite> &#8211; MP</a><br />Scotland Yard keeps mum: Scotland Yard officers investigating allegations of computer hacking by News International staff have declined to &#8220;give a running commentary&#8221; on their probe, batting away MP Tom Watson&#8217;s narration of the saga.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/02/facebook_hacked_before/">Facebook warns investors of potential SPAM DELUGE</a><br />IPO filing: Spamvalanche could kill us: Facebook has been the first internet company to baldly state the risks it faces from hacking and spam to the markets since the SEC issued guidance on the issue.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/02/ice_ix_trojan_social_engineering_trickery/">New Trojan routes your bank&#8217;s calls to CROOKS</a><br />That&#8217;s right, I really just ordered 10 plasma tellies&#8230;: Devious cybercrooks have developed a banking Trojan that is capable of redirecting calls your bank has made to verify suspicious transactions straight into the waiting handsets of professional criminal caller services.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/01/fairfax_site_compromised/">Fairfax bunkers down after alleged hack</a><br />Privacy Commissioner wakes up: Two Fairfax sites remain offline this morning after they were apparently compromised, with the possible loss of credit card information.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/E36-0G6mZZ8/WikiLeaks_Assange_takes_appeal_to_U.K._Supreme_Court">WikiLeaks&#8217; Assange takes appeal to U.K. Supreme Court</a><br />WikiLeaks founder Julian Assange launched his appeal in the U.K. Supreme Court on Wednesday in his last attempt in Britain to avoid extradition to Sweden to face sexual assault allegations.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/01/ms_attack_ads_google_privacy/">Microsoft ad campaign savages Google over privacy</a><br />&#8216;We are not like them, and hey, why not try IE?&#8217;: Microsoft is launching a three-day advertising campaign in the US, offering itself as the privacy-respecting alternative to Google.
</li>
<li><a href="http://business.financialpost.com/2012/02/02/will-investors-like-facebook/">Will the market like Facebook?</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c591be6/l/0Lnews0Btechworld0N0Csecurity0C33346910Cmps0Ecall0Eon0Egovernment0Estep0Eup0Emalware0Eprotection0C0Dolo0Frss/story01.htm">MPs call on government to step up malware protection</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/sXbvvwe0SPU/">Google, Microsoft Spar Over Privacy Policy Claims</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c588c1b/l/0Lreview0Btechworld0N0Csecurity0C33340A320Cbitdefender0Einternet0Esecurity0E20A120Ereview0C0Dolo0Frss/story01.htm">Bitdefender Internet Security 2012 review</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/020112-symantec-recants-android-malware-255610.html?source=nww_rss">Symantec recants Android malware claims</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/jRA0linji4Y/secworld.php">Security breaches driving authentication changes</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c578004/l/0Lnews0Btechworld0N0Csecurity0C33346250Csymantec0Ebacktracks0Efrom0Egoogle0Eandroid0Emalware0Eclaims0C0Dolo0Frss/story01.htm">Symantec backtracks from Google Android malware claims</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/uk-politics-16839217">Keep calm and log on, MPs argue</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/-9QTwoO2XKo/">Charges shed light on alleged plot to smuggle Saadi Gaddafi to Mexico</a>
</li>
<li><a href="http://www.cbc.ca/news/canada/british-columbia/story/2012/02/01/bc-canadian-nazis-exposed.html?cmp=rss">Hacked neo-Nazi websites reveal Canadian connections</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/R94m-mJgB7Q/">Facebook Discloses Hacking, Spam as Business Risks in IPO Documents</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/coMGM_dwLzk/">Wave Systems Launches Cloud-Based Encryption Management Platform</a>
</li>
<li><a href="http://business.financialpost.com/2012/02/01/a-timeline-of-facebooks-meteoric-ascent/">A timeline of Facebooks meteoric ascent</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/akVmTXRoSPM/">Trojan Targets Industry, Government with Fake Conference Invitations</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/xSrfx5rbpLM/apple-store-employee-reportedly-being-spied-on-via-imessage-bug.ars">Apple Store employee reportedly being spied on via iMessage bug</a>
</li>
<li><a href="http://business.financialpost.com/2012/02/01/facebook-files-for-ipo/">Facebook files for US$5-billion IPO</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232600082/backupify-announces-security-best-practices-adds-multiple-layers-of-protection-to-cloud-application-data-backup.html">Backupify Announces Security Best Practices, Adds Multiple Layers Of Protection To Cloud Application Data Backup</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232600083/vulnerabilities-reported-in-mac-encryption-products.html">Vulnerabilities Reported In Mac Encryption Products</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232600085/cloudpassage-launches-network-security-in-the-cloud-inbox.html">CloudPassage Launches Network Security In The Cloud Inbox</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/JzDgKAbU14Q/">Mexico files charges in alleged Saadi Gaddafi smuggling plot involving Canadian woman</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Zvx5E0m1bNw/">WordPress attacks try to infect users with dangerous rootkit</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=db489faf4ab0f9baf0e2a168a57fd7e8">RFID Credit Cards Are Easy Prey for Hackers, Demo Shows</a>
</li>
<li><a href="http://datalossdb.org/incidents/5567-identity-information-on-at-least-187-students-found-in-possession-of-another-student-who-may-have-used-data-for-tax-refund-fraud">Identity information on at least 187 students found in possession of another student who may have used data for tax refund fraud</a>
</li>
<li><a href="http://datalossdb.org/incidents/5566-392-e-mail-addresses-and-md5-passwords-dumped-on-internet">392 e-mail addresses and MD5 passwords dumped on Internet</a>
</li>
<li><a href="http://datalossdb.org/incidents/5568-12-374-job-applicants-and-fewer-than-500-patients-notified-that-their-names-addresses-social-security-numbers-and-insurance-info-may-have-been-accessed-after-virus-was-discovered-on-system">12,374 job applicants and fewer than 500 patients notified that their names, addresses, Social Security numbers and insurance info may have been accessed after virus was discovered on system</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/QX5I9AwGwcI/meet-our-new-security-editor-and-help-shape-our-coverage.ars">Meet our new Security Editor and help shape our coverage</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/020112-kelihos-botnet-once-crippled-now-255571.html?source=nww_rss">Kelihos botnet, once crippled, now gaining strength</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/020112-for-malware-as-a-service-255581.html?source=nww_rss">For &#8216;Malware as a Service&#8217; merchants, business is booming</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=7b0c7b9d491f99ed9c83c20cdaaa7390">Counterclank Apps To Remain In Android Market</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/02/copyright-to-the-batmobile/">Copyright: To the Batmobile!</a>
</li>
<li><a href="http://datalossdb.org/incidents/5563-employees-401k-data-on-flash-drive-lost-in-the-mail-decryption-code-was-in-the-same-mailing-but-remained-in-package">Employees&#8217; 401k data on flash drive lost in the mail; decryption code was in the same mailing but remained in package</a>
</li>
<li><a href="http://datalossdb.org/incidents/5561-160-e-mail-addresses-and-clear-text-passwords-dumped-on-internet">160 e-mail addresses and clear-text passwords dumped on Internet</a>
</li>
<li><a href="http://datalossdb.org/incidents/5562-12-456-digital-game-purchasers-notified-network-intruder-intercepted-and-acquired-credit-card-numbers-expiration-dates-security-codes-postal-and-email-addresses-and-passwords-to-optional-user-accounts">12,456 digital game purchasers notified network intruder intercepted and acquired credit card numbers, expiration dates, security codes, postal and email addresses, and passwords to optional user accounts</a>
</li>
<li><a href="http://datalossdb.org/incidents/5560-1-018-patients-notified-after-laptop-stolen-from-neurology-dept">1,018 patients notified after laptop stolen from Neurology Dept.</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=ee0fec15c76d8efeb0a456edb9346e6a">Cyber Attacks Becoming Top Terror Threat, FBI Says</a>
</li>
<li><a href="http://business.financialpost.com/2012/02/01/internet-complaints-skyrocket-in-canada/">Internet complaints skyrocket in Canada</a>
</li>
<li><a href="http://www.torontosun.com/2012/02/01/ukraine-government-sites-attacked-after-piracy-crackdown">Ukraine government sites attacked after piracy crackdown</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/XEYnX-erBWA/">Mobile Data Security: 10 Tips to Avoid Prying Eyes at the U.S. Border</a>
</li>
<li><a href="http://business.financialpost.com/2012/02/01/when-will-facebook-change-its-status-from-private-to-public/">When will Facebook change its status from private to public?</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/t7Pn0rwKUPY/">Syria rebels hope Damascus battle will force international allies to act</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/TFk5sH1tvlg/">Timeline: Julian Assange and WikiLeaks</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c52aa3c/l/0Lnews0Btechworld0N0Csecurity0C33344280Ckelihos0Ebotnet0Ecranks0Eback0Eup0Eafter0Emicrosoft0Eattack0C0Dolo0Frss/story01.htm">Kelihos botnet cranks back up after Microsoft attack</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/02/infosec-news-2012-02-02/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-02-01</title>
		<link>http://jacksch.com/2012/02/infosec-news-2012-02-01/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-02-01</link>
		<comments>http://jacksch.com/2012/02/infosec-news-2012-02-01/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 13:59:07 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4572</guid>
		<description><![CDATA[InfoSec News for Wednesday February 1, 2012. Romanian cops cuff suspected serial hacker TinKodeAlleged Royal Navy, Pentagon invader gets keelhauled: Romanian police have arrested a man suspected of breaking into the websites of NASA and the Pentagon in a series of high-profile hack attacks. Expert to finger air steward commentards who &#8216;harassed&#8217; pilotProbe into airline [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Wednesday February 1, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/01/tinkode_nasa_hack_suspect_cuffed/">Romanian cops cuff suspected serial hacker TinKode</a><br />Alleged Royal Navy, Pentagon invader gets keelhauled: Romanian police have arrested a man suspected of breaking into the websites of NASA and the Pentagon in a series of high-profile hack attacks.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/01/high_court_says_scrutinising_forum_database_isok/">Expert to finger air steward commentards who &#8216;harassed&#8217; pilot</a><br />Probe into airline staff forum &#8216;will not breach privacy rights&#8217;: A trade union has been ordered to let an independent expert examine its computer database to try to identify anonymous users of a forum it operated who allegedly defamed and harassed an airline pilot.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/01/spear_phishing_rats/">Trojan smuggles out nicked blueprints as Windows Update data</a><br />Malware backdoors government-targeted kit &#8216;using Adobe 0-days&#8217;: Security watchers have uncovered a new highly targeted email-borne attack that uses a supposed conference invitation as a lure &#8211; and disguises extracted data as Microsoft Update traffic.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/LZtJ07Skm-Y/Lawmakers_question_proposed_change_to_video_privacy_law">Lawmakers question proposed change to video privacy law</a><br />Let&#8217;s say you like to watch heady documentaries over Netflix&#8217;s streaming service and would like to share recommendations with your friends on Facebook. Netflix would like to offer that service, but the company says a 24-year-old U.S. law is in the way.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/0hCMuK164Uk/In_letter_to_Congress_Google_defends_privacy_changes_">In letter to Congress, Google defends privacy changes</a><br />In a letter sent to eight members of Congress, Google yesterday defended its move to consolidate its privacy policies and users&#8217; personal information.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/31/cyberwar_survey/">Cyberwar report: Israel, Finland best prepared for conflict</a><br />Do GCHQ and the NSA have some catching up to do?: Analysis Israel, Finland and Sweden are more prepared than larger nations to fight a conflict in cyberspace, according to a McAfee-backed cyber-defence study.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/31/wordpress_vuln_phoenix/">Virus-slingers abuse WordPress vulns, dose punters with exploit</a><br />Blogs also infected with information-harvesting Trojan: Malware-spreaders are hacking into vulnerable WordPress-powered sites in order to drive traffic towards pages loaded with exploits.
</li>
<li><a href="http://business.financialpost.com/2012/02/01/nortel-executive-faced-deluge-of-data-trial-told/">Nortel executive faced deluge of data, trial told</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/nhiIcR5qWuw/secworld.php">Romaninan hacker TinKode allegedly arrested</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/ePTbkKaXiDo/slain-kelihos-botnet-still-spams-from-beyond-the-grave.ars">&#8220;Slain&#8221; Kelihos botnet still spams from beyond the grave</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c511f49/l/0Lnews0Btechworld0N0Csecurity0C33343570Ctrojan0Efound0Ebreaking0Eyahoo0Ecaptcha0Esecurity0Ein0Eminutes0C0Dolo0Frss/story01.htm">Trojan found breaking Yahoo CAPTCHA security in minutes</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/SNDj3ZsHXiY/megauploads-hosting-company-teams-up-with-eff-to-identify-legal-files.ars">Megaupload&#8217;s hosting company teams up with EFF to identify legal files</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/l4ki5j3KKt0/">Mexican man accused of beating Calgary tourist says he confessed under torture</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/google-censoring-blogger/">Google to Censor Blogger Blogs on a Per Country Basis</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/2qWm7hJk788/">Google won&#8217;t pull Android apps deemed malicious</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/cHdn4Bo9yu4/">Rising Cyber-War Threat Forcing Nations to Bolster Defenses: McAfee</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232600001/country-with-most-online-fraud-attempts-how-much-fraud-on-mobile-devices-revealed.html">Country With Most Online Fraud Attempts/How Much Fraud On Mobile Devices Revealed</a>
</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232600002/new-survey-two-thirds-of-companies-interested-in-switching-authentication-vendors.html">New Survey: Two-Thirds Of Companies Interested In Switching Authentication Vendors</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/-IbTXP_tbWE/">Stop SOPA, PIPA Madness: Ways to Sensibly Protect Copyrights</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/iVDtmMQQxEA/fake-windows-updater-targets-government-contractors-stealing-sensitive-data.ars">Fake Windows updater targets government contractors, stealing sensitive data</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/iVPFULnBpyU/">Obama plays down Iraq drone presence as he confirms Pakistan strikes</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/megaupload-server-purge/">Megaupload Server Purge Delayed</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/carder-sex-gang/">Carder Forced Gang Members to Have Sex to Weed Out Undercover Feds</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/013112-hackers-infect-wordpress-321-blogs-255514.html?source=nww_rss">Hackers infect WordPress 3.2.1 blogs to distribute TDSS rootkit</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/4kIvGs8bDzw/">Investors Warned of Email Accounts Being Hacked to Illegally Transfer Funds</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/rz5JsWcWFeU/">Iran may or may not be building nuclear weapon, but theyre keeping their options open: U.S. intelligence chief</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/S1eyxKIgP6I/">Google Tells Congress It is Changing Privacy Policies, Not Practices</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/gtGwdXpKobU/mobile-device-privacy-act-would-prevent-secret-smartphone-monitoring.ars">&#8220;Mobile Device Privacy Act&#8221; would prevent secret smartphone monitoring</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c4b6961/l/0Lreview0Btechworld0N0Csecurity0C33340A270Cwebroot0Esecureanywhere0Eessentials0E20A120Ereview0C0Dolo0Frss/story01.htm">Webroot SecureAnywhere Essentials 2012 review</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232500774/ibm-announces-new-software-to-manage-and-secure-the-influx-of-mobile-devices-to-the-workplace.html">IBM Announces New Software to Manage And Secure The Influx Of Mobile Devices To The Workplace</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/02/infosec-news-2012-02-01/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-31</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-31/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-31</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-31/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 13:59:08 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4570</guid>
		<description><![CDATA[InfoSec News for Tuesday January 31, 2012. Glavmed Sister Program GlavTorg to CloseA prominent affiliate program that pays people to promote knockoff luxury goods closing down at the end of January. The program &#8212; GlavTorg.com &#8212; is run by the same individuals who ran the infamous Glavmed and SpamIt rogue pharmacy operations. Warnings About Windows [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Tuesday January 31, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/rVOcPUmDfi0/">Glavmed Sister Program GlavTorg to Close</a><br />A prominent affiliate program that pays people to promote knockoff luxury goods closing down at the end of January. The program &#8212; GlavTorg.com &#8212; is run by the same individuals who ran the infamous Glavmed and SpamIt rogue pharmacy operations.
</li>
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/qn2h75xp3Ag/">Warnings About Windows Exploit, pcAnywhere</a><br />Security experts have spotted drive-by malware attacks exploiting a critical security hole in Windows that Microsoft recently addressed with a software patch. Separately, Symantec is warning users of its pcAnywhere remote administration tool to either update or remove the program, citing a recent data breach at the security firm that the company said could help attackers find holes in the aging software title.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/6-E0rgq6y7w/Many_pcAnywhere_systems_still_sitting_ducks">Many pcAnywhere systems still sitting ducks</a><br />Symantec warns that its product should not be connected directly to the Internet, yet an estimated 140,000 computers are configured to allow direct external access
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/31/midlothian_data_breach_fine/">Council fined 140k for leaking kids&#8217; sensitive info</a><br />First Scottish organisation fined by information commissioner: The Information Commissioner&#8217;s Office (ICO) has fined Midlothian council 140,000 for disclosing sensitive personal data about children and their carers to the wrong people on five separate occasions.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/sKvf0GLVuKE/Lawmaker_pushes_consumer_notification_bill_in_wake_of_Carrier_IQ_concerns">Lawmaker pushes consumer notification bill in wake of Carrier IQ concerns</a><br />U.S. Rep. Edward Markey (D-Mass.) has proposed a bill that would require all phone companies to notify consumers of any user tracking and monitoring software in their cell phones.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/vOanBfqg3iA/Feds_say_Megaupload_user_content_could_be_deleted_this_week">Feds say Megaupload user content could be deleted this week</a><br />Federal prosecutors say that two companies hosting Megaupload&#8217;s servers in the U.S. could begin deleting all user content on them as early as Thursday.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/30/dmarc_email_authentication_push/">Google, Facebook, Microsoft in PHISH-FIGHTING smackdown</a><br />DMARC Brothers back cross-industry standard: Google, Facebook and other internet heavyweights are collaborating together to back a standard designed to curtail phishing by improving the collaboration between legitimate senders and receivers of emails.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/30/counterclank_android_malware/"><i>Sexy Girls Puzzle</i>: Android Trojan or eager ad-slinger?</a><br />Researchers split on Counterclank&#8217;s naughtiness: Security researchers are split on the seriousness of an Android &#8220;malware&#8221; campaign that some estimates suggest may have &#8220;infected millions&#8221; of smartphones via gaming apps from Google&#8217;s Android Market.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/gNAlbr5qJp8/Accused_Kelihos_botmaster_proclaims_innocence">Accused Kelihos botmaster proclaims innocence</a><br />Andrey Sabelnikov, the Russian programmer accused by Microsoft of creating and operating the Kelihos spam botnet said he&#8217;s innocent.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/rdWTneE_to4/Researchers_unearth_more_Chinese_links_to_defense_contractor_attacks">Researchers unearth more Chinese links to defense contractor attacks</a><br />Symantec researchers have uncovered additional clues that point to Chinese hacker involvement in attacks against a large number of Western companies, including major U.S. defense contractors.
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=b61b7ad950044c78536b7081e1027533">Norton Wants To Help You Remember Your Password</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/013012-cybersecurity-report-all-countries-lag-255498.html?source=nww_rss">Cybersecurity report: All countries lag behind the bad guys</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/013012-cybersecurity-report-stresses-need-for-255500.html?source=nww_rss">Cybersecurity Report Stresses Need for Cooperation</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c48cf02/l/0Lnews0Btechworld0N0Csecurity0C33339150Caccused0Ekelihos0Ebotmaster0Eandrey0Esabelnikov0Eclaims0Einnocence0C0Dolo0Frss/story01.htm">Accused Kelihos botmaster Andrey Sabelnikov claims innocence</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/r-qhgLgH2dQ/secworld.php">The state of global cyber-readiness</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c47d868/l/0Lnews0Btechworld0N0Csecurity0C33338840Cuk0Elags0Ewell0Ebehind0Ecyber0Eattackers0Esays0Ereport0C0Dolo0Frss/story01.htm">UK prepared for cyberattack, but cybercriminals &#8216;faster and swifter&#8217;</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/uk-scotland-edinburgh-east-fife-16780239">Council fined for data breaches</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Q2U1KgBaLJw/secworld.php">The Web Application Hacker&#8217;s Handbook, 2nd Edition</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/Q3BoDSR3Yro/">Android.Counterclank an Aggressive Mobile Ad Network, Not Malware: Lookout</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/pqdAL6qd3T4/">Google, Microsoft Team Up to Fight Phishing, Spoofed Emails With DMARC</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=b6a05f32d633db86369e3cef1b03f3f3">Five Ways to Protect Your Email at Work</a>
</li>
<li><a href="http://www.darkreading.com/security-monitoring/167901086/security/news/232500752/baltimore-based-security-provider-lookingglass-raises-5-million-in-funding.html">Baltimore-Based Security Provider Lookingglass Raises $5 Million In Funding</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/CaqjDJMNRk8/">Megaupload founder Kim Dotcom gets a huge, inflatable tank</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/9QgNdsldhBA/">Accused Kelihos spam botmaster: It wasn&#8217;t me, Microsoft</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/new-mobile-phone-privacy-law-proposed/">New Mobile-Phone Privacy Law Proposed</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/uON4sIpjaRU/">Facebook sues Adscend Media for malware and spam</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/gyIhMm1wPeg/">McAfee Updates Mobile Security With Remote Tracking, Data Wipes</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/zMdpRKH93Nc/hackers-put-hijacked-web-views-up-for-sale-for-webfraud.ars">Hackers put hijacked Web views up for sale for webfraud</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/30/rims-dramatically-different-recycled-marketing-campaign/">RIMs dramatically different recycled marketing campaign</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/30/obama-campaign-turns-to-square-for-mobile-fundraising/">Obama campaign turns to Square for mobile fundraising</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/bin-laden-photo-flap/">CIA Claims Publication of Bin Laden Death Photos Would Trigger Violence</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232500734/auto-mate-launches-guard-mate.html">Auto/Mate Launches Guard/Mate</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/aHfgUAG5W1M/internet-awash-in-inaccurate-anti-acta-arguments.ars">As Anonymous protests, Internet drowns in inaccurate anti-ACTA arguments</a>
</li>
<li><a href="http://www.darkreading.com/compliance/167901112/security/news/232500723/infoblox-and-ca-technologies-deliver-network-automation-and-compliance-capabilities.html">Infoblox And CA Technologies Deliver Network Automation And Compliance Capabilities</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232500724/wave-launches-cloud-based-encryption-service.html">Wave Launches Cloud-Based Encryption Service</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/fda-spying-on-workers/">FDA Accused of Spying on Whistleblowing Employees</a>
</li>
<li><a href="http://www.darkreading.com/database-security/167901020/security/news/232500720/survey-of-security-and-audit-pros-dbas-reveals-responsibility-disconnect-lack-of-management-commitment-impedes-database-security-efforts.html">Survey Of Security And Audit Pros, DBAs Reveals Responsibility Disconnect, Lack Of Management Commitment Impedes Database Security Efforts</a>
</li>
<li><a href="http://www.darkreading.com/security-services/167801101/security/news/232500722/metaflows-announces-software-based-idps-enables-idps-hardware-for-1-10-the-price.html">MetaFlows Announces Software-Based IDPS, Enables IDPS Hardware For 1/10 The Price</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/srdetect20120130-ex-special-forces-officers-launch-indiabased-threat-detection-company">Ex. Special Forces officers launch India-based threat detection company</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/Lu-GAT7hECk/">Megaupload Data Subject to Deletion by Hosting Providers Feb. 2</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/013012-dmarc-255432.html?source=nww_rss">Google, Microsoft, Facebook, Bank of America team to wipe out phishing</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=0353d5a28557ad48dcfce09c5104029d">Android Counterclank: Malware, Or Smartphone Advertising?</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232500700/mcafee-and-security-defence-agenda-release-global-cyber-defense-report.html">McAfee and Security &amp; Defence Agenda Release Global Cyber Defense Report</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/l3n8sj3gniE/">Costa Concordia wreck will not be moved until at least the end of the year or longer</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/pS8__kTQaEw/android-trojans-downloaded-by-millions-still-on-android-market.ars">Android Trojans downloaded by millions, still on Android Market</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232500689/mcafee-announces-next-generation-of-mobile-security-software.html">McAfee Announces Next Generation Of Mobile Security Software</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/hiShig7HOJs/article.php">Keeping on top of financial malware</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/b2_AdDcnuvU/malware_news.php">Students used keyloggers on school computers, changed grades</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16757150">Botnet suspect denies involvement</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/RMhFOVVYoOI/pirate-party-of-catalonia-wants-to-sue-fbi-in-spain-over-megaupload-seizure.ars">Pirate Party of Catalonia wants to sue FBI, in Spain, over Megaupload seizure</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-31/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-30</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-30/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-30</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-30/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 13:59:13 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4568</guid>
		<description><![CDATA[InfoSec News for Monday January 30, 2012. 4 Sun journos, 1 cop bailed in police bung probeCuffed on suspicion of corruption after tip-off from News Corp: Police officers investigating allegations of illegal payments to cops as part of a larger probe of News International arrested four journalists on Saturday. All four were either current or [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Monday January 30, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/30/op_elveden_arrests_sun_and_cop/">4 Sun journos, 1 cop bailed in police bung probe</a><br />Cuffed on suspicion of corruption after tip-off from News Corp: Police officers investigating allegations of illegal payments to cops as part of a larger probe of News International arrested four journalists on Saturday. All four were either current or former hacks at Rupert Murdoch&#8217;s tabloid <cite>The Sun</cite>. Police also arrested a Metropolitan police service officer at the weekend.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/30/kelihos_suspect_denial/">Microsoft&#8217;s Kelihos kingpin suspect: It wasn&#8217;t me</a><br />Sabelnikov denies botnet herder allegation: The Russian man named by Microsoft as the mastermind behind the Kelihos botnet has stepped forward to plead his innocence.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/30/sky_users_get_google_privacy_email/">Google spews out &#8216;privacy&#8217; email to Sky punters too</a><br />Not just Virgin Media customers fuming over web giant&#8217;s intrusion: Sky users have joined Virgin Media subscribers in receiving emails directly from Google about its new privacy policy.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/29/quantum_key_schemes_vendor_mitm/">Quantum Trojans undermine security theory</a><br />Can dodgy vendors compromise uncrackable security?: A group of English and Canadian researchers has cast doubt on the nascent push to develop device-independent quantum cryptography standards, asserting that such schemes could be undermined by malicious vendors.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/27/students_hack_teachers_computers/">Students busted for hacking computers, changing grades</a><br />&#8216;Very bright kids&#8217; too bright for their own good: Three high school juniors have been arrested after they devised a sophisticated hacking scheme to up their grades and make money selling quiz answers to their classmates.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/kJYL_-9UpKg/Adscend_denies_Facebook_AG_allegations">Adscend denies Facebook, AG allegations</a><br />Adscend Media, the defendant in lawsuits filed this week by Facebook and the Washington attorney general, on Friday denied the allegations in the complaints and shifted blame to its affiliates.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/o8JFG3-pVjY/Hawaii_legislators_bid_aloha_to_controversial_data_retention_bill">Hawaii legislators bid aloha to controversial data retention bill</a><br />Lawmakers in Hawaii quietly dropped a bill that would have required Internet service providers to collect the browsing histories of Internet users in the state and store the data for at least two years.
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c411128/l/0Lnews0Btechworld0N0Csecurity0C33336340Cgoogle0Emicrosoft0Efacebook0Ebattle0Ephishing0Ewith0Enew0Especification0C0Dolo0Frss/story01.htm">Google, Microsoft and Facebook battle phishing with new specification</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/VTYYfYJpQ5k/malware_news.php">Bogus &#8220;browser update&#8221; pages deliver malware</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c4010b1/l/0Lnews0Btechworld0N0Csecurity0C33335530Csymantec0Eclaims0Elargest0Eever0Eandroid0Emalware0Efind0C0Dolo0Frss/story01.htm">Symantec claims largest ever Android malware find</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c4010b0/l/0Lnews0Btechworld0N0Csecurity0C33335560Clookout0Eclaims0Esymantec0Ecrying0Ewolf0Eover0Eandroid0Emalware0C0Dolo0Frss/story01.htm">Lookout claims Symantec crying wolf over Android malware</a>
</li>
<li><a href="http://www.ottawacitizen.com/technology/City+staff+review+private+messages/6070097/story.html">City staff to review private messages</a>
</li>
<li><a href="http://www.itnews.com.au/News/288489,twitter-buys-anti-malware-firm.aspx">Twitter buys anti-malware firm</a>
</li>
<li><a href="http://datalossdb.org/incidents/5544-curious-nurse-snooped-in-108-patients-files">&#8220;Curious&#8221; nurse snooped in 108 patients&#8217; files</a>
</li>
<li><a href="http://datalossdb.org/incidents/5548-a-hacker-aqcuired-a-a-small-portion-of-payment-firm-s-european-eft-business-according-to-sec-filing">A hacker aqcuired a &#8220;a small portion of payment firm&#8217;s European EFT business according to SEC filing</a>
</li>
<li><a href="http://datalossdb.org/incidents/5542-laptops-stolen-in-office-burglary-contained-some-clinical-and-demographic-information-as-well-as-some-social-security-numbers">Laptops stolen in office burglary contained some clinical and demographic information as well as some Social Security numbers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5547-personal-info-on-former-and-current-customers-exposed-on-the-internet-in-a-spreadsheet-that-contained-social-security-numbers">Personal info on former and current customers exposed on the Internet in a spreadsheet that contained Social Security numbers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5543-over-400-clients-records-but-no-financial-info-on-laptop-stolen-from-office">Over 400 clients&#8217; records (but no financial info) on laptop stolen from office</a>
</li>
<li><a href="http://www.itnews.com.au/News/288486,hawaiian-university-settles-data-breach-lawsuit.aspx">Hawaiian University settles data breach lawsuit</a>
</li>
<li><a href="http://datalossdb.org/incidents/5538-2-131-names-usernames-postal-and-e-mail-addresses-phone-numbers-and-encrypted-passwords-dumped-on-the-internet">2,131 names, usernames, postal and e-mail addresses, phone numbers, and encrypted passwords dumped on the Internet</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/q-gVC3uC6Y4/pro-government-hactivists-deface-al-jazeera-coverage-of-syrian-violence.ars">Pro-government hactivists deface Al Jazeera coverage of Syrian violence</a>
</li>
<li><a href="http://www.ottawacitizen.com/news/Hitler+painting+fetches+euros+Slovak+auction/6069117/story.html">Hitler painting fetches 32,000 euros in Slovak auction</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/5gtFHl5bBuE/">Android Counterclank Malware Assails Android Market: Symantec</a>
</li>
<li><a href="http://datalossdb.org/incidents/5525-boxes-full-of-2-000-personal-medical-records-including-names-addresses-phone-numbers-and-social-security-numbers-in-a-trash-can">Boxes full of 2,000 personal medical records including names, addresses, phone numbers and social security numbers in a trash can</a>
</li>
<li><a href="http://datalossdb.org/incidents/5527-student-used-an-application-on-his-cell-phone-to-hack-into-the-school-s-computer-network">Student used an application on his cell phone to hack into the school&#8217;s computer network</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/phmZVp2P7-A/">EU 24-Hour Data Breach Notification Rule &#8216;Unworkable&#8217;: ATandT Executive</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/3HsFMpZBYwA/">Sanctions against Iran may destabilize, topple regime by ratcheting up hassle factor: expert</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/UidjK0pcxwE/">Stealing the Titanic: Artifacts auction draws accusations of grave robbery</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012712-security-roundup-255424.html?source=nww_rss">Security roundup: The triumph of hactivists, the sorrow of Symantec</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012712-massive-android-malware-op-may-255443.html?source=nww_rss">Massive Android malware op may have infected 5 million users</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012812-lookout-security-rebuts-rivals-android-255450.html?source=nww_rss">Lookout Security rebuts rival&#8217;s Android malware claims</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/Rs2asp4U3yc/">Google Privacy Policy Update Challenged by Lawmakers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5524-customers-names-email-addresses-billing-and-shipping-addresses-telephone-numbers-credit-card-information-and-or-a-cryptographically-scrambled-passwords-exposed">Customers names, email addresses, billing and shipping addresses, telephone numbers, credit card information and/or a cryptographically scrambled passwords exposed</a>
</li>
<li><a href="http://datalossdb.org/incidents/5523-man-stole-numerous-customer-accounts-for-more-than-a-year">Man stole numerous customer accounts for more than a year</a>
</li>
<li><a href="http://datalossdb.org/incidents/5521-650-000-names-email-addresses-birth-dates-and-nutritional-data-due-to-hacked-database">650,000 names, email addresses, birth dates and nutritional data due to hacked database</a>
</li>
<li><a href="http://datalossdb.org/incidents/5522-2-257-social-security-numbers-of-living-veterans-was-mistakenly-released-to-ancestry-com-as-part-of-a-response-to-a-freedom-of-information-act-request">2,257 Social Security numbers of living veterans was mistakenly released to Ancestry.com as part of a response to a Freedom of Information Act request</a>
</li>
<li><a href="http://datalossdb.org/incidents/5518-hacker-able-to-view-every-member-s-personal-data-photos-pseudonyms-and-passwords">Hacker able to view every member&#8217;s personal data, photos, pseudonyms and passwords</a>
</li>
<li><a href="http://datalossdb.org/incidents/5517-7-000-full-customer-names-complete-addresses-dates-of-birth-social-security-numbers-gender-medicaid-identification-numbers-case-management-information-and-telephone-numbers">7,000 full customer names, complete addresses, dates of birth, Social Security numbers, gender, Medicaid identification numbers, case management information and telephone numbers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5516-fraudulent-purchases-made-with-information-from-dozens-of-locals-credit-and-debit-cards">Fraudulent purchases made with information from dozens of locals credit and debit cards</a>
</li>
<li><a href="http://datalossdb.org/incidents/5520-data-backup-file-held-by-vendor-was-accessed-by-an-intruder-included-user-names-email-addresses-and-passwords">Data backup file held by vendor was accessed by an intruder included user names, email addresses and passwords</a>
</li>
<li><a href="http://datalossdb.org/incidents/5515-391-current-and-former-hospital-employees-names-and-social-security-numbers-posted-on-website">391 current and former hospital employees names and Social Security numbers posted on website</a>
</li>
<li><a href="http://datalossdb.org/incidents/5514-8-000-social-security-numbers-and-some-credit-card-numbers-of-prospective-students-on-a-public-server">8,000 Social Security numbers and some credit card numbers of prospective students on a public server</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/latvian-securities-hacker/">SEC Goes After Online Trading Firms That Unwittingly Helped Latvian Hacker</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/27/commerce-or-chaos/">Commerce or chaos</a>
</li>
<li><a href="http://www.ottawasun.com/2012/01/27/anonymous-targets-mexican-websites">Anonymous targets Mexican websites</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/twitter-agent-of-the-censor/">Twitter Censorship Move Sparks Backlash: Is it Justified?</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/bUve0yRK6as/">FINRA advises brokers to bulk up security</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Jg07a9d-vxI/">Univ. of Hawaii settles with 98,000 over five breaches</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=fe769eac944cc73136d85ccd99ab027c">The Lede Blog: Twitter&#8217;s New Policy on Blocking Posts Is Attacked, and Defended</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=a65dfdf4e0ca1397cbb79bc66882a49b">White House Presses For New Cybersecurity Laws</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-27</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-27/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-27</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-27/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 13:59:15 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4566</guid>
		<description><![CDATA[InfoSec News for Friday January 27, 2012. Mr. Waledac: The Peter North of SpammingMicrosoft on Monday named a Russian man as allegedly the guy responsible for running the Kelihos botnet, a spam engine that infected an estimated 40,000 PCs. But closely held data seized from the world&#8217;s largest spam affiliate program suggests that the driving [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Friday January 27, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/t1-fO5Zuzfg/">Mr. Waledac: The Peter North of Spamming</a><br />Microsoft on Monday named a Russian man as allegedly the guy responsible for running the Kelihos botnet, a spam engine that infected an estimated 40,000 PCs. But closely held data seized from the world&#8217;s largest spam affiliate program suggests that the driving force behind Kelihos is a different individual who is still coordinating spam campaigns for hire.
<p>Kelihos shares a great deal of code with the infamous Waledac botnet, a far more pervasive threat that infected hundreds of thousands of computers and pumped out tens of billions of junk emails promoting shady online pharmacies. Despite the broad base of shared code between the two malware families, Microsoft classifies them as fundamentally different threats. The company used clever legal techniques to seize control over and shutter both botnets, sucker punching Waledac in early 2010 and taking out Kelihos last fall.</p>
<p>On Monday, Microsoft filed papers with a Virginia court stating that Kelihos was run by Andrey N. Sabelnikov, a St.</p>
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/tQJozpOxs2c/Lawmakers_question_Google_on_its_new_privacy_practices">Lawmakers question Google on its new privacy practices</a><br />Google&#8217;s decision this week to share user data across its online services has caught the attention of eight members of the U.S. House of Representatives, with the lawmakers asking whether the changes will compromise privacy.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/biAFzWFuHDI/Google_says_privacy_change_won_t_affect_government_users">Google says privacy change won&#8217;t affect government users</a><br />Google today dismissed concerns by a former senior federal IT official that its controversial new privacy policy would create problems for customers of Google Apps for Government.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/RTMMH9br6fU/European_Parliament_says_its_website_victim_of_DDOS_attack">European Parliament says its website victim of DDOS attack</a><br />The European Parliament&#8217;s website fell under a distributed denial-of-service attack on Thursday in what the organization classified as retaliation for the shutdown of the Megaupload file-sharing site and an anti-counterfeiting trade agreement.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/DzB6lO41vH0/European_Parliament_says_its_website_taken_offline_by_attackers">European Parliament says its website taken offline by attackers</a><br />The European Parliament&#8217;s website fell under a distributed denial-of-service attack (DDOS) on Thursday in what the organization classified as retaliation for the shutdown of the Megaupload file-sharing site and an anti-counterfeiting trade agreement.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/26/google_emails_virgin_media_subscribers/">Google emails Virgin Media subscribers &#8230; about privacy</a><br />Infuriated customers want to know how the Goog got their addresses: Fuming Virgin Media customers have taken to the telco&#8217;s forum to complain that their email addresses have been used by Google, instead of being kept private.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/26/sophos_fakeav_conficker/">Blackhole crimeware kit drives web threat spike</a><br />Report: Conficker also still causing mayhem: Fake anti-virus scams are on the wane but drive-by-download threats have rocketed over the past year thanks to the hugely popular Blackhole crimeware kit, while Conficker remains prolific some three years after its release, according to Sophos.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/2UwerMmVs9A/EU_regulators_drop_legal_case_after_UK_implements_ePrivacy_legislation">EU regulators drop legal case after UK implements ePrivacy legislation</a><br />European regulators have dropped a legal case against the United Kingdom over failure to implement ePrivacy laws saying that changes in UK legislation fixes the problems.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/pwn2own_2012/">Pwn2Own 2012 touts bigger prizes, drops mobile hacks</a><br />Make $60,000 with a few carefully injected bytes: Organisers of security conference CanSecWest have changed the rules for the next outing of its Pwn2Own computer hacking contest.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/o2_stop_phone_number_leak/">O2 3G stops giving punters&#8217; mobile numbers to websites</a><br />HTTP header blooper stamped out within hours after outcry: After a flurry of complaints, O2 engineers appear to have shut off the proxy server quirk that leaked to websites the phone numbers of punters browsing the net on 3G connections.
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/BQLDXZ2ZP7U/">Costa Concordia company offers $14,400 in compensation to cruise ship passengers</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012612-security-companies-255358.html?source=nww_rss">6 security companies to watch</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012612-are-you-at-risk-what-255369.html?source=nww_rss">Are You at Risk? What Cybercriminals Do With Your Personal Data</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012612-ftc-commissioner-talks-online-privacy-255387.html?source=nww_rss">FTC Commissioner Talks Online Privacy, Puts Data Brokers on Notice</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/hlEhn3avwy4/secworld.php">Protect sensitive data on Mac OS X, Windows and Linux</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/YhymgdSstfU/malware_news.php">Perplexing malware served on social welfare site</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c2e7c55/l/0Lnews0Btechworld0N0Csecurity0C33331780Czscaler0Elaunches0Efree0Elink0Emalware0Escanner0Ezulu0C0Dolo0Frss/story01.htm">Zscaler launches free link malware scanner Zulu</a>
</li>
<li><a href="http://www.ottawacitizen.com/news/Rockets+Pakistan+academy+near+Laden+home/6058756/story.html">Rockets hit Pakistan academy near bin Laden home</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/26/end-of-the-big-tv-package-era/">End of the Big TV package era</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/ridT3JOE2vM/">Verdasys Offers Enterprise Data Leak Protection as Managed Service</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/anonymous-welcome-glenn-beck/">Eight Reasons Anonymous Should Welcome Glenn Beck With Open Arms</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/symantec-source-code-hack/">Symantec: We Didnt Know in 2006 Source Code Was Stolen</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/xC5jphLkikU/">Google privacy policy changes raise concerns</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/bpcXKDPBsEQ/">Drones: Barack Obamas weapon of choice against terrorism</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_tech/~3/oov57sRt31Q/index.html">We&#8217;re losing control of our digital privacy</a>
</li>
<li><a href="http://www.ottawacitizen.com/technology/European+parliament+website+under+cyber+attack/6056344/story.html">European parliament website under cyber attack</a>
</li>
<li><a href="http://www.cbc.ca/news/canada/british-columbia/story/2012/01/26/bc-uvic-data-theft.html?cmp=rss">UVic hard drives recovered with thieves&#8217; note</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/O17mRoJU47c/">Study: BlackHole appears, Conficker remains</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/railroad-memo/">Railroad Association Says Hack Memo Was Inaccurate</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/kim-dotcom/">The Fast, Fabulous, Allegedly Fraudulent Life of Megauploads Kim Dotcom</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/yZ9I2ql6OUg/">EU 24-hour Data Breach Notification Rule Unworkable:` ATandT Executive</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/oLBKmnJbdq8/symantec-suspected-breach-in-2006-didnt-confirm-until-anonymous-revealed-source-code.ars">Symantec suspected Anonymous code breach back in 2006</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/26/wikipedia-and-orange-partner-to-bring-free-access-to-developing-world/">Wikipedia and Orange partner to bring free access to developing world</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/r2SWDnbnlSQ/malware_news.php">Malicious MIDI files lead to rootkit malware</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/A6F-fmEvV04/secworld.php">Web attacks peak at 38,000 an hour</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/t08xcOUHt38/">Catbird Unveils vSecurity 5.0 for Virtualized and Cloud Computing</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/osmjGS2jJ2A/">Google Centers Privacy Policies Around Google+</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-27/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-26</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-26/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-26</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-26/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 13:59:14 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4564</guid>
		<description><![CDATA[InfoSec News for Thursday January 26, 2012. Symantec&#8217;s profits up in calm third quarterGrowth in security and compliance keeps ship steady: CEO Enrique Salem stands crisp and smart on the poop deck of the good ship Symantec, looking back at a straight course and ahead to more growth. It&#8217;s a pretty unexciting third quarter story [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Thursday January 26, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/26/symantec_q3_fy2012/">Symantec&#8217;s profits up in calm third quarter</a><br />Growth in security and compliance keeps ship steady: CEO Enrique Salem stands crisp and smart on the poop deck of the good ship Symantec, looking back at a straight course and ahead to more growth. It&#8217;s a pretty unexciting third quarter story really.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/R4EUVV4QO-E/Google_stirs_up_privacy_hornet_s_nest">Google stirs up privacy hornet&#8217;s nest</a><br />Google has whipped up a privacy brouhaha with a blog post announcing that the company is rewriting its privacy policy, consolidating user information across its services.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/bk56xih3Cvc/Threatened_by_Anonymous_Symantec_tells_users_to_pull_pcAnywhere_s_plug">Threatened by Anonymous, Symantec tells users to pull pcAnywhere&#8217;s plug</a><br />Symantec this week told users of its pcAnywhere remote access software to disable or uninstall the software while it fixes an unknown number of bugs.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/TrZO4iaY0Pc/Accused_Kelihos_botmaster_s_former_employer_angered_at_revelation">Accused Kelihos botmaster&#8217;s former employer &#8216;angered&#8217; at revelation</a><br />A security-related company that until late December employed the Russian developer who allegedly created the Kelihos botnet said today it was &#8216;extremely disappointed and angered&#8217; at the revelation.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/VfOBfqL796Y/Final_phase_of_Mass._data_protection_law_kicks_in_March_1">Final phase of Mass. data protection law kicks in March 1</a><br />All companies storing personal data on Massachusetts residents have until March 1 to ensure that their contractors, suppliers, technology providers and other third parties comply with a new provision of the state&#8217;s data breach law.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/QsLUBgG-cQI/IT_pros_say_data_breach_assessment_is_more_valuable_than_notification_study_says">IT pros say data breach assessment is more valuable than notification, study says</a><br />IT professionals believe that assessing the potential harm caused by data breaches is more useful to mitigating the effects of such incidents than notifying affected individuals, according to a survey published on the day the European Union&#8217;s proposed a 24-hour deadline for data breach disclosures.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/o2_number_sharing/">Why O2 shared your mobile number with the world</a><br />And why they&#8217;ll probably do similar again: O2 has been sharing customers&#8217; phone numbers with every website they visited, but O2 isn&#8217;t the only offender &#8211; it&#8217;s just the one that slipped up and got caught.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/opireland_sopa_anonymous/">OpIreland hackers spank gov sites as &#8216;Irish SOPA&#8217; nears</a><br />Angry hacktivists land on Irish shores: Anonymous took out several key Irish government websites last night and promised more disruption to come in retaliation for new SOPA-like legislation which it claimed would make it easier for copyright-holders to block access to file sharing and other sites in the country.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/pcanywhere_patch/">pcAnywhere let anyone anywhere inject code into PCs</a><br />Symantec plugs holes in desktop remote-control tool: Symantec is urging users to patch pcAnywhere, its remote control application, following the discovery of a brace of serious security flaws.
</li>
<li><a href="http://business.financialpost.com/2012/01/26/is-google-evil-not-really/">Is Google evil? Not really</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/T4yHajlFWe4/secworld.php">User error is the biggest threat on the Internet</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012512-2011-eventful-year-for-mac-255312.html?source=nww_rss">2011 &#8216;eventful year for Mac malware&#8217;</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012512-intego-2011-offered-bumper-crop-255308.html?source=nww_rss">Intego: 2011 offered bumper crop of Mac malware</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012512-critics-eus-proposed-data-protection-255320.html?source=nww_rss">Critics: EU&#8217;s proposed data protection rules could hinder Internet</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c26635f/l/0Lnews0Btechworld0N0Csecurity0C33328460Cdata0Ebreach0Eharm0Eassessment0Emore0Eimportant0Ethan0Etelling0Evictims0C0Dolo0Frss/story01.htm">Data breach harm assessment &#8216;more important than telling victims&#8217;</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/PkEFYaoCrO8/malware_news.php">Malicious QR codes and the persistence of rootkits</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c2627c7/l/0Lreview0Btechworld0N0Csecurity0C33326740Csophos0Eendpoint0Eanti0Evirus0E10A0Ereview0C0Dolo0Frss/story01.htm">Sophos Endpoint Anti-Virus 10 review</a>
</li>
<li><a href="http://datalossdb.org/incidents/5512-1-8-million-customers-social-security-numbers-dates-of-birth-and-in-some-cases-financial-institution-account-numbers-compromised">1.8 million customers Social Security numbers, dates of birth and, in some cases, financial institution account numbers compromised</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/CZ62K-CAUkY/">Symantec Warns pcAnywhere Users to Disable Tool Due to Source Code Theft</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/CiGtoaaWaMM/eu-proposes-a-right-to-be-forgotten.ars">Europe proposes a &#8220;right to be forgotten&#8221;</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/anonymous-internationalist/">Anonymous Goes After World Governments in Wake of Anti-SOPA Protests</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/PNx9BvM4Qm8/">Attackers Using DNS Poisoning to Hijack Website Domains, Divert Traffic</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/OTPQFi-kHDA/">Secret Government Talks Create Treaty Stricter Than SOPA, PIPA</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/bL_xG1ldxcM/symantec-says-anonymous-stole-source-code-tells-customers-to-disable-security-product.ars">Symantec: Anonymous stole source code, users should disable pcAnywhere</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/i85HDnDxme8/">EU Proposed New Data Privacy Laws to Impact U.S. Internet Giants</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/hHn4nUzCQYs/us-has-already-flexed-cyberwar-muscle-says-former-nsa-director.ars">US has already flexed cyberwar muscle, says former NSA director</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/R6V8sIKDxkw/blackhole-dominates-web-malware-attacks-says-sophos.ars">&#8220;Blackhole&#8221; toolkit dominates Web malware attacks, says Sophos</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/Ub8sf_afHcc/">Google Privacy Policies Rile Users, Regulators With Zero Opt-Out</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/ZrmpbJ3YibQ/">Harper to tout capitalism, Canadian oil at World Economic Forum</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/At3rw6IZnJA/">Symantec admits stolen source code impacts pcAnywhere</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/IRejxCVYx_c/">Symantec admits stolen source code impacts pcAnywhere users</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/scotus-gps-analysis/">Legality of Mobile Phone Tracking Still Unclear Despite Supreme Court GPS Decision</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/25/qnx-rims-last-hope/">QNX: RIMs last hope?</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/bail-kim-dotcom/">Bail Denied for Megauploads Kim Dotcom</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/i74fwLwMLMI/">SCADA Systems in Railways Vulnerable to Attack</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012512-are-cios-championing-consumer-255292.html?source=nww_rss">Are CIOs Championing Consumer Tech?</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012512-it-pros-believe-data-breach-255301.html?source=nww_rss">IT pros believe data breach harm assessment is more valuable than victim notification, study says</a>
</li>
<li><a href="http://www.darkreading.com/security-services/167801101/security/news/232500458/firehost-s-european-based-secure-cloud-hosting-services-go-live.html">FireHost&#8217;s European-Based Secure Cloud Hosting Services Go Live</a>
</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232500459/sophos-reveals-assessment-on-threat-landscape-in-security-threat-report-2012.html">Sophos Reveals Assessment On Threat Landscape In Security Threat Report 2012</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232500461/dome9-unveils-industry-first-multi-cloud-security-groups.html">Dome9 Unveils Industry First Multi-Cloud Security Groups</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232500462/mobile-marketing-association-releases-final-privacy-policy-guidelines-for-mobile-apps.html">Mobile Marketing Association Releases Final Privacy Policy Guidelines For Mobile Apps</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=79d21454bcf08dbd12c122bb848f4df1">7 Tools To Tighten Healthcare Data Security</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=99bb50d5d8a7adbdeebfd7cbb697c6d4">Microsoft Names Alleged Kelihos Botnet Operator</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/vnF3MGgyuwQ/">Anonymous Cons Web Users Into Joining DDoS Attacks With Camouflaged Links</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/EqWsQKgDPCc/">DreamHost, T-Mobile Data Breaches Compromise User Passwords</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/tfem9hAM-cU/">Security Best Practices Reduce Downtime From Cyber-Attacks: Survey</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c2121e9/l/0Lnews0Btechworld0N0Csecurity0C33326730Capple0Emalware0Ebecame0Emore0Esophisticated0Ein0E20A110C0Dolo0Frss/story01.htm">Apple malware became more sophisticated in 2011</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/9HYRejmvvns/malware_news.php">&#8220;Frankenmalware&#8221; active in the wild</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/y_j3XNLGqB4/">Megauploads Kim Dotcom displays mischievous sense of humour</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/ZVXXlmnfjdU/">As Libya victory high ends, claims of violence and torture escalate</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-26/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-25</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-25/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-25</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-25/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 14:01:50 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4562</guid>
		<description><![CDATA[InfoSec News for Wednesday January 25, 2012. Thank you Chris DoddThe web is buzzing with contempt over a statement by Motion Picture Association of America (MPAA) Chairman and CEO Chris Dodd to Fox last Thursday: &#8220;Those who count on quote &#8216;Hollywood&#8217; for support need to understand that this industry is watching very carefully who&#8217;s going [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Wednesday January 25, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://jacksch.com/2012/01/thank-you-chris-dodd/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=thank-you-chris-dodd">Thank you Chris Dodd</a><br />The web is buzzing with contempt over a statement by Motion Picture Association of America (MPAA) Chairman and CEO Chris Dodd to Fox last Thursday: &#8220;Those who count on quote &#8216;Hollywood&#8217; for support need to understand that this industry is watching very carefully who&#8217;s going to stand up for them when their job is at [...]
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/fMe1XEOVG00/Proposed_EU_data_protection_rules_include_right_to_be_forgotten">Proposed EU data protection rules include right to be forgotten</a><br />New proposals for Europe&#8217;s data-protection law would see companies facing fines of up to 2% of their global turnover if they breach the rules.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/europe_data_protection_proposal/">Reding&#8217;s &#8216;right to be forgotten&#8217; bill polarises Euro biz world</a><br />Rewriting data protection law in internet age: EU Justice Commissioner Viviane Reding will imminently table a draft bill that will if passed in Parliament require internet firms to be upfront about the user data they hold.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/frankenmalware/">Super-powered &#8216;frankenmalware&#8217; strains detected in the wild</a><br />Virus-worm crossbreeds will trash systems faster than ever before: Viruses are accidentally infecting worms on victims computers, creating super-powered strains of hybrid software nasties.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/25/mckinnon_case_back_in_court/">Judges probe minister&#8217;s role in McKinnon extradition saga</a><br />Pentagon hacker&#8217;s medical files ignored: The long-running case of Gary McKinnon returns to court on Friday.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/hu5K7ZMLh9o/Google_to_combine_users_data_across_its_services">Google to combine users&#8217; data across its services</a><br />Google will be able to combine data from several Google services when a Google Accounts user is signed in, as part of a rewritten set of privacy policies that the company announced on Tuesday.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/24/nokia_stalks_own_customers/">Nokia busted for dodgy SMS to customers</a><br />Spam Act breach draws $AU55k wrist-slap: Nokia has fallen foul of the Australian Communications and Media Authority, incurring a $AU55,000 fine following consumer complaints over its SMS marketing practices.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/24/antisec_sopa_acta_hack/">US govt security advice site trashed by hackers</a><br />Hacktivist campaign against SOPA, PIPA and ACTA continues: Anonymous and LulzSec members have hacked US government security web site OnGuard Online and defaced it, forcing it offline, in retaliation for the recent MegaUpload takedown and the controversial Anti-Counterfeiting Trade Agreement (ACTA), the groups have announced.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/kbm5DeT0WHc/Accused_Kelihos_botnet_maker_worked_for_two_security_firms">Accused Kelihos botnet maker worked for two security firms</a><br />A Russian man who was accused Monday by Microsoft of creating the Kelihos botnet worked for a pair of security-related firms from 2005 to 2011, according to evidence on the Web.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/6of94-_lJ7E/Microsoft_names_alleged_Kelihos_botnet_creator">Microsoft names alleged Kelihos botnet creator</a><br />Microsoft has named a Russian man as the alleged creator of Kelihos, a spammy botnet that abused the company&#8217;s Hotmail service until the botnet was shutdown last September.
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=de57ba1661420be34c49740e0e0b6adb">9 Ways To Minimize Data Breach Fallout</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/BKY8PHsQuXA/secworld.php">Searching for Google Chrome can lead to malicious content</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120125-hackers-attack-u-s-railways">Hackers attack U.S. railways</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/FWLNLszqg8g/malware_news.php">Carberp Trojan targets French broadband subscribers</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/5pNACDE9fF4/were-just-like-youtube-megaupload-lawyer-tells-ars.ars">&#8220;We&#8217;re just like YouTube,&#8221; Megaupload lawyer tells Ars</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/24/torontos-audiobooks-com-launches-all-you-can-hear-cloud-streaming/">Torontos Audiobooks.com launches all-you-can-hear cloud streaming</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/bJao5UseOl8/">EU Poised to Propose 24-Hour Breach Notification, Data Privacy Rules</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/lcvSn6whGp8/">Twitter Acquires Dasient for Anti-Malvertising Security Technology</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/O-gJkFAUAps/">Twitter acquires web malware fighter Dasient</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/IdSoO1S-Mhs/">Appeals court clears way for look at divorce application of Russell Williams wife</a>
</li>
<li><a href="http://www.thestar.com/news/canada/article/1120667--posting-personal-information-online-could-backfire-privacy-commissioner-warns-young-canadians">Posting personal information online could backfire, privacy commissioner warns young Canadians</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232500408/fluke-rolls-out-new-threat-signatures-released-to-protect-against-wireless-attacks.html">Fluke Rolls Out New Threat Signatures Released To Protect Against Wireless Attacks</a>
</li>
<li><a href="http://www.thestar.com/news/canada/article/1120667--posting-personal-information-online-could-backfire-privacy-commissioner">Posting personal information online could backfire: privacy commissioner</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/00EsaP76gkU/">Microsoft names Russian man in Kelihos botnet suit</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/x2rduxwEi_Q/">Security Best Practices Reduce Downtime from Cyber-Attacks: Survey</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/KUiU1k1B9uE/">Microsoft Names Developer, Operator of Kelihos Botnet</a>
</li>
<li><a href="http://www.ottawacitizen.com/news/Ontario+court+clears+look+divorce+application+killer+Williams+wife/6044573/story.html">Ontario court clears way for look at divorce application of sex-killer Williamss wife</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/N7BmpjFksPw/secworld.php">Hacker allegedly leaks 100K Facebook account credentials of Arab users</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/railyway-hack/">Hackers Breached Railyway Network, Disrupted Service</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/gn5HfE0MU7U/">Google+ Supports Most Nicknames, Only Some Pseudonyms</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/8bOYlSM0BYU/kelihos-botnet-creator-worked-for-antivirus-company-microsoft-says.ars">Kelihos botnet creator worked for antivirus company, Microsoft says</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/Kxf7ABoo_Z0/">Mitt Romney releases tax numbers: US$6.2M owed on US$42.5M earned in 2010, 2011</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-25/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thank you Chris Dodd</title>
		<link>http://jacksch.com/2012/01/thank-you-chris-dodd/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=thank-you-chris-dodd</link>
		<comments>http://jacksch.com/2012/01/thank-you-chris-dodd/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 15:00:38 +0000</pubDate>
		<dc:creator>Eric Jacksch</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Stupidity]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4560</guid>
		<description><![CDATA[The web is buzzing with contempt over a statement by Motion Picture Association of America (MPAA) Chairman and CEO Chris Dodd to Fox last Thursday: &#8220;Those who count on quote &#8216;Hollywood&#8217; for support need to understand that this industry is watching very carefully who&#8217;s going to stand up for them when their job is at [...]]]></description>
			<content:encoded><![CDATA[<p>The web is buzzing with contempt over a statement by Motion Picture Association of America (MPAA) Chairman and CEO Chris Dodd to Fox last Thursday:</p>
<blockquote><p>&#8220;Those who count on quote &#8216;Hollywood&#8217; for support need to understand that this industry is watching very carefully who&#8217;s going to stand up for them when their job is at stake. Don&#8217;t ask me to write a check for you when you think your job is at risk and then don&#8217;t pay any attention to me when my job is at stake.&#8221;</p></blockquote>
<p>As pointed out on the <a href="http://www.mpaa.org/about/ceo" target="_blank">MPAA web site</a>, Dodd is also a former US Senator from Connecticut. Surely he understood the implications of publicly confirming what we have always expected &#8212; that Hollywood spends a lot of money on politicans and expects a return on their investments. Rather than condemn him, perhaps we should be thanking him for putting this out in the open.</p>
<p>The movie industry, like many others, is facing a harsh new reality &#8212; one that, for the most part, they appear to be in denial about. Pushing for draconian, ill-informed legislation such as the Stop Online Piracy Act (SOPA) and the Protect IP Act isn&#8217;t the solution. Perhaps it&#8217;s time that Hollywood stop trying to purchase politicians and apply some creativity to their business model instead.</p>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/thank-you-chris-dodd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-24</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-24/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-24</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-24/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 13:59:26 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4556</guid>
		<description><![CDATA[InfoSec News for Tuesday January 24, 2012. Microsoft: Worm Operator Worked at Antivirus FirmIn a surprise filing made late Monday, Microsoft said a former technical expert at a Russian antivirus firm was the lead person responsible for operating the Kelihos botnet, a global spam machine that Microsoft dismantled in a coordinated takedown last year. Supreme [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Tuesday January 24, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/KzS-H8GwBz8/">Microsoft: Worm Operator Worked at Antivirus Firm</a><br />In a surprise filing made late Monday, Microsoft said a former technical expert at a Russian antivirus firm was the lead person responsible for operating the Kelihos botnet, a global spam machine that Microsoft dismantled in a coordinated takedown last year.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/owfpsrEz1g4/Supreme_Court_GPS_ruling_called_a_win_for_privacy">Supreme Court GPS ruling called a win for privacy</a><br />Calling it a victory for privacy rights, civil rights advocates hailed a U.S. Supreme Court ruling that requires law enforcement officials to obtain a search warrant before they can attach a GPS tracking device to a vehicle.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/24/council_contract/">Councils tout 1.2bn for IT whizkid to grab their backend</a><br />Outsourced IT includes crim record checks and payroll: A one-billion-pound contract is up for grabs as three London councils hunt for IT hotshots to streamline their back-office systems &#8211; handling everything from criminal record checks and financial accounts to the payroll and psychometric testing.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/senator_grassley_twitter_crack/">US Senator&#8217;s Twitter account back after hack</a><br />Anti-SOPA activists play &#8216;occupy @ChuckGrassley&#8217;: The office of US Senator Chuck Grassley has confirmed that his Twitter account was taken over and used to launch anti-SOPA messages on Monday, US time.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/Pw2oa_fhvRo/Google_ups_ante_for_Chrome_hack_at_revamped_Pwn2Own">Google ups ante for Chrome hack at revamped Pwn2Own</a><br />The sponsor of the annual Pwn2Own hacking contest has dramatically revamped the challenge and will be awarding a first prize of $60,000 this year, four times 2011&#8242;s top reward.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/lLKBlog44KQ/Researcher_traces_Gameover_malware_to_maker_of_Zeus">Researcher traces &#8216;Gameover&#8217; malware to maker of Zeus</a><br />The &#8216;Gameover&#8217; malware that the FBI warned about earlier this month is a preview of the next version of the even-more-notorious Zeus money-stealing Trojan, a security researcher said today.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/UmJdzzjLEWY/Supreme_Court_GPS_tracking_needs_court_warrant">Supreme Court: GPS tracking needs court warrant</a><br />U.S. law enforcement agents need court-approved warrants to track a suspect&#8217;s whereabouts using a GPS device, the U.S. Supreme Court said Monday, in deciding a burning issue where privacy intersects with modern technology.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/sourcefire_anti_malware/">Sourcefire jumps into anti-malware market</a><br />Cyber-outbreak defence tech to shore up big biz: Sourcefire, the security biz behind the commercial versions of the open-source Snort intrusion-detection software, is bowling itself at enterprises and touting tech designed to quickly detect and block malware outbreaks.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/mxXlR8I0qqs/DreamHost_resets_passwords_after_database_breach">DreamHost resets passwords after database breach</a><br />Los Angeles-based Web hosting firm DreamHost reset the FTP and shell access passwords for all of its customers on Friday after detecting unauthorized activity within one of its databases.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/android_marketplace/">Android hackers mull rooted mobe app marketplace</a><br />As if things weren&#8217;t complicated enough: Android hackers are discussing the creation of a specialist app store, listing software for rooted handsets and other things that even Google won&#8217;t allow.
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16700192">Microsoft names botnet &#8216;suspect&#8217;</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c172c23/l/0Lnews0Btechworld0N0Csecurity0C33322740Cmicrosoft0Eaccuses0Erussian0Eof0Emasterminding0Ekelihos0Ebotnet0C0Dolo0Frss/story01.htm">Microsoft accuses Russian of masterminding Kelihos botnet</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012312-sourcefire-antimalware-255213.html?source=nww_rss">Sourcefire debuts anti-malware software FireAMP for enterprise</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012412-twitter-acquires-antimalware-company-255229.html?source=nww_rss">Twitter acquires antimalware company Dasient</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/xJroAJ3Mw5k/malware_news.php">Kelihos malware author, botnet herder named by Microsoft</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/SNzzbkouJvM/malware_news.php">Unique Web malware hosts increase</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/10000-control-systems-online/">10K Reasons to Worry About Critical Infrastructure</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c153477/l/0Lnews0Btechworld0N0Csecurity0C33321310Cgameover0Emalware0Eis0Enext0Egen0Ezeus0Etrojan0C0Dolo0Frss/story01.htm">&#8216;Gameover&#8217; malware is next-gen Zeus trojan</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c157367/l/0Lnews0Btechworld0N0Csecurity0C3332130A0Csourcefire0Eshows0Ecloud0Ebased0Emalware0Etracker0Efireamp0C0Dolo0Frss/story01.htm">Sourcefire shows cloud-based malware tracker FireAMP</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=a1301aa28d4dae97567059e849e13dbc">Europe Weighs a Tough Law on Online Privacy and User Data</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/judge-orders-laptop-decryption/">Judge Orders Defendant to Decrypt Laptop</a>
</li>
<li><a href="http://www.ottawacitizen.com/news/officer+charged+over+classified+leaks/6038385/story.html">Ex-CIA officer charged over classified leaks</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/klyc3vombro/">Dreamhost, T-Mobile Data Breaches Compromise User Passwords</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/CXIdFTS7mMg/">Ex-CIA officer charged with leaking classified information to journalists</a>
</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232500318/yubico-reports-2011-record-growth-outlook-for-2012.html">Yubico Reports 2011 Record Growth, Outlook For 2012</a>
</li>
<li><a href="http://www.darkreading.com/smb-security/167901073/security/news/232500319/bb-t-payment-solutions-offers-free-data-security-webinar-for-small-business-owners.html">BB&amp;T Payment Solutions Offers Free Data Security Webinar For Small Business Owners</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232500321/watchdox-introduces-secure-annotation-collaboration-for-ipad-iphone.html">WatchDox Introduces Secure Annotation, Collaboration For iPad, iPhone</a>
</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232500322/packet-plus-introduces-interactive-networking-stack-debugger.html">Packet Plus Introduces Interactive Networking Stack Debugger</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/8XapdwiITvc/more-megaupload-fallout-fileserve-shutters-file-sharing-service.ars">More Megaupload fallout: FileServe shutters file-sharing service</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/fXhjLGZBn-Y/">How exactly did Megaupload work before it got shut down?</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/qqnxLp5neEE/">Arab Facebook logins posted by Israeli hacker</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/videoconferencing-hijacked/">I Spy Your Companys Boardroom</a>
</li>
<li><a href="http://www.ottawacitizen.com/Former+official+charged+with+intelligence+leaks/6038385/story.html">Former CIA official charged with intelligence leaks</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/23/polar-mobile-closes-6m-funding-round/">Polar Mobile closes $6M funding round</a>
</li>
<li><a href="http://www.thestar.com/news/world/article/1119882--former-cia-agent-charged-with-leaking-classified-secrets-to-reporters">Former CIA agent charged with leaking classified secrets to reporters</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/WHh1oO3m-Wo/secworld.php">Researchers demonstrate tragic state of SCADA security</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012312-dreamhost-resets-customer-ftp-passwords-255176.html?source=nww_rss">DreamHost resets customer FTP passwords following database breach</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012312-do-you-need-a-255187.html?source=nww_rss">Do you need a cyberumbrella?</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/MNVU2m9Cdj0/">Anonymous Cons Web Users Into Joining DDoS Attacks with Camouflaged Links</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/-R8iIZeIvYg/">DSKHuffington Post launches new website in France</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232500292/sourcefire-rolls-out-fireamp-for-blocking-advanced-malware-utilizing-big-data-analytics.html">Sourcefire Rolls Out FireAMP For Blocking Advanced Malware Utilizing Big Data Analytics</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/CmhixphtJN0/">Costa Concordia captain passes drug test as more bodies found in wreckage</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/rEUgK0g4J0s/malware_news.php">Advanced malware protection with Sourcefire FireAMP</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/scotus-gps-ruling/">Warrants Needed for GPS Monitoring, Supreme Court Rules</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/CwF9VsFAsKE/">Consta Concordia captain passes drug test as more bodies found in wreckage</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=f6c28063e7da1f2a848cd4c610e201ff">FireAMP Fights Malware with Big Data Analytics</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-24/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-23</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-23/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-23</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-23/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 13:59:19 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4554</guid>
		<description><![CDATA[InfoSec News for Monday January 23, 2012. Citadel Trojan Touts Trouble-Ticket SystemUnderground hacker forums are full of complaints from users angry that a developer of some popular banking Trojan or bot program has stopped supporting his product, stranding buyers with buggy botnets. Now, the proprietors of a new ZeuS Trojan variant are marketing their malware [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Monday January 23, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/GcdI2q8cBPY/">Citadel Trojan Touts Trouble-Ticket System</a><br />Underground hacker forums are full of complaints from users angry that a developer of some popular banking Trojan or bot program has stopped supporting his product, stranding buyers with buggy botnets. Now, the proprietors of a new ZeuS Trojan variant are marketing their malware as the first offering that lets customers file bug reports, suggest and vote on new features in upcoming versions, and track trouble tickets that can be worked on by the developers and fellow users alike.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/sharepoint_leaky_security/">SharePoint gods peek into colleagues&#8217; info poll</a><br />Security is for other people: SharePoint admins are abusing their privileged status to sneak a peak at classified documents according to a poll that shows consistent abuse of security in Microsoft&#8217;s business collaboration server.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/itv_slapped/">ITV wrist-slapped for showing video game as IRA attack</a><br />Fined for Youtube rip and bungled riot coverage: ITV has escaped a fine for using video game footage to illustrate IRA activities, and portraying the wrong riot, but will tighten up procedures to stop it happening again.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/dreamhost_breach/">DreamHost nightmare attack sparks passwords reset</a><br />Hackers inappropriately touched customer database: US-based hosting firm DreamHost is advising customers to change their passwords following a database breach.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/israeli_hacking_followup/">&#8216;Hannibal&#8217; leaks &#8217;100,000 Facebook logins&#8217;</a><br />Then demands Middle East cyber-war truce: The tit for tat between pro-Palestinian and pro-Israel hackers escalated at the weekend after a hacker called Hannibal claimed to have leaked the Facebook login details of &#8220;100,000 Arabs&#8221;.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/europe_data_protection_proposed_revision/">Europe exposes its stiff data protection law this week</a><br />Time for Facebook, Google et al to lobby hard: Stringent proposals for the revision of Europe&#8217;s outdated 1995 data protection law are to be revealed by officials this coming Wednesday.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/23/romanian_nasa_hacker_jailed/">Romanian who hacked NASA spared cooler stint</a><br />If you can&#8217;t do the time, well, do the crime anyway: A Romanian hacker who admitted breaking into NASA&#8217;s network has avoided jail, receiving a three-year suspended prison sentence instead.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/5x8cTJZq6uM/Anonymous_dupes_users_into_joining_Metaupload_attack">Anonymous dupes users into joining Metaupload attack</a><br />The Anonymous hacking group recruited unwitting accomplices in Thursday&#8217;s attacks against U.S. government sites, a security researcher said today.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/k2RW8gmEUOI/Researchers_expose_flaws_in_popular_industrial_control_systems">Researchers expose flaws in popular industrial control systems</a><br />Researchers showcased unpatched security flaws in software used to control critical industrial systems by oil, gas, water and electrical distribution plants at the 2012 SCADA Security Scientific Symposium (S4) on Thursday.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/jxvYSLbZ4jA/malware_news.php">Tax-themed spam delivers malware</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c0f7353/l/0Lnews0Btechworld0N0Csecurity0C333190A30Ceu0Eenforce0E240Ehour0Edata0Ebreach0Edisclosure0C0Dolo0Frss/story01.htm">EU to enforce 24-hour data breach disclosure</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/uDNZWtY_XrE/secworld.php">Tool used in Anonymous Megaupload campaign</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120123-gao-critical-infrastructure-operators-need-more-coherent-regulations">GAO: critical infrastructure operators need more coherent regulations</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1c0c6b81/l/0Lnews0Btechworld0N0Csecurity0C33316450Cscada0Eindustrial0Econtrol0Esystems0Eexposed0Eby0Esecurity0Eresearchers0C0Dolo0Frss/story01.htm">SCADA industrial control systems exposed by security researchers</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/22/thorsten-heins-to-take-over-as-rim-ceo-as-mike-lazaridis-jim-balsillie-step-down/">Thorsten Heins to take over as RIM CEO as Mike Lazaridis, Jim Balsillie step down</a>
</li>
<li><a href="http://datalossdb.org/incidents/5510-unauthorized-access-to-a-database-server-exposes-unencrypted-customer-passwords-including-ftp-shell-and-email-accounts">Unauthorized access to a database server exposes unencrypted customer passwords including FTP/shell and email accounts</a>
</li>
<li><a href="http://datalossdb.org/incidents/5509-email-addresses-system-login-information-and-other-unknown-data-stolen-from-virus-infected-computer-after-employee-involved-in-h-ii-transfer-vehicle-project-opens-malicious-e-mail-attachment">Email addresses, system login information and other unknown data stolen from virus-infected computer after employee involved in H-II Transfer Vehicle project opens malicious e-mail attachment</a>
</li>
<li><a href="http://www.itnews.com.au/News/287862,data-breach-resolution-the-first-24-hours.aspx">Data breach resolution: the first 24 hours</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/0Vh7aCYQ-6w/">Megauploads high-profile defense lawyer Robert Bennett withdraws from piracy case</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/H7Omezj0H7s/">Internet policing and copyright protection must be in balance: EU</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/Zv-BEQXFC6Y/">Kim Dotcom, Megaupload founder, claims he is smarter than Bill Gates</a>
</li>
<li><a href="http://datalossdb.org/incidents/5508-124-410-names-dates-of-birth-e-mail-addresses-phone-numbers-and-md5-passwords-dumped-on-internet">124,410 names, dates of birth, e-mail addresses, phone numbers, and MD5 passwords dumped on Internet</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/uPd2w0Yrlrg/">Costa Concordia captain denies delaying alarm, allegedly admits he messed up</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/F6JBDR6mKuU/">Megauploads Kim Dotcom barricaded himself in mansion: police</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012012-anonymous-dupes-users-into-joining-255143.html?source=nww_rss">Anonymous dupes users into joining Megaupload attack</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012012-security-roundup-255148.html?source=nww_rss">Security roundup: Anonymous attacks DOJ, RIAA sites; Israeli-Palestinian cyberconflict escalates</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/9QOWEwIsJt4/">Alleged spy Jeffrey Delisle fed misinformation to fool Russians: source</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/0s9SYiyo8LI/">FBI Megupload Shutdown Cuts Off Uses From Personal Files, Business Data</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/20/fp-letters-to-the-editor-stupid-over-sopa/">FP Letters to the Editor: Stupid over SOPA</a>
</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232500248/version-8-3-of-astaro-security-gateway-brings-utm-to-the-cloud.html">Version 8.3 Of Astaro Security Gateway Brings UTM To The Cloud</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232500249/avira-partners-with-secure-me-to-offer-facebook-protection.html">Avira Partners With Secure.me To Offer Facebook Protection</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232500247/nq-mobile-launches-mobile-security-v6-0-for-android.html">NQ Mobile Launches Mobile Security V6.0 For Android</a>
</li>
<li><a href="http://www.darkreading.com/advanced-threats/167901091/security/news/232500245/suits-and-spooks-anti-conference-aims-to-redefine-security.html">Suits And Spooks Anti-Conference Aims to Redefine Security</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/Vh6VwHKFSYA/">Meet Kim Dotcom, king of Megauploads media empire</a>
</li>
<li><a href="http://www.darkreading.com/smb-security/167901073/security/news/232500232/qualys-launches-new-freemium-web-security-service-for-smbs.html">Qualys Launches New Freemium Web Security Service For SMBs</a>
</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232500233/trend-micro-marks-2011-the-year-of-data-breaches.html">Trend Micro Marks 2011 &#8220;The Year Of Data Breaches&#8221;</a>
</li>
<li><a href="http://www.darkreading.com/database-security/167901020/security/news/232500235/sharepoint-users-develop-insecure-habits.html">SharePoint Users Develop Insecure Habits</a>
</li>
<li><a href="http://www.darkreading.com/security-services/167801101/security/news/232500236/prolexic-enhances-portal-to-provide-customers-with-more-insight-into-ddos-threats-and-mitigation.html">Prolexic Enhances Portal to Provide Customers With More Insight Into DDoS Threats And Mitigation</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/anons-rickroll-botnet/">Anons Tricked Bystanders into Joining Attack on DoJ</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/mjzVcq22jwA/">Mystery woman Domnica Cemortan says shes ready to testify in defence of Costa Concordia captain</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/cScRlMbSQW0/">Stephen Colberts Hermain Cain antics rankle South Carolina Democrats</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/K6TlKvj2AwI/">Anonymous shutters government, music industry sites</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232500210/alcatel-lucent-and-arbor-networks-team-up-in-the-fight-against-denial-of-service-attacks.html">Alcatel-Lucent and Arbor Networks Team Up In The Fight Against &#8216;Denial-Of-Service&#8217; Attacks</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/YKl_TlHKB5c/secworld.php">McAfee closes spam-spewing hole in its anti-malware service</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/XobcBqXM48s/secworld.php">Programmer steals US government software source code</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/NpH8GSzKjAY/secworld.php">Megaupload shuttered, founders arrested, Anonymous retaliates with DDoS attacks</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=8e62049b84919fb761a447dcf05c1740">Has Anonymous Crossed the Line with MegaUpload.com Retaliation?</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/jinaeCr_crs/">PIPA postponed: Harry Reid delays senate vote on anti-piracy bill</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/309X1mpodrw/">Costa Concordia captain cried like a baby after the crash; rescue operations suspended amid choppy seas</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/pipa-vote-delayed/">Reid Calls Off Protect IP Act Vote</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-23/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-20</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-20/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-20</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-20/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 13:59:21 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4552</guid>
		<description><![CDATA[InfoSec News for Friday January 20, 2012. Mozilla pushes browser-based alternative to passwordsGive us your keys to look after, we&#8217;re lovely: Mozilla is promoting a browser-based alternative to usernames and passwords for website logins. Federal Reserve contractor charged with source code theftA U.S. Federal Reserve contractor has been charged with copying the source code of [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Friday January 20, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/20/browserid/">Mozilla pushes browser-based alternative to passwords</a><br />Give us your keys to look after, we&#8217;re lovely: Mozilla is promoting a browser-based alternative to usernames and passwords for website logins.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/lRq18bpyCE4/Federal_Reserve_contractor_charged_with_source_code_theft">Federal Reserve contractor charged with source code theft</a><br />A U.S. Federal Reserve contractor has been charged with copying the source code of software that keeps track of large exchanges of money between U.S. government agencies.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/tDcA4Sp4uXY/Feds_charge_7_in_massive_case_against_Megaupload_online_piracy_ring">Feds charge 7 in &#8216;massive&#8217; case against Megaupload online piracy ring</a><br />A day after thousands of websites went on strike protesting controversial anti-piracy legislation in the U.S., federal authorities today announced they have busted a pirate ring that allegedly hauled in $175 million.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/19/feds_arrest_programmer_for_software_theft/">Feds cuff coder accused of US bank source code swipe</a><br />Alleged thief &#8216;nicked $9.5m software to train his students&#8217;: A computer programmer has been charged with stealing source code worth $9.5m from the Federal Reserve Bank of New York, according to the FBI and prosecutors.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/19/mcafee_spam_relay_patch/">Spam-squirting hole found in McAfee antivirus kit</a><br />Ironic server-side flaw exploited, patch promised: McAfee is promising to patch a vulnerability in its hosted anti-malware service after it found a flaw that allowed systems where the product was installed to be turned into potential spam-relay nodes.
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/jOx77-yp5YE/">U.S. drone strikes kill senior al-Qaeda official Aslam Awan in Abbottabad</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_tech/~3/_DJuL4si0nE/index.html">Fed websites back online after Anonymous attack</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16646023">Hackers retaliate over Megaupload</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/012012-anonymous-retaliates-for-megaupload-shutdown-255113.html?source=nww_rss">Anonymous retaliates for Megaupload shutdown, attacks DOJ, others</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120120-2012-business-worries">2012 business worries</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_topstories/~3/oEuVzGZOJyY/index.html">Fed sites online after Anonymous attack</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/nNIYEJo8q_8/">Phone-hacking settlements by Rupert Murdochs News Corp. top $1-million</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/vgxGahbAgwo/">Hackers attack FBI, Justice Department websites after file sharing service shutdown</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/19/u-s-shutters-megaupload-hackers-retaliate/">U.S. shutters Megaupload, hackers retaliate</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/S9Pccs1tKsY/">U.S. Justice Department site taken down by hackers over Megaupload shutdown</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=05bb10f34a5faf5c6884731249908dd9">Advertising: The Push for Online Privacy &#8211; Advertising</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/sopa-watering-down/">SOPA Getting a Face-Lift: How Evil Will It Be?</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/scada-exploits/">Hoping to Teach a Lesson, Researchers Release Exploits for Critical Infrastructure Software</a>
</li>
<li><a href="http://www.itnews.com.au/News/287432,microsoft-takes-aim-at-rootkits-misses.aspx">Microsoft takes aim at rootkits, misses</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/oR3WIUq1OSg/">NSA Releases SE Android With Better Sandboxing, Access Control Policies</a>
</li>
<li><a href="http://www.darkreading.com/compliance/167901112/security/news/232500156/sita-first-to-achieve-pci-security-compliance-for-passenger-processing.html">SITA First To Achieve PCI Security Compliance For Passenger Processing</a>
</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232500153/metasploit-exploit-module-released-for-plc-scada-devices.html">Metasploit Exploit Module Released For PLC SCADA Devices</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/DzPZL_w5VZk/">More source code stolen, says Symantec</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/megaupload-indicted-shuttered/">Feds Shutter Indicts, Shutters Megaupload</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011912-mcafee-due-to-patch-spam-255061.html?source=nww_rss">McAfee due to patch spam relay problem in cloud product</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011912-ie-uri-encoding-behavior-facilitates-255073.html?source=nww_rss">IE URI encoding behavior facilitates XSS attacks, researchers say</a>
</li>
<li><a href="http://www.darkreading.com/security-monitoring/167901086/security/news/232500140/hbgary-and-hp-enterprise-security-partner-to-deliver-advanced-threat-intelligence-on-the-arcsight-platform-to-combat-targeted-attacks.html">HBGary And HP Enterprise Security Partner To Deliver Advanced Threat Intelligence On The ArcSight Platform To Combat Targeted Attacks</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Z4rY5uV05o0/malware_news.php">Koobface botnet goes down, suspects scurry to erase tracks</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bf764e1/l/0Lnews0Btechworld0N0Csecurity0C33312830Cbarclays0E970Epercent0Eof0Edata0Ebreaches0Estill0Edue0Esql0Einjection0C0Dolo0Frss/story01.htm">Barclays: 97 percent of data breaches still due to SQL injection</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Nhr8fyDVyRo/">More source code stolen, Symantec</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/NOZ-M_vdepk/">Iraq okays death penalty for 2009 Baghdad bombings convicts</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=fb681bdc444180cb7621e0b9e8f2153f">Facebook Users Hit By Money-Grubbing Malware</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-19</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-19/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-19</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-19/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 13:59:25 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4550</guid>
		<description><![CDATA[InfoSec News for Thursday January 19, 2012. Japanese cops cuff six smut-scam ransomware suspectsVictims forced to pay stiff charges: Japanese police have arrested six suspected cyber-crooks over a one-click billing fraud scam that allegedly targeted sweaty smut surfers. Facebook, experts spar over Ramnit worm contagionSecurity boss says stalking site is free of bank account-raiding malware: [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Thursday January 19, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/19/japanese_cops_cuff_smut_trojan_suspects/">Japanese cops cuff six smut-scam ransomware suspects</a><br />Victims forced to pay stiff charges: Japanese police have arrested six suspected cyber-crooks over a one-click billing fraud scam that allegedly targeted sweaty smut surfers.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/19/ramnit_re_visited/">Facebook, experts spar over Ramnit worm contagion</a><br />Security boss says stalking site is free of bank account-raiding malware: Facebook has downplayed the significance of Ramnit, a recently discovered worm that attempts to steal login credentials for the social networking site.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/19/care_provider_data_protection/">Careless care charity loses unencrypted patient data stick</a><br />Whoops, won&#8217;t happen again: A care provider with offices in the Isle of Man and Northern Ireland has committed to improving its data protection standards after losing a memory stick containing unencrypted patient data.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/YISH6CIwqaA/Alcatel_Lucent_Arbor_Networks_partner_on_DDOS_mitigation">Alcatel-Lucent, Arbor Networks partner on DDOS mitigation</a><br />Alcatel-Lucent is now offering a router with technology from Arbor Networks that defends against distributed denial-of-service attacks, the two companies said on Wednesday.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/yZn2Q07WVno/Secunia_sets_six_month_deadline_for_vulnerability_disclosures">Secunia sets six-month deadline for vulnerability disclosures</a><br />Vulnerability research firm Secunia announced that, effective from the beginning of the year, software vendors will have a six-month deadline to fix vulnerabilities reported through its Vulnerability Coordination Reward Programme.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/18/russian_cybercrime_suspect_deported/">Alleged Muscovite cybercrime daddy hauled in to face US court</a><br />Feds allege pre et fils duo scooped $100ks using malware: A suspected Russian cyber-crook has arrived in the US to face charges of security fraud, computer hacking and ID theft following his deportation from Switzerland.
</li>
<li><a href="http://business.financialpost.com/2012/01/19/lock-your-online-doors/">Lock your online doors</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011812-senate-to-consider-cybersecurity-255051.html?source=nww_rss">Senate to Consider Cybersecurity Overhaul</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011912-rsa-breach-255042.html?source=nww_rss">RSA, unapologetic, looks to move beyond The Breach</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16627713">Anti-malware code&#8217;s spambot flaw</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Pvg013jU4Kg/secworld.php">Twitter users targets of social spear phishing</a>
</li>
<li><a href="http://www.ottawasun.com/2012/01/19/mcafee-bug-could-turn-pcs-into-spam-servers">McAfee bug could turn PCs into spam servers</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/EaZArJsJqCw/">Facebook, Security Investigators Unmask Five Men Behind Koobface Crime Ring</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/18/william-watson-a-teachers-lesson/">William Watson: A teachers lesson</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/internet-revolt-follow/">Internet SOPA/PIPA Revolt: Dont Declare Victory Yet</a>
</li>
<li><a href="http://www.thestar.com/business/article/1117745--zappos-amazon-hit-by-lawsuit-after-a-hacker-attack-on-the-online-shoe-retailer">Zappos, Amazon hit by lawsuit after a hacker attack on the online shoe retailer</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/loling-our-way-to-internet-freedom/">LOLing Our Way to Internet Freedom</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/vsOG5dw3zVs/">SOPA, PIPA Still Threaten Internet Operations Even Without DNS Filtering</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/6CBIQc6Qbdk/">Symantec Confirms Source Code Stolen in 2006 Breach It Didn&#8217;t Know About</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/sopa-piracy-costs/">SOPA, Internet Regulation, and the Economics of Piracy</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/1xZM8ueX3jE/">Senators change sides on SOPA/PIPA issue</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/loP_7G4cXwY/">USB Drive Security: 10 Tips for Guarding Enterprise Data</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/lwmB_hyAzh8/">Costa Concordia captain claims he tripped and fell from sinking ship into lifeboat</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/scotus-re-copyright-decision/">Supreme Court Says Congress May Re-Copyright Public Domain Works</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011812-facebook-attack-255010.html?source=nww_rss">New Facebook attack targets e-cash users</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/DU97qI4RBhg/">SOPA Web Protests Sure to Inspire Malware Distribution Scams</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/AOcIUeZsxoo/">Google, Wikipedia Lead Protests of SOPA, PIPA Across Web</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/2B_UG77ZdtY/">How to Kill SOPA, PIPA While Building Consensus for Sensible Legislation</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/WeAPjnKCPEQ/secworld.php">Symantec admits its networks were hacked and source code stolen</a>
</li>
<li><a href="http://www.pheedcontent.com/click.phdo?i=874c85bfbd31b4a1a5e786c3cbf7d880">Symantec Confirms Hackers Breached Network in 2006</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/18/yangs-exit-from-yahoo-may-remove-barrier-to-asia-asset-sale/">Yangs exit from Yahoo may remove barrier to Asia asset sale</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/KC7QWkSbisY/">Wikipedia, Google, Others Protest SOPA, PIPA</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/emZidTbqca8/">Google blacks out its home page in support of Wikipedia SOPA protest</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/9J6SsllX0lM/">DoD ID cards under attack</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=7c37cf6ccf1cf65d2ee2a46823cb4fe4">How Facebook Took Down Koobface Malware</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/raeWKltuDPE/article.php">Questioning of incoming data crucial for security awareness</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-19/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-18</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-18/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-18</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-18/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 13:59:23 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4548</guid>
		<description><![CDATA[InfoSec News for Wednesday January 18, 2012. MegaSearch Aims to Index Fraud Site WaresA new service in the cyber underground aims to be the Google search of underground Web sites, connecting buyers to a vast sea of shops that offer an array of dodgy goods and services, from stolen credit card numbers to identity information [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Wednesday January 18, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/SWVPNSh_kyA/">MegaSearch Aims to Index Fraud Site Wares</a><br />A new service in the cyber underground aims to be the Google search of underground Web sites, connecting buyers to a vast sea of shops that offer an array of dodgy goods and services, from stolen credit card numbers to identity information and anonymity tools.
<p>A glut of stolen card data has spawned dozens of stores that sell the information. The trouble is that each store requires users to create accounts and sign in before they can search for cards.</p>
<p>Enter MegaSearch.cc, which aims to let fraudsters discover which fraud shops hold the cards they&#8217;re looking for, without having to first create accounts at each shop. This underground search engine aggregates data about compromised payment cards, and points searchers to various fraud shops selling them.</p>
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/18/koobface_prime_suspect_outed/"><i>NYT</i> names five Koobface botnet suspects</a><br />Trojan coins millions for its masters, say researchers: Five suspected masterminds behind the infamous Koobface botnet have been unmasked in a move abetted by Facebook to put the heat on cyber-crimelords.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/18/carberp_steals_e_cash_facebook/">New stealthy botnet Trojan holds Facebook users hostage</a><br />Victims must pay $25 to get back into stalkerbase: A new strain of cybercrime Trojan is targeting Facebook users by taking over their machines and shaking them down for cash.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/O1XxeGhshao/Symantec_backtracks_admits_own_network_hacked">Symantec backtracks, admits own network hacked</a><br />Symantec today backed away from earlier statements regarding the theft of source code of some of its flagship security products, now admitting that its own network was compromised.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/yc9na5yQG0U/Facebook_may_let_you_share_what_you_do_off_site">Facebook may let you share what you do off-site</a><br />Speculation is swirling that Facebook is getting ready to announce a way to combine information on what users do on, and off, the social network.
</li>
<li><a href="http://www.cbc.ca/news/technology/story/2012/01/17/ottawa-fraud-computer-purchases.html?cmp=rss">Police charge man with fraud over phoney computer orders</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/why-weve-censored-wired-com/">Why Weve Censored Wired.com</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011712-clamor-for-cloud-apps-increases-254972.html?source=nww_rss">Clamor for cloud apps increases corporate data breach risk</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011712-zappos-data-breach-254971.html?source=nww_rss">Zappos data breach response a good idea or just panic mode?</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120118-stuxnet-and-duqu-part-of-assembly-line-researchers">Stuxnet and Duqu part of assembly line: researchers</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/swj3HytuKpI/">Oracle Accused of Downplaying Database Flaws, Severity</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/rAyKAoRMQUY/">Google &#8216;Good to Know&#8217; Campaign Touts Web Privacy, Security</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/dRz-l8qhmII/">Smartphones, Tablets, Android Are Why Malware Is Going Mobile in 2012</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/xEjrOD3sRk8/">Oracle Patches 78 Bugs in January&#8217;s Critical Patch Update</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/TBgu5Li4eKk/">Coastguard begged Costa Concordia captain Francesco Schettino to return to ship after crash, recording shows</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/IMmU5hc8HE8/">Russia faces violent revolution if it doesnt embrace democracy, billionaire Putin challenger declares</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/j6tEWui2gaU/">Why is Wikipedia staging a blackout and what is SOPA?</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/17/vivian-krause-oil-sands-money-trail/">Vivian Krause: Oil sands money trail</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/websites-dark-in-revolt/">A SOPA/PIPA Blackout Explainer</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=8610b4b1c2a75c9c9a80125e2f70127e">Google&#8217;s &#8216;Good to Know&#8217; Is a Great Online Privacy Resource for Business</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/EEWGD2vF3tM/israeli-and-palestinian-hackers-trade-ddos-attacks-in-rising-cyber-gang-war.ars">Israeli and Palestinian hackers trade DDoS attacks in rising cyber-gang war</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=1dee3c832c61e45e2c441f24041ca9cd">Bits Blog: Even Big Companies Cannot Protect Their Data</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/R0cu8FGuXIs/">Zappos Breach Illustrate the Need for Stronger Password Rules</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/zvxPbeccbJI/">New Sykipot Variant Targets Defense Sector Smart Card Credentials</a>
</li>
<li><a href="http://www.darkreading.com/advanced-threats/167901091/security/news/232400491/gfi-software-enhances-dynamic-malware-analysis.html">GFI Software Enhances Dynamic Malware Analysis</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/17/canadians-ignoring-brands-on-social-networks/">Canadians ignoring brands on social networks</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/htjsM1vUEU8/">Hacktivists expose personal info of T-Mobile staff</a>
</li>
<li><a href="http://www.darkreading.com/advanced-threats/167901091/security/news/232400480/cambridge-company-launches-ultra-secure-3rd-generation-networked-scada-system.html">Cambridge company Launches Ultra-Secure 3rd Generation Networked SCADA System</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/scotus-student-social-media/">Supreme Court Rejects Student Social-Media Cases</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=a1ec322c0979b4ab7a69eeedc90b9893">Email, Personal Information on PlayBook Left Vulnerable to Hackers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/zV6-LHG9fI0/secworld.php">Threat incidents and security wins in 2011</a>
</li>
<li><a href="http://www.darkreading.com/advanced-threats/167901091/security/news/232400468/facebook-koobface-malware-gang-unmasked-sophos-releases-exclusive-research.html">Facebook &#8216;Koobface&#8217; Malware Gang Unmasked &#8212; Sophos Releases Exclusive Research</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/VE69juc4UWA/secworld.php">Brazen Brazilian hackers opening cybercrime schools</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/xQORaIEPXek/">Wikipedia Planning SOPA, PIPA Protest Shutdown</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=de65973dbcc302d58af5bca0bb03e2b2">10 Security Trends To Watch In 2012</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Se0BSe3_UUc/">Collection of information key to thwarting APT attacks</a>
</li>
<li><a href="http://www.darkreading.com/compliance/167901112/security/news/232400437/symantec-announces-intelligent-information-governance-to-mitigate-risks-and-free-information.html">Symantec Announces Intelligent Information Governance To Mitigate Risks And Free Information</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/17/u-s-online-piracy-bill-headed-for-major-makeover/">U.S. online piracy bill headed for major makeover</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1be50901/l/0Lnews0Btechworld0N0Csecurity0C3330A5370Cfacebook0Ename0Eshame0Erussian0Ekoobface0Egang0C0Dolo0Frss/story01.htm">Facebook to name and shame Russian Koobface gang</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/9huqhbDmJ2w/">Collection of information key to thwarting APT attacks, report</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-18/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-17</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-17/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-17</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-17/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 13:59:28 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4546</guid>
		<description><![CDATA[InfoSec News for Tuesday January 17, 2012. Phishing Your Employees 101A new open source toolkit makes it ridiculously easy to set up phishing Web sites and lures. The software was designed to help companies test the phishing awareness of their employees, but as with most security tools, this one can be abused by miscreants to [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Tuesday January 17, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/8Ec5XOp43rs/">Phishing Your Employees 101</a><br />A new open source toolkit makes it ridiculously easy to set up phishing Web sites and lures. The software was designed to help companies test the phishing awareness of their employees, but as with most security tools, this one can be abused by miscreants to launch real-life attacks.
<p>The Simple Phishing Toolkit includes a site scraper that can clone any Web page &#8212; such as a login page &#8212; with a single click, and ships with an easy-to-use phishing lure creator. An education package is bundled with the toolkit that allows administrators to record various metrics about how recipients respond, such as whether a link was clicked, the date and time the link was followed, and the user&#8217;s Internet address, browser and operating system. Lists of targets to receive the phishing lure can be loaded into the toolkit via a spreadsheet file.</p>
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/17/security_hardened_android/">NSA constructs hardened Android, unleashes it on world</a><br />Vicious apps squashed by super-spook mobile OS: The US Defense Department&#8217;s The National Security Agency (NSA) has released a security-hardened version of Google&#8217;s mobile OS, Android.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/17/japan_space_agency_malware_scare/">Japanese boffins fear virus nicked spacecraft blueprints</a><br />Tokyo, we have a problem: Japanese space engineers have admitted one of their computers has been infected by a Trojan that may have leaked sensitive data, including system login information, to hackers.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/17/game_hack_denied/">GAME: Our website wasn&#8217;t hacked!</a><br />Leaked account login details are bogus, says chain: Video games purveyor GAME says it has <i>not</i> been hacked after reports yesterday claimed that the retail biz had suffered a security breach.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/17/hmrc_misses_deadline/">Taxman two months late on cyber-crimefighters deadline</a><br />HMRC still wants our dosh on time though: HMRC has missed a key deadline to create teams of cyber crime investigators and launch initiatives to counter the increased threat of web attacks on the authority&#8217;s systems and customers.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/fihyl0QsyaU/secworld.php">Security challenges for the finance sector</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011712-endpoint-survey-254621.html?source=nww_rss">Survey: Security deployments, training reduce cyberattack wipeouts, downtime</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120117-chinese-hackers-target-dod-dhs-smart-cards">Chinese hackers target DoD, DHS smart cards</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/17/cyber-attacks-cost-firms-nearly-500k-per-year-study/">Cyber attacks cost firms nearly US$500K per year, study finds</a>
</li>
<li><a href="http://datalossdb.org/incidents/5507-call-center-employee-pleads-guilty-to-stealing-and-misusing-customers-credit-card-numbers">Call center employee pleads guilty to stealing and misusing customers&#8217; credit card numbers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5500-44-employees-names-e-mail-addresses-phone-numbers-and-clear-text-passwords-dumped-on-the-internet">44 employees&#8217; names, e-mail addresses, phone numbers, and clear-text passwords dumped on the Internet</a>
</li>
<li><a href="http://datalossdb.org/incidents/5491-5-294-e-mail-addresses-md5-passwords-and-usernames-dumped-on-the-internet">5,294 e-mail addresses, MD5 passwords, and usernames dumped on the Internet</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/chO5HLZnFw4/">Visa advises on more secure credit card transactions</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=74ec9a6d44ba127783549e191fb75ccc">Zappos Hacked: What You Need to Know</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/50GuLEtEBms/secworld.php">Hackers breach T-Mobile Web server, leak staff data</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/mZ2_Byxoz5w/">Zappos breach affects 24M, opens door for more attacks</a>
</li>
<li><a href="http://www.thestar.com/business/article/1116340--online-retailer-zappos-warns-customers-after-major-hacker-attack">Online retailer Zappos warns customers after major hacker attack</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bde813d/l/0Lnews0Btechworld0N0Csecurity0C3330A3450Cnon0Eus0Ecustomers0Ekept0Ein0Edark0Eas0Ezappos0Ecleans0Eup0Eafter0Edata0Ebreach0C0Dolo0Frss/story01.htm">Non-US customers kept in dark as Zappos cleans up after data breach</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/H8p0-dB2tRY/">White House Opposes DNS Blocking in SOPA</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bde0035/l/0Lnews0Btechworld0N0Csecurity0C3330A3380Ccollege0Estudents0Eravaged0Eby0Emalware0Efor0Eover0Edecade0C0Dolo0Frss/story01.htm">College and students ravaged by malware for over a decade</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bde2666/l/0Lnews0Btechworld0N0Csecurity0C3330A3380Ccollege0Estudents0Eravaged0Eby0Emalware0Efor0Eover0Edecade0C0Dolo0Frss/story01.htm">College and students ravaged by viruses for over a decade</a>
</li>
<li><a href="http://datalossdb.org/incidents/5489-24-million-email-addresses-billing-and-shipping-addresses-phone-numbers-the-last-four-digits-from-credit-cards-passwords-and-more-illegally-accessed">24 million email addresses, billing and shipping addresses, phone numbers, the last four digits from credit cards, passwords and more illegally accessed</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/kM97iHlBNdk/zappos-gets-hacked-resets-customers-passwords.ars">Zappos gets hacked, resets customers&#8217; passwords</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/16/shopping-site-zappos-hit-by-hacker/">Shopping site Zappos hit by hacker</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16576542">Hackers target children&#8217;s sites</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/uk-scotland-scotland-politics-16576255">MP quits over Hitler joke video</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/aT67X1rY-CQ/">Russia vows to expose those responsible for Phobos-Grunt Mars probes inglorious end over the Pacific</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/suNVC69oZv4/">Pakistan PM Gilani found in contempt of court for suspected corruption cover-up</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16574987">Hackers strike Amazon-owned site</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bdc7c57/l/0Lnews0Btechworld0N0Csecurity0C3330A2640Cnasa0Eiss0Edata0Estolen0Efrom0Ejapanese0Espace0Eagency0C0Dolo0Frss/story01.htm">NASA and ISS data stolen from Japanese space agency</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-17/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-16</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-16/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-16</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-16/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 13:59:27 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4544</guid>
		<description><![CDATA[InfoSec News for Monday January 16, 2012. DHS media monitoring could chill public dissent, EPIC warnsThe U.S. Department of Homeland Security is engaging in media monitoring activity that achieves no public safety goals and will likely have a chilling effect on legitimate criticism of the agency, a leading privacy advocacy group warned. Zappos coughs to [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Monday January 16, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/N-Z4_u-f4ss/DHS_media_monitoring_could_chill_public_dissent_EPIC_warns">DHS media monitoring could chill public dissent, EPIC warns</a><br />The U.S. Department of Homeland Security is engaging in media monitoring activity that achieves no public safety goals and will likely have a chilling effect on legitimate criticism of the agency, a leading privacy advocacy group warned.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/16/zappo_breach/">Zappos coughs to HUGE data breach</a><br />Up to 24 million users zappwn3d: Online online shoe and apparel outlet Zappos.com has apologised over a massive data breach that exposed the personal details of millions.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/g79Vl4OECe0/Facebook_chat_phishing_attack_impersonates_Facebook_security_team">Facebook chat phishing attack impersonates Facebook security team</a><br />A new phishing attack that&#8217;s spreading through Facebook chat modifies hijacked accounts in order to impersonate the social network&#8217;s security team.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/13/sykipot_trojan_dod_smart_card_attack/">US military access cards cracked by Chinese hackers</a><br />Access to buildings and intranets harvested by super-spy Trojan: A new strain of the Sykipot Trojan is been used to compromise the Department of Defense-sanctioned smart cards used to authorise network and building access at many US government agencies, according to security researchers.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/lSEWP2P77FU/Sykipot_Trojan_hijacks_DoD_smart_cards">Sykipot Trojan hijacks DoD smart cards</a><br />A variant of the Sykipot Trojan Horse hijacks U.S. Department of Defense (DoD) smart cards in order to access restricted resources.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/13/mocality_kenya_business_listing_startup_google_false_collaboration_claim/">Kenyan startup claims Google &#8216;scalped&#8217; its data after staging a STING</a><br />Google smacks back: Mocality&#8217;s data was &#8216;publicly available&#8217;: Google has been accused of &#8220;fraudulently&#8221; accessing a rival Kenya-based business listings database and then attempting to sell the internet giant&#8217;s competing GKBO product to that customerbase.
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/world-16577184">New attacks on Israeli websites</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_tech/~3/beBDzNq1w0c/index.html">White House blasts Internet piracy bills</a>
</li>
<li><a href="http://www.thestar.com/news/world/article/1116164--israel-s-stock-exchange-airline-attacked-by-website-hackers">Israels stock exchange, airline attacked by website hackers</a>
</li>
<li><a href="http://www.thestar.com/business/article/1116168--hackers-attack-websites-of-israel-s-stock-exchange-national-air-carrier">Hackers attack Israels stock exchange, national air carrier</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011612-rsa-coviello-interview-254931.html?source=nww_rss">Q&amp;A: RSA&#8217;s Art Coviello reflects on last year&#8217;s big data breach</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011612-rsa-coviello-story-254932.html?source=nww_rss">RSA chief: Last year&#8217;s breach has silver lining</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/dFEY46-lI-o/secworld.php">Zappos hacked, info of 24+ million customers may be compromised</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/etqrWEqdnf8/">Zappos Latest Company Hit by Data Breach</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/NbLvfqN8K0A/malware_news.php">San Francisco City College systems infected for over a decade</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bda8868/l/0Lnews0Btechworld0N0Csecurity0C3330A20A20Crsa0Esecurity0Ebreach0Ehas0Eimproved0Esecurity0Emeasures0C0Dolo0Frss/story01.htm">RSA security breach has improved security measures</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bda8864/l/0Lnews0Btechworld0N0Csecurity0C3330A20A70Cfacebook0Esecurity0Eimpersonated0Eby0Ehackers0Ein0Echat0Ephishing0Eattack0C0Dolo0Frss/story01.htm">Facebook Security impersonated by hackers in chat phishing attack</a>
</li>
<li><a href="http://www.ama-assn.org/amednews/2012/01/16/bil20116.htm">Small medical practices greatly at risk for data breaches</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/white-house-blasts-internet-blacklisting-bills/">White House Blasts Internet Blacklisting Bills</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/wzBf8BcWp1E/">Microsoft&#8217;s Trustworthy Computing, Security Still Priority 10 Years Later</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011412-chinese-attack-us-dod-smart-254927.html?source=nww_rss">Chinese &#8216;attack US DoD Smart Cards&#8217; with Sykipot Malware</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/r-GYt7airl4/obama-administration-joins-the-ranks-of-sopa-skeptics.ars">Obama administration joins the ranks of SOPA skeptics</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/14/nortel-trial-to-open-old-wounds/">Nortel trial to open old wounds</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/14/where-nortel-went-wrong/">Where Nortel went wrong</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/14/were-senior-executives-scapegoats-for-nortels-demise/">Were senior executives scapegoats for Nortels demise?</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/6w73dnKVAzI/">Confessions of a Mossad spy</a>
</li>
<li><a href="http://datalossdb.org/incidents/5485-customers-account-administration-e-mail-account-names-dates-of-birth-contact-numbers-postal-addresses-passwords-and-credit-card-details-may-have-been-accessed-by-hacker">Customers&#8217; account administration e-mail, account names, dates of birth, contact numbers, postal addresses, passwords, and credit card details may have been accessed by hacker</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/dns-sopa-provision/">Rep. Smith Waters Down SOPA, DNS-Redirects Out</a>
</li>
<li><a href="http://datalossdb.org/incidents/5482-podiatrist-used-names-and-identity-information-of-approximately-200-nursing-home-patients-as-part-of-medicare-fraud-scheme">Podiatrist used names and identity information of approximately 200 nursing home patients as part of Medicare fraud scheme</a>
</li>
<li><a href="http://datalossdb.org/incidents/5484-office-of-the-privacy-commissioner-retrieved-hundreds-of-medical-records-that-were-scattered-amongst-debris-in-an-abandoned-rural-property-belonging-to-a-doctor-who-had-been-disciplined">Office of the Privacy Commissioner retrieved hundreds of medical records that were scattered amongst debris in an abandoned rural property belonging to a doctor who had been disciplined</a>
</li>
<li><a href="http://datalossdb.org/incidents/5481-banking-information-and-other-data-from-perhaps-tens-of-thousands-of-students-faculty-and-administrators-were-exfiltrated-overseas-by-numerous-viruses-that-were-on-systems-for-over-a-decade">Banking information and other data from perhaps tens of thousands of students, faculty and administrators were exfiltrated overseas by numerous viruses that were on systems for over a decade</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/kR_cVzVYnr8/">Symantec accused of selling &#8220;scareware&#8221;</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/bar-eyeing-righthaven/">Nevada State Bar Investigating Copyright-Troll Righthaven</a>
</li>
<li><a href="http://datalossdb.org/incidents/5477-342-000-records-of-subscriber-customers-including-315k-e-mail-addresses-and-phone-numbers-85k-dates-of-birth-and-27k-md5-passwords-dumped-on-web">342,000 records of subscriber/customers, including 315K e-mail addresses and phone numbers, 85K dates of birth, and 27K MD5 passwords dumped on web</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/_Jmkt0RrQnc/">Microsoft to scale up its threat intelligence sharing</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/Bn5NM2VmDa4/">Syria tank attack on border town leaves at least 15 dead, add to civil-war fears</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/IKgSOytEGb8/">Oracle Plans 78 bug Fixes in January&#8217;s Giant Critical Patch Update</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011312-facebook-chat-based-phishing-attack-impersonates-254908.html?source=nww_rss">Facebook chat-based phishing attack impersonates Facebook Security</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/gsY2MtXsgK8/">U.S. still using RQ-170 Sentinel drones despite capture by Iran</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=065b315f0859b0d098187f84fcee0bcb">Expired Digital Certificates: A Management Challenge</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=ea1183c72de606bc8903bc92151450d9">Sykipot Malware Steals Pentagon Smart-Card Credentials</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/air-marshal-arrested-occupy/">TSA Air Marshal Arrested for Stealing Boston Occupiers iPhone on the Eve of Eviction</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/13/complaints-about-online-traffic-slowdowns-increasing-crtc/">Complaints about online traffic slowdowns increasing: CRTC</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/E7CVY6f75Vk/">Arab League braces for civil war as protests erupt across Syria</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-16/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-13</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-13/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-13</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-13/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 13:59:28 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4542</guid>
		<description><![CDATA[InfoSec News for Friday January 13, 2012. Namesco spits out phishy warning after credit card info leak&#8216;Please do not treat this as SPAM&#8217;: Namesco customers are angry over the domain name and hosting firm&#8217;s handling of a security breach that exposed the credit card details of some of the domain name and hosting firm&#8217;s users. [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Friday January 13, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/13/namesco_phish_like_security_warning/">Namesco spits out phishy warning after credit card info leak</a><br />&#8216;Please do not treat this as SPAM&#8217;: Namesco customers are angry over the domain name and hosting firm&#8217;s handling of a security breach that exposed the credit card details of some of the domain name and hosting firm&#8217;s users.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/13/epic_letter_to_ftc_on_google_social_search/">EPIC asks FTC to probe Google&#8217;s search biz tweak</a><br />It&#8217;s a sticky social situation: The Electronic Privacy Information Center (EPIC), as expected, has now written to the US Federal Trade Commission requesting that the watchdog investigates Google&#8217;s search business.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/fzbK6plBCRA/Cyber_insurance_offers_IT_peace_of_mind_or_maybe_not">Cyber insurance offers IT peace of mind &#8212; or maybe not</a><br />Cyber insurance can help mitigate damages after a breach, but it&#8217;s no substitute for top-notch security, IT pros say.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/13/nhs_fined_stolen_data/">NHS fined 375k after stolen patient data flogged on eBay</a><br />Hospital bosses appeal against ICO&#8217;s stiffest punishment yet: The Information Commissioner is proposing to issue its heaviest ever fine for a breach of UK data protection laws. It proposes fining a health body after patient records were stolen from a hospital and sold on eBay.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/12/trustdefender_acquired_by_threatmetrix/">Aussie fraud buster seized by global rival</a><br />Founder joins as global CTO: Cybercrime buster ThreatMetrix has added Australian malware protector TrustDefender to its global fold.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/Nw6YX_C2X88/Lawmakers_seek_hearing_on_Carrier_IQ_privacy_issues">Lawmakers seek hearing on Carrier IQ privacy issues</a><br />Three House members today called for a Congressional hearing on the implications raised by the use of the Carrier IQ&#8217;s software by wireless carriers.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/12/stratfor_returns/">Stratfor slaps website back online after Anon mega-hack</a><br />CEO: Hacktivists can&#8217;t silence us &#8211; and soz about the credit cards: Stratfor has restored its website to normal operation on Wednesday, more than two weeks after a hack attack by Anonymous that made the global intelligence analyst firm a byword for information insecurity.
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120113-walden-university-offers-m-s-in-emergency-management">Walden University offers M.S. in Emergency Management</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bc95925/l/0Lnews0Btechworld0N0Csecurity0C33298970Cchinese0Eattack0Eus0Edod0Esmart0Ecards0Ewith0Esykipot0Emalware0C0Dolo0Frss/story01.htm">Chinese &#8216;attack US DoD smart cards&#8217; with Sykipot malware</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bc9155c/l/0Lnews0Btechworld0N0Csecurity0C33298870Cmicrosoft0Eshare0Evaluable0Ereal0Etime0Ethreat0Edata0Efeed0Ewith0Esecurity0Ecommunity0C0Dolo0Frss/story01.htm">Microsoft to share valuable real-time threat data feed with security community</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/cnKdfXlRDIY/malware_news.php">Chinese using malware to attack US DoD smart card security</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/lzjWERszidQ/secworld.php">Identity intelligence and the complexity of security</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/dyG0Tlfz-oo/">Syria regime liquidating journalists, opposition council says</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/leahy-pipa-amendment/">Leahy Offers to Remove Net-Altering DNS Redirects in Anti-Piracy Bill</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/yEKa3ZPIYKU/">Stratfor returns as Anonymous readies 5M stolen emails</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/uNl4Xm73wWM/">Statfor returns as Anonymous readies 5M stolen emails</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=ff1a02ea972b3cccd28e6f1f936d2099">Microsoft Planning Real-Time Feed of Valuable Threat Data</a>
</li>
<li><a href="http://datalossdb.org/incidents/5462-2-651-e-mail-addresses-and-md5-passwords-acquired-and-dumped-by-hacker">2,651 e-mail addresses and MD5 passwords acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5461-4-504-usernames-md5-passwords-and-e-mail-addresses-acquired-and-dumped-by-hacker">4,504 usernames, MD5 passwords, and e-mail addresses acquired and dumped by hacker</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/manning-court-martialed/">Manning Should Be Court-Martialed, Court Official Recommends</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=c11cb2c4f777865de120a26e2a81885e">Air Force Drone Controllers Embrace Linux, But Why?</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232400286/prolexic-revenues-increase-45-percent-in-2011.html">Prolexic Revenues Increase 45 Percent In 2011</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232400287/sentrybay-and-netstar-sign-strategic-technology-partnership.html">SentryBay And NetSTAR Sign Strategic Technology Partnership</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/manning-deposition-request/">Bradley Manning Attorney Wants to Depose Rejected Witnesses</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/FMFQSWblFbc/">Microsoft Testing Real-Time Botnet Threat Intelligence Data Feed</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/9VTGS_GfS80/">DNSSEC Adoption Needs to Grow to Secure Core Internet, Protocols</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232400277/spam-key-trends-in-2011-and-predictions-for-2012.html">Spam&#8211;Key Trends In 2011 And Predictions For 2012</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232400281/bsa-details-cybersecurity-priorities-in-letter-to-senate.html">BSA Details Cybersecurity Priorities In Letter To Senate</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232400284/f5-keeps-android-users-connected-and-productive-with-new-secure-access-solutions.html">F5 Keeps Android Users Connected And Productive With New Secure Access Solutions</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232400285/new-associate-of-isc-programs-for-csslp-and-cap-help-aspiring-professionals-prepare-for-careers-in-cyber-security.html">New Associate of (ISC) Programs For CSSLP And CAP Help Aspiring Professionals Prepare For Careers In Cyber Security</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/6_-dLxlNnMQ/">IBM Security Software Manages Employee Data Access Privileges</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=6c77452521bd93fce673e512cd2585e4">Hack Attacks Now Leading Cause Of Data Breaches</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/GGCg-ocayHs/wyden-issa-and-cea-prepare-for-critical-battles-against-sopa-and-pipa.ars">Wyden, Issa, CEA prepare for critical battles against SOPA and PIPA</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bc3a6b7/l/0Lfeatures0Btechworld0N0Csecurity0C33297230Ccybersecurity0Ehelp0Eexists0Eif0Eyou0Eknow0Ewhere0Elook0C0Dolo0Frss/story01.htm">Cybersecurity help exists, if you know where to look</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/0_6juhEX3Ck/microsoft-building-real-time-security-threat-feed-for-governments-partners.ars">Microsoft building real-time security threat feed for governments, partners</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-12</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-12/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-12</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-12/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 13:59:47 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4540</guid>
		<description><![CDATA[InfoSec News for Thursday January 12, 2012. Flying the Fraudster SkiesGiven the heightened security surrounding air travel these days, it may be hard to believe that fraudsters would try to board a plane using stolen tickets. But incredibly, there are a number of criminal travel agencies doing business in the underground, and judging from the [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Thursday January 12, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/0OQ60dkZkM4/">Flying the Fraudster Skies</a><br />Given the heightened security surrounding air travel these days, it may be hard to believe that fraudsters would try to board a plane using stolen tickets. But incredibly, there are a number of criminal travel agencies doing business in the underground, and judging from the positive feedback left by patrons, business appears to be booming.
<p>The tickets often are purchased at the last minute and placed under the criminal buyer&#8217;s real name. The reservations are made using either stolen credit cards or hijacked accounts belonging to independent contractors in the travel industry. Customers are charged a fraction of the cost of the tickets and/or reservations, typically between 25 and 35 percent of the actual cost.</p>
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/12/colour_change_facebook_survey_scam/">Scammers punt bogus pink Facebook makeover</a><br />Lame lure promises to banish &#8216;boring blue&#8217;: The latest survey scam doing the rounds on Facebook works by falsely offering to change the profile of prospective marks from blue to red, black or shocking pink.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/12/world_economic_forum_risks/">WEF report: Cyber-attack risk to global stability is real</a><br />Cybercrime, wealth divide ranked among top 5 perils the world faces: Cyber-attacks against governments and businesses are among the top five risks in the world in terms of likelihood, according to the startlingly obvious World Economic Forum&#8217;s (WEF) Global Risks for 2012 report.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/nPT_ZJLa_Nw/Stratfor_relaunches_site_CEO_accuses_attackers_of_censorship">Stratfor relaunches site; CEO accuses attackers of censorship</a><br />Strafor Global Intelligence CEO George Friedman on Wednesday blasted those responsible for a December attack on the global intelligence firm&#8217;s website and decried what he called &#8216;censorship&#8217; by the attackers.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/11/mozilla_firefox_extended_support/">Mozilla deploys Firefox safety net for corporate mindreaders</a><br />Security fixes applied to as-yet-undisclosed older builds: Mozilla has pledged to update old versions of Firefox with security fixes, granting enterprises extra time to test and deploy major upgrades of the browser safe in the knowledge that vulnerabilities in existing installations will be patched.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/11/qr_codes_mobile_spam/">Spammers hit mobes with QR code junkmail jump pads</a><br />Ultimate URL obfuscator: Security researchers have spotted spam emails that point at URLs featuring embedded Quick Response codes (QR codes).
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/gFqLpipwjIU/Carrier_IQ_detection_tool_converted_to_premium_SMS_Trojan">Carrier IQ detection tool converted to premium SMS Trojan</a><br />Android malware writers are taking advantage of the controversy surrounding Carrier IQ&#8217;s smartphone tracking software in order to distribute a premium SMS Trojan, security researchers from Symantec warn.
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/acigPMurTog/mpaa-attacks-ars-for-challenging-efforts-to-curb-content-theft.ars">MPAA attacks Ars for &#8220;challenging efforts to curb content theft&#8221;</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/_u3gRsy3MBE/malware_news.php">Rootkit masquerading as Pro Evolution Soccer 2012 keygen</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bc0d6ff/l/0Lnews0Btechworld0N0Csecurity0C33296320Chackers0Euse0Ecarrier0Eiq0Econtroversy0Epush0Etrojan0C0Dolo0Frss/story01.htm">Hackers use Carrier IQ controversy to push Trojan</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120112-sandia-addresses-complex-dns-vulnerabilities">Sandia addresses complex DNS vulnerabilities</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120112-gender-gap-hinders-cybersecurity-hiring-boom">Gender gap hinders cybersecurity hiring boom</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011112-data-recovery-254804.html?source=nww_rss">Can you trust data-recovery service providers?</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/world-middle-east-16526067">Israeli hacker&#8217;s retaliatory leak</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bbfa126/l/0Lnews0Btechworld0N0Csecurity0C33296130Csaudi0Ecredit0Ecard0Enumbers0Eposted0Eby0Eisraeli0Ehacker0C0Dolo0Frss/story01.htm">Saudi credit card numbers posted by Israeli hacker</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/sk5UmGq2kwk/">New Sandia DNSSEC Visualization Tool Simplifies DNS Security for IT Managers</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/WgLXYXXuMKQ/">Stratfor Relaunches Site as CEO Apologizes for Data Breach</a>
</li>
<li><a href="http://datalossdb.org/incidents/5459-21-subscribers-e-mail-addresses-as-well-as-10-agents-e-mail-addresses-clear-text-passwords-contact-details-some-bank-account-information-acquired-and-dumped-by-hacker">21 subscribers&#8217; e-mail addresses as well as 10 agents&#8217; e-mail addresses, clear-text passwords, contact details, some bank account information acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5457-3-people-accessed-personal-tax-data-inadvertently-displayed-from-property-transfer-tax-returns-on-a-vendor-portion-of-the-state-s-web-site-including-social-security-numbers-of-1-332-individuals-and-the-federal-id-numbers-of-245-businesses">3 people accessed personal tax data inadvertently displayed from Property Transfer Tax Returns on a vendor portion of the state&#8217;s web site, including Social Security numbers of 1,332 individuals and the federal ID numbers of 245 businesses</a>
</li>
<li><a href="http://datalossdb.org/incidents/5456-5-450-e-mail-addresses-and-clear-text-passwords-acquired-and-dumped-by-hacker">5,450 e-mail addresses and clear-text passwords acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5460-personal-records-of-2-700-members-of-the-healthy-indiana-plan-care-select-and-hoosier-healthwise-health-programs-including-medicaid-numbers-exposed-on-the-internet-after-an-upgrade">Personal records of 2,700 members of the Healthy Indiana Plan, Care Select and Hoosier Healthwise health programs, including Medicaid numbers, exposed on the Internet after an upgrade</a>
</li>
<li><a href="http://datalossdb.org/incidents/5458-60-customers-online-bank-statements-viewed-by-other-customers-after-bank-reinstated-online-statements-following-a-fix-for-a-previously-detected-vulnerability">60 customers&#8217; online bank statements viewed by other customers after bank reinstated online statements following a fix for a previously detected vulnerability</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/11/china-in-canada-part-2-four-misconceptions-on-china/">China in Canada, part 2: Four misconceptions on China</a>
</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232400211/ibm-attacks-the-complexity-of-security-with-identity-intelligence.html">IBM Attacks The Complexity Of Security With Identity Intelligence</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/pci-lawsuit/">Rare Legal Fight Takes On Credit Card Company Security Standards and Fines</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/MOepY8_Q2lI/">ThreatMetrix Buys TrustDefender to Add Device Integrity Tools to Products</a>
</li>
<li><a href="http://www.ottawacitizen.com/Internet+addiction+becomes+more+than+buzzword/5980935/story.html">Internet addiction becomes more than a buzzword</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/2w57RQHiZNE/">Spam with QR code targets mobile users</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/universal-blasts-megaupload/">Universal Blasts Megaupload in Video Takedown Flap</a>
</li>
<li><a href="http://www.darkreading.com/mobile-security/167901113/security/news/232400179/entrust-uses-near-field-communication-bluetooth-to-bring-enterprise-credentials-management-to-popular-mobile-devices.html">Entrust Uses Near-Field Communication, Bluetooth to Bring Enterprise Credentials, Management To Popular Mobile Devices</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232400180/u-s-coast-guard-purchases-unisys-stealth-solution-for-secure-virtual-terminal.html">U.S. Coast Guard Purchases Unisys Stealth Solution For Secure Virtual Terminal</a>
</li>
<li><a href="http://www.darkreading.com/compliance/167901112/security/news/232400182/free-pci-compliance-task-list-provides-structure-to-help-maintain-pci-security-standards.html">Free PCI Compliance Task List Provides Structure To Help Maintain PCI Security Standards</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232400172/will-2012-be-the-year-of-the.html">Will 2012 be the year of the&#8230;..</a>
</li>
<li><a href="http://www.darkreading.com/compliance/167901112/security/news/232400174/columbia-sportswear-leverages-tokenization-and-encryption-to-reduce-pci-scope.html">Columbia Sportswear Leverages Tokenization And Encryption To Reduce PCI Scope</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232400176/threatmetrix-acquires-trustdefender.html">ThreatMetrix Acquires TrustDefender</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011112-cybersecurity-254792.html?source=nww_rss">Cybersecurity help exists, focusing it is the trick</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/mRdwoOgKnQM/">Data Recovery Services Pose Data Breach Risk Without Security Guarantees</a>
</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232400173/thales-and-infoblox-help-protect-internet-integrity.html">Thales And Infoblox Help Protect Internet Integrity</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=00150e53759abd469056bb7f21d79a83">Stratfor Relaunches Web Site in Wake of Attack</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/xwhGTyT5NJM/blame-the-internet-londons-burglars-wont-even-steal-cds-dvds.ars">Blame the Internet: London&#8217;s burglars won&#8217;t even steal CDs, DVDs</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/WC5gzxA3_kk/">Israel not shedding a tear over mystery death of Iranian nuclear scientist</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/GUuxHMqGe9U/review.php">Review: Preventing Good People From Doing Bad Things</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/AdKb-kD9CaY/malware_news.php">The anatomy of the Gameover Zeus variant</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-11</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-11/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-11</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-11/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 13:59:17 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4538</guid>
		<description><![CDATA[InfoSec News for Wednesday January 11, 2012. Adobe, Microsoft Issue Critical Security FixesAdobe and Microsoft today each issued software fixes to tackle dangerous security flaws in their products. If you use Acrobat, Adobe Reader or Windows, it&#8217;s time to patch. Microsoft released seven security bulletins addressing at least eight vulnerabilities in Windows. The lone &#8220;critical&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Wednesday January 11, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/wnaHXIaNg1k/">Adobe, Microsoft Issue Critical Security Fixes</a><br />Adobe and Microsoft today each issued software fixes to tackle dangerous security flaws in their products. If you use Acrobat, Adobe Reader or Windows, it&#8217;s time to patch.
<p>Microsoft released seven security bulletins addressing at least eight vulnerabilities in Windows. The lone &#8220;critical&#8221; Microsoft patch addresses a pair of bugs in Windows Media Player. Microsoft warns that attackers could exploit these flaws to break into Windows systems without any help from users; the vulnerability could be triggered just by browsing to a site that hosts specially crafted video content.</p>
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/_lNwInTBxDs/Adobe_plugs_6_critical_holes_in_Reader">Adobe plugs 6 critical holes in Reader</a><br />Adobe on Tuesday patched six vulnerabilities in the newest version of its popular Reader PDF viewer, making good on a late-2011 promise when it shipped an emergency update for an older edition.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/7Jq5-PZyXYE/Attack_code_published_for_serious_ASP.NET_DoS_vulnerability">Attack code published for serious ASP.NET DoS vulnerability</a><br />Exploit code for a recently patched denial-of-service (DoS) vulnerability that affects Microsoft&#8217;s ASP.NET Web development platform has been published online, therefore increasing the risk of potential attacks.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/10/pro_israeli_hackers_threaten_reprisal_leak/">Pro-Israel hackers threaten tit for tat after card leak</a><br />Saudi e-stores and Israeli diplomat&#8217;s site nobbled in cyber-spat: Pro-Israel hackers have reportedly breached Saudi shopping sites in retaliation for the publication of Israeli credit-card details by a pro-Palestinian &#8220;Saudi&#8221; hacker last weekend.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/10/google_wallet_sprint/">Sprint tucks Google Wallet into new pay-by-tap phones</a><br />Two 4G LTE phones, one wallet, no legacy networking: Sprint&#8217;s two newly announced 4G handsets both support Google Wallet, bringing an important boost to Google&#8217;s aspirations, but they also hammer the death nail into WiMAX in the USA.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/lDb4lv6g6ug/secworld.php">Easy ways to protect your privacy and data</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/011012-microsoft-patch-tuesday-254753.html?source=nww_rss">Media Player, security bypass are focus of Microsoft&#8217;s first Patch Tuesday of 2012</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/vE1JYVgc2eg/secworld.php">Google admits profiting from ads for illegal sites</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=c627737a8c2ac21bd466b77c68c4bff0">2012 World Economic Forum Risks Are Released</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bb71ed9/l/0Lnews0Btechworld0N0Csecurity0C332930A40Cmicrosoft0Easpnet0Eflaw0Etargeted0Eby0Ehacker0Ecode0C0Dolo0Frss/story01.htm">Microsoft ASP.Net flaw targeted by hacker exploit code</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bb70366/l/0Lnews0Btechworld0N0Csecurity0C33292950Cmicrosoft0Eissue0Epatch0Etuesday0Efix0Efor0Emedia0Eplayer0Esecurity0Ebypass0C0Dolo0Frss/story01.htm">Microsoft issue Patch Tuesday fix for Media Player and security bypass</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/anonymous-dicators-existential-dread/">2011: The Year Anonymous Took On Cops, Dictators and Existential Dread</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/mnZGirCyhhs/the-credit-card-that-may-stop-or-at-least-hinder-on--and-offline-fraud.ars">The credit card that may stop, or at least hinder, on- and offline fraud</a>
</li>
<li><a href="http://datalossdb.org/incidents/5450-109-usernames-encrypted-passwords-and-decrypted-passwords-acquired-and-dumped-by-hacker">109 usernames, encrypted passwords and decrypted passwords acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5448-160-names-e-mail-addresses-clear-text-passwords-addresses-phone-number-and-title-acquired-and-dumped-by-hacker">160 names, e-mail addresses, clear-text passwords, addresses, phone number, and title acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5443-36-usernames-clear-text-passwords-and-e-mail-addresses-acquired-and-dumped-by-hacker">36 usernames, clear-text passwords, and e-mail addresses acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5442-3-410-customers-company-names-address-username-clear-text-password-phone-number-and-e-mail-address-acquired-and-dumped-by-hacker">3,410 customers&#8217; company names, address, username, clear-text password, phone number, and e-mail address acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5440-125-e-mail-addresses-clear-text-passwords-and-country-of-origin-acquired-and-dumped-by-hacker">125 e-mail addresses, clear-text passwords, and country of origin acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5439-173-users-names-dates-of-birth-e-mail-addresses-phone-numbers-md5-passwords-and-some-bank-account-information-acquired-and-dumped-by-hacker">173 users&#8217; names, dates of birth, e-mail addresses, phone numbers, MD5 passwords and some bank account information acquired and dumped by hacker</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/10/peter-foster-the-banker-the-deal-his-wife-and-their-cover/">Peter Foster: The banker, the deal, his wife and their cover</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/45ykgmdCv0o/">Adobe patches Reader bugs, releases new JavaScript feature</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/S9fJdap0Bx4/">Adobe Fixes Bugs, Adds JavaScript Whitelisting to Reader, Acrobat</a>
</li>
<li><a href="http://www.cbc.ca/news/politics/story/2012/01/10/pol-pnp-afghan-container.html?cmp=rss">Military gear missing from Afghan mission shipments</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/f0VaF7RKFMg/">Microsoft issues seven security patches, BEAST fix included</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/10/ces-2012-rims-playbook-software-overhaul-brings-hope/">CES 2012: RIMs PlayBook software overhaul brings hope</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/1jpq2IwaFtA/">Microsoft Fixed Eight Bugs in Seven Patches in January&#8217;s Patch Tuesday</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=59286e00d1b1017784c4caa2ef1177df">Microsoft Slays the BEAST, and Six Other Patch Tuesday Updates</a>
</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232400099/guardian-analytics-releases-anomaly-detection-toolkit-inbox.html">Guardian Analytics Releases Anomaly Detection Toolkit Inbox</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232400100/2012-ponemon-report-on-trends-in-security-of-data-recovery.html">2012 Ponemon Report On Trends In Security Of Data Recovery</a>
</li>
<li><a href="http://datalossdb.org/incidents/5433-employment-agency-s-files-including-social-security-numbers-names-contact-info-and-medical-records-disposed-of-by-cleaning-crew-of-landlord">Employment agency&#8217;s files, including Social Security numbers, names, contact info, and medical records, disposed of by cleaning crew of landlord</a>
</li>
<li><a href="http://datalossdb.org/incidents/5429-boxes-filled-with-student-information-including-applications-for-free-and-reduced-price-meals-with-financial-information-thrown-out-by-cleaning-crew">Boxes filled with student information, including applications for free and reduced price meals with financial information, thrown out by cleaning crew</a>
</li>
<li><a href="http://datalossdb.org/incidents/5434-232-hard-drives-containing-patient-information-that-were-being-decommissioned-were-stolen-from-a-locked-store-at-the-hospital-some-wound-up-for-sale-on-ebay">232 hard drives containing patient information that were being decommissioned were stolen from a locked store at the hospital; some wound up for sale on eBay</a>
</li>
<li><a href="http://datalossdb.org/incidents/5432-36-names-e-mail-addresses-and-sha1-passwords-acquired-and-dumped-by-hacker">36 names, e-mail addresses, and SHA1 passwords acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5431-160-names-phone-numbers-e-mail-addresses-clear-text-passwords-birthdates-id-numbers-and-usernames-acquired-and-dumped-by-hacker">160 names, phone numbers, e-mail addresses, clear-text passwords, birthdates, ID numbers, and usernames acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5430-594-names-postal-addresses-sha1-passwords-and-e-mail-addresses-acquired-and-dumped-by-hacker-along-with-database-of-e-mails">594 names, postal addresses, SHA1 passwords, and e-mail addresses acquired and dumped by hacker along with database of e-mails.</a>
</li>
<li><a href="http://datalossdb.org/incidents/5427-5-208-customers-e-mail-addresses-and-clear-text-passwords-acquired-and-dumped-by-hacker">5,208 customers&#8217; e-mail addresses and clear-text passwords acquired and dumped by hacker</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/0NM14R5UEWA/">Polish prosecutor who shot himself at press conference had $800,000 bounty on his head</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=a82fb5f8b4382f9e2b9e97c997a88013">Feds Seek Stronger Security For Power Grid</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=d29e99b239964d5303466f1a70281fda">Avira Teams with secure.me for Facebook Security</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232400082/isc-announces-newly-elected-2012-board-of-directors.html">(ISC) Announces Newly Elected 2012 Board Of Directors</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bb1535e/l/0Lfeatures0Btechworld0N0Csecurity0C332910A20Cdo0Eyou0Eknow0Eyour0Ecyberthreat0Eterms0C0Dolo0Frss/story01.htm">Do you know your cyberthreat terms?</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/10/force-firms-to-disclose-data-breaches-report-urges-2/">Force firms to disclose data breaches, report urges</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/BtsdOddABtg/">Mass SQL Injection Attacks Uses Automated Tools, Search to Infect New Sites</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/4LJW8mHvX-M/">Polish prosecutor says he shot himself in the head at a press conference to expose government corruption</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1bb130c2/l/0Lnews0Btechworld0N0Csecurity0C33290A670Canonymous0Ehackers0Ehit0Ewebsites0Eafter0Epirate0Ebay0Eblock0C0Dolo0Frss/story01.htm">Anonymous hackers hit websites after Pirate Bay block</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/AOZ-GM7i_JA/">Arab League members injured in rebel assault as Assad mocks monitors efforts</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-10</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-10/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-10</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-10/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 13:59:37 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4536</guid>
		<description><![CDATA[InfoSec News for Tuesday January 10, 2012. German cops hacked in revenge for spying dadPayback after officer used cyber-bug to snoop on daughter: An infiltration of a German federal security system last year has been traced back to a botched attempt by an unnamed security official to use a Trojan to monitor his daughter&#8217;s internet [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Tuesday January 10, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/10/german_police_hack_domestic_row_theory/">German cops hacked in revenge for spying dad</a><br />Payback after officer used cyber-bug to snoop on daughter: An infiltration of a German federal security system last year has been traced back to a botched attempt by an unnamed security official to use a Trojan to monitor his daughter&#8217;s internet usage, Der Spiegel reports.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/kA4zrq0IltA/Oracle_s_latest_Java_moves_frustrate_users_and_vendors">Oracle&#8217;s latest Java moves frustrate users and vendors</a><br />The company is under fire for modularization, licensing, and security issues
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/09/apple_rim_indian_government_backdoor/">Apple, RIM deny claims of data backdoor for Indian government</a><br />Symantec hackers claim intelligence memo shows secret deal: Updated Apple and RIM have denied providing the Indian government with backdoor access to customers&#8217; data, after the release of a memo that appears to suggest that they and Nokia did a deal in exchange for access to the Indian smartphone market.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/09/apple_power_adapter_password_recovery/">Apple patent stashes passwords in chargers</a><br />Forgot your login? Your power adapter will spill the beans: Apple has filed a patent on a power adapter that helps users to get back forgotten passwords.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/09/hp_fixes_lasetjet_uberbug/">HP sneaks out printer firebomb firmware security fix</a><br />Says no one has blown up any LaserJets: HP has quietly patched a serious security vulnerability that had left its LaserJet printers open to attack by net villains.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/09/smart_meter_privacy_oops/">Smart meter SSL screw-up exposes punters&#8217; TV habits</a><br />Also showed researchers WHETHER OR NOT THEY WERE HOME: White-hat hackers have exposed the privacy shortcomings of smart meter technology.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/CzkigdB07ds/malware_news.php">Recycled cybercrime tactics adapted to conceal fraud</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120110-delaware-student-takes-top-prize-at-annual-cyber-competition">Delaware student takes top prize at annual cyber competition</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120110-al-qaeda-wants-to-be-your-friend-and-follower">Al Qaeda wants to be your friend and follower</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/010912-cyberthreats-254681.html?source=nww_rss">Do you know your cyberthreats?</a>
</li>
<li><a href="http://datalossdb.org/incidents/5423-337-customers-usernames-clear-text-passwords-account-level-login-count-createdate-and-id-acquired-and-dumped-by-hacker">337 customers&#8217; usernames, clear-text passwords, account level, login count, createdate and id acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5422-201-usernames-and-hashed-passwords-acquired-and-dumped-by-hacker">201 usernames and hashed passwords acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5421-121-names-usernames-clear-text-passwords-landline-and-mobile-phone-numbers-and-e-mail-addresses-acquired-and-dumped-by-hacker">121 names, usernames, clear-text passwords, landline and mobile phone numbers, and e-mail addresses acquired and dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5420-37-names-e-mail-addresses-telephone-numbers-and-md5-with-corresponding-clear-text-passwords">37 names, e-mail addresses, telephone numbers and MD5 with corresponding clear-text passwords</a>
</li>
<li><a href="http://datalossdb.org/incidents/5419-names-of-employees-social-insurance-number-employee-number-bank-account-information-for-employee-direct-deposits-and-latest-payroll-information-were-in-burgled-safe-and-electronic-devices">Names of employees, social insurance number, employee number, bank account information for employee direct deposits, and latest payroll information were in burgled safe and electronic devices</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/09/terence-corcoran-a-war-on-green-radicals/">Terence Corcoran: A war on green radicals</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/righthaven-domain-sold/">Mystery Buyer Wins Auction for Copyright Trolls Domain</a>
</li>
<li><a href="http://www.ottawacitizen.com/health/Ottawa+public+health+unit+reached+cent+Farazli+clinic+patients/5969302/story.html">Ottawa public health unit has reached 90 per cent of Farazli clinic patients</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/X4mUgJ8L_e8/">Israel Likens Credit Card Breach to Terrorist Act</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/GFA8mY6CAFc/">Judge Denies Request to Block Twitter From Handing Over Account Data</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/geeks-sopa/">Geeks to Testify (Finally!) About SOPA Blacklisting Implications</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232301554/unboundid-debuts-industry-s-first-identity-management-products-based-on-scim-specification.html">UnboundID Debuts Industry&#8217;s First Identity Management Products Based On SCIM Specification</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/ZbacoY0d30M/">Energy Department to analyze power grid cyber threats</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/0WqyU06OJLw/">FTC settles with rewards company over security infractions</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/09/ces-2012-apples-mystery-tv-is-the-years-hottest-phantom-gadget/">CES 2012: Apples mystery TV is the years hottest phantom gadget</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/_EYuk33WE3s/">Oracle Beefs Up Database Firewall With SQL Injection Defenses, MySQL</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232301529/prolexic-mitigates-weekend-ddos-attack-for-foundation-source.html">Prolexic Mitigates Weekend DDoS Attack For Foundation Source</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/FQRiSByd5aQ/top-german-cop-uses-spyware-on-daughter-gets-hacked-in-retaliation.ars">Top German cop uses spyware on daughter, gets hacked in retaliation</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/010912-israel-steps-up-rhetoric-against-254651.html?source=nww_rss">Israel steps up rhetoric against credit-card hackers</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/srinfrastructure20120109-government-contractors-now-required-to-have-cybersecurity-plans">Government contractors now required to have cybersecurity plans</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/srinfrastructure20120109-etrade-cyberattack-shuts-down-trading">ETrade cyberattack shuts down trading</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/srinfrastructure20120109-japan-develops-antihacker-weapon">Japan develops anti-hacker weapon</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/WZ-pR-qo3WI/">Secret Service charges Romanian man with ATM fraud</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/tJpl29JfRnc/secworld.php">Cyber attack on Israeli sites considered terrorist operation, says Israeli official</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1ba80e67/l/0Lnews0Btechworld0N0Csecurity0C33287340Cpolice0Earrest0Eatm0Eskimmer0Eafter0E150Emillion0Estolen0C0Dolo0Frss/story01.htm">Police arrest ATM skimmer after $1.5 million stolen</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Z73ctygluwc/">Secret Services charges Romanian man with ATM fraud</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_tech/~3/YvEQ42bVi5M/index.html">Stratfor apparently targeted again by hackers</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-09</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-09/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-09</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-09/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 13:59:38 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4534</guid>
		<description><![CDATA[InfoSec News for Monday January 9, 2012. Virtual Sweatshops Defeat Bot-or-Not TestsJobs in the hi-tech sector can be hard to find, but employers in one corner of the industry are creating hundreds of full-time positions, offering workers on-the-job training and the freedom to work from home. The catch? Employees will likely work for cybercrooks and [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Monday January 9, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/CTMp1fwTqrk/">Virtual Sweatshops Defeat Bot-or-Not Tests</a><br />Jobs in the hi-tech sector can be hard to find, but employers in one corner of the industry are creating hundreds of full-time positions, offering workers on-the-job training and the freedom to work from home. The catch? Employees will likely work for cybercrooks and may make barely enough money in a week to purchase a Happy Meal at McDonald&#8217;s.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/06/symantec_source_code_theft/">Symantec downplays source-code trophy theft</a><br />Indian hackers posted 5-year-old Norton code: Symantec has confirmed earlier versions of its anti-virus source code have leaked, following a security breach of what the company said was the network of a &#8220;third party entity&#8221; rather than their own.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/06/patch_tuesday_pre_alert_jan_2012/">BEAST SSL fix in supersized Patch Tuesday</a><br />Microsoft&#8217;s 2012 kick-off features 7 security bulletins: Microsoft plans to start 2012 with a surprisingly large Patch Tuesday that covers seven security bulletins which collectively address eight separate vulnerabilities. Previous January releases have normally featured only one or two bulletins.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/06/sony_defacement/">Sony website defacer pwned by second hacker</a><br />It&#8217;s a dog-eat-dog world: A defacer affiliated with Anonymous vandalised Sony&#8217;s online front door this week over the corporate behemoth&#8217;s support of SOPA, a hated anti-piracy law proposed in the US.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/06/blackberry_mafia_rim/">Mafia hit suspect cuffed after BlackBerry chatter intercept</a><br />Cops keep schtum on sniffing RIM data: Canadian police have apparently used BlackBerry communications to arrest murder suspect Raynald Desjardins in a move seen as an unprecedented use of intercepted data.
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/5cBkNb5zKA4/part-virus-part-botnet-spreading-fast-ramnit-moves-past-facebook-passwords.ars">Part virus, part botnet, spreading fast: Ramnit moves past Facebook passwords</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120109-umd-lunarline-partner-on-cybersecurity">UMD, Lunarline partner on cybersecurity</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120109-signcryption-technology-tightens-cybersecurity">Signcryption technology tightens cybersecurity</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/V5970jDmmYA/malware_news.php">DotA 2 and Diablo III beta testing crack files carry malware</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/STxqYHextoc/secworld.php">Kaspersky Mobile Security Lite available for free</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/08/rims-alec-saunders-and-the-quest-to-woo-developers-back-to-blackberry/">RIMs quest to woo developers back to BlackBerry</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/8VMjJYwMmss/">DND censors Taliban photos over privacy, national security</a>
</li>
<li><a href="http://datalossdb.org/incidents/5407-30-patients-and-150-students-that-a-hacker-might-have-accessed-their-names-medical-information-and-or-social-security-numbers">30 patients and 150 students that a hacker might have accessed their names, medical information and/or Social Security numbers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5404-employee-stole-over-130-customers-credit-card-numbers">Employee stole over 130 customers&#8217; credit card numbers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5403-nine-laptops-stolen-in-a-burglary-contained-personal-information">Nine laptops stolen in a burglary contained personal information</a>
</li>
<li><a href="http://www.torontosun.com/2012/01/08/israeli-credit-cards-hit-by-cyber-attack">Israeli credit cards hit by cyber attack</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=d674abb76d998b9eb5a2c01ca1f2e930">Israeli Credit Card Numbers Exposed in Cyberattack</a>
</li>
<li><a href="http://datalossdb.org/incidents/5397-bank-customers-details-e-mails-and-gold-purchase-transactions-reportedly-viewable-by-reporters-working-for-bank-owned-newspapers-due-to-failure-to-turn-off-file-sharing-on-shared-server">Bank customers&#8217; details, e-mails, and gold purchase transactions reportedly viewable by reporters working for bank-owned newspapers due to failure to turn off file-sharing on shared server</a>
</li>
<li><a href="http://www.ottawacitizen.com/news/Israel+vows+treat+hackers+like+terrorists/5962029/story.html">Israel vows to treat hackers like &#8216;terrorists&#8217;</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/010612-security-roundup-254619.html?source=nww_rss">Security roundup: DOD revving up cyber-defense for 2012; Microsoft to have big January Patch Tuesday</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/010612-gameover-malware-254623.html?source=nww_rss">FBI warns of new Zeus-based malware in phishing scam</a>
</li>
<li><a href="http://datalossdb.org/incidents/5394-usernames-domain-information-and-hashed-passwords-hacked-via-database-sql-injection">Usernames, domain information and hashed passwords hacked via database SQL injection</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_topstories/~3/lPdT1sYQpqs/index.html">Battle rages on over online privacy bill</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/WPCCC-PIYrs/">Symantec: Hackers did steal code, but it&#8217;s old</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/nLT5hvyYxNU/">Adobe Plans Fixes for Critical 3D Bugs in Reader, Acrobat X</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/MRk8Ifs_oyM/new-slow-motion-dos-attack-just-a-few-pcs-little-fear-of-detection.ars">New slow-motion DoS attack: just a few PCs, little fear of detection</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/scotus-dog-sniffing-case/">Supreme Court to Decide Dog-Sniffing Privacy Case</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/1GLK2tcbLP8/">Symantec Confirms Hackers Stole Outdated Code, Downplays Impact</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/crAHFBj3YiA/">Stratfor subscribers receive phony emails</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/SvugmdsG7Wc/">OpenSSL Fixes Six Flaws in the Secure Sockets Layer Protocol Tool</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/hsbc-skimming-operation/">Romanian Man Charged in $1.5 Million ATM Skimming Scam</a>
</li>
<li><a href="http://www.ottawacitizen.com/news/Saudi+hacker+targets+Israel+with+Trojan+horse+virus/5957243/story.html">&#8216;Saudi&#8217; hacker targets Israel with Trojan horse virus</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/symantec-source-code-leaked/">Hackers Get Symantec Anti-Virus Source Code</a>
</li>
<li><a href="http://datalossdb.org/incidents/5364-email-accounts-of-police-chiefs-as-well-as-files-with-personal-information-of-members-acquired-and-dumped-by-hackers-see-curator-s-note">Email accounts of police chiefs as well as files with personal information of members acquired and dumped by hackers (see Curator&#8217;s note)</a>
</li>
<li><a href="http://datalossdb.org/incidents/5363-personal-data-of-4-44-million-users-including-names-passport-numbers-telephone-numbers-and-dates-of-birth-could-have-been-seen-by-anyone-visiting-the-exit-and-entry-administration-website">Personal data of 4.44 million users including names, passport numbers, telephone numbers and dates of birth could have been seen by anyone visiting the exit and entry administration website</a>
</li>
<li><a href="http://datalossdb.org/incidents/5353-bank-allegedly-revealed-dozens-of-state-employees-names-and-social-security-numbers-to-each-other-when-they-mailed-them-copies-of-subpoenas-they-had-received-for-their-records-from-the-state">Bank allegedly revealed dozens of state employees&#8217; names and Social Security numbers to each other when they mailed them copies of subpoenas they had received for their records from the state</a>
</li>
<li><a href="http://datalossdb.org/incidents/5357-dozens-of-sensitive-files-tossed-in-garbage-outside-the-40th-precinct">Dozens of sensitive files tossed in garbage outside the 40th Precinct</a>
</li>
<li><a href="http://datalossdb.org/incidents/5362-employees-who-had-opted-to-get-2009-or-2010-w-2-forms-electronically-had-their-w-2-data-exposed-online-and-indexed-by-google">Employees who had opted to get 2009 or 2010 W-2 forms electronically had their W-2 data exposed online and indexed by Google</a>
</li>
<li><a href="http://datalossdb.org/incidents/5355-patients-records-from-defunct-businesses-found-near-a-dumpster-unshredded">Patients&#8217; records from defunct businesses found near a dumpster, unshredded</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/8AOdbtpu7LM/iphone-4s-users-are-big-data-hogs-compared-to-iphone-4-users.ars">iPhone 4S users are big data hogs compared to iPhone 4 users</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/T5yLQFKoJjc/secworld.php">Anonymous hacks Sony website and Facebook account</a>
</li>
<li><a href="http://datalossdb.org/incidents/5340-1-678-employee-admin-usernames-clear-text-passwords-and-ids-acquired-and-dumped-by-hacker">1,678 employee/admin usernames, clear-text passwords, and IDs acquired and dumped by hacker</a>
</li>
<li><a href="http://www.ottawacitizen.com/technology/Israel+under+cyber+attack/5957243/story.html">Israel may be under cyber attack</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b9544ff/l/0Lnews0Btechworld0N0Csecurity0C3328250A0Cgoogle0Echrome0Egets0Emalware0Edownload0Eprotection0C0Dolo0Frss/story01.htm">Google Chrome finally gets malware download protection</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=35159bbca46fe96a33c1c5e038a0901b">Facebook Worm Siphons 45,000 Accounts</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Regretsy: Do as we say, not as we do</title>
		<link>http://jacksch.com/2012/01/regretsy-do-as-we-say-not-as-we-do/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=regretsy-do-as-we-say-not-as-we-do</link>
		<comments>http://jacksch.com/2012/01/regretsy-do-as-we-say-not-as-we-do/#comments</comments>
		<pubDate>Sat, 07 Jan 2012 15:00:33 +0000</pubDate>
		<dc:creator>Eric Jacksch</dc:creator>
				<category><![CDATA[Stupidity]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4532</guid>
		<description><![CDATA[Thursday I wrote about the alleged destruction of a violin, based in part upon a letter posted on Regretsy. I also created an account on Regretsy to post a comment that included a note to the original author of the letter asking her to contact me via my web site and a link to my article. [...]]]></description>
			<content:encoded><![CDATA[<p>Thursday I wrote about <a title="PayPal dispute ends in destruction of violin" href="http://jacksch.com/2012/01/paypal-dispute-ends-in-destruction-of-violin/" target="_blank">the alleged destruction of a violin</a>, based in part upon a<a href="http://www.regretsy.com/2012/01/03/from-the-mailbag-27/" target="_blank"> letter posted on Regretsy</a>. I also created an account on Regretsy to post a comment that included a note to the original author of the letter asking her to contact me via my web site and a link to <a title="PayPal dispute ends in destruction of violin" href="http://jacksch.com/2012/01/paypal-dispute-ends-in-destruction-of-violin/" target="_blank">my article</a>.</p>
<p>Apparently the folks at Regretsy don&#8217;t like what I have to say:  They deleted my account and removed my comment.</p>
<p>The mob at Regretsy are very quick to jump on what they perceive to be heavy-handed behaviour by PayPal, but it appears that they don&#8217;t apply the same standards to themselves. And in failing to do so, they call the credibility of the original post and the balance of comments into question. It leaves me wondering if I should Regretsy using them as a source.</p>
<p>Regretsy did not respond to my email inquiry.</p>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/regretsy-do-as-we-say-not-as-we-do/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-06</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-06/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-06</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-06/#comments</comments>
		<pubDate>Fri, 06 Jan 2012 14:02:01 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4529</guid>
		<description><![CDATA[InfoSec News for Friday January 6, 2012. PayPal dispute ends in destruction of violinCNET ran an interesting article yesterday on how a PayPal dispute ended in the destruction of a violin. In summary, the allegation is that the purchaser disputed the authenticity of his $2,500 puchase, PayPal agreed, and they instructed the purchaser to destroy [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Friday January 6, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://jacksch.com/2012/01/paypal-dispute-ends-in-destruction-of-violin/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=paypal-dispute-ends-in-destruction-of-violin">PayPal dispute ends in destruction of violin</a><br />CNET ran an interesting article yesterday on how a PayPal dispute ended in the destruction of a violin. In summary, the allegation is that the purchaser disputed the authenticity of his $2,500 puchase, PayPal agreed, and they instructed the purchaser to destroy the violin it in order to obtain a refund. People are asking a [...]
</li>
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/IIlmTEzu2uo/">Pharma Wars: Mr. Srizbi vs. Mr. Cutwail</a><br />The last post in this series introduced the world to &#8220;Google,&#8221; an alias chosen by the hacker in charge of Cutwail &#8212; currently the world&#8217;s largest spam botnet. Google rented his crime machine to members of SpamIt, an organization that paid spammers to promote rogue Internet pharmacy sites. This made Google a top dog, but also a primary target of other botmasters selling software to SpamIt, particularly the hacker known as &#8220;SPM,&#8221; the guy behind the infamous Srizbi botnet.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/06/aol_im_privacy/">New AOL IM considered harmful by privacy warriors</a><br />EFF baulks at centralised chat logging by default: Privacy advocates have raised concerns about beta versions of AOL&#8217;s latest IM client, urging privacy-sensitive surfers to stay on older versions of the software.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/fAipEloF8XM/Symantec_confirms_source_code_leak_in_two_enterprise_security_products">Symantec confirms source code leak in two enterprise security products</a><br />Symantec late Thursday confirmed that source code used in two of its older enterprise security products was publicly exposed by hackers this week.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/06/ico_enforcement_of_info_rights_to_focus_on_health_sector/">ICO to &#8216;focus&#8217; on health sector when enforcing info rights</a><br />A breach too far?: The Information Commissioner&#8217;s Office (ICO) is to give &#8220;particular regulatory attention&#8221; to health organisations as it focuses on areas most likely to result in damage to people&#8217;s information rights, the watchdog has said.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/06/gchq_offers_retention_bonuses_to_keep_tech_experts/">GCHQ wants to enlarge &#8216;experienced&#8217; specialists&#8217; packages</a><br />Spooks offer &#8216;retention payments&#8217; to keep online security experts: GCHQ is offering its expert tech employees bonuses to prevent more staff from leaving for high-tech companies such as Google and Microsoft.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/5uKdZ3bF-a4/Hacker_group_threatens_to_release_Symantec_AV_source_code">Hacker group threatens to release Symantec AV source code</a><br />Symantec is investigating an Indian hacking group&#8217;s claims that it accessed source code used in the company&#8217;s flagship Norton Antivirus program.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/KlvJqF0XyHc/Microsoft_plans_big_January_Patch_Tuesday">Microsoft plans big January Patch Tuesday</a><br />Microsoft today said it would deliver seven security updates next week &#8212; tying the record for January &#8212; to patch eight vulnerabilities in Windows and its developer tools.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/05/etrade_in_ddos_attack/">Etrade suffers DDOS festive treat</a><br />Gremlins shut down trading: ANZ Bank-owned online broker ETrade, has been the target of a sustained malicious offshore generated cyber attack.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/9LabYWjwIaU/Privacy_2012_I_know_what_you_did_at_3_30_a.m.">Privacy 2012: I know what you did at 3:30 a.m.</a><br />For a peek into what experts expect this year and beyond when it comes to privacy, we turn to the Rebecca Herold (aka the Privacy Professor) for answers.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/05/ramnit_social_networking/">Dammit Ramnit! Worm slurps 45,000 Facebook passwords</a><br />Bank-raid malware is latest nasty to infect social networks: A bank account-raiding worm has started spreading on Facebook, stealing login credentials as it creeps across the site, security researchers have revealed.
</li>
<li><a href="http://business.financialpost.com/2012/01/06/siri-doubles-iphone-data-usage/">Siri doubles iPhone data usage</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/ltRH2K1mHwg/">Deadly suicide bombing kills 25 in Damascus: Syrian state TV</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120106-wireless-passwords-vulnerable-to-hackers-uscert-warns">Wireless passwords vulnerable to hackers, US-CERT warns</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b92f3c6/l/0Lnews0Btechworld0N0Csecurity0C33281840Cinvisible0Edos0Eattack0Edevised0Eby0Ewhite0Ehat0Ehacker0C0Dolo0Frss/story01.htm">Invisible DoS attack devised by white hat hacker</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/occupy-drones/">Livestreaming Journalists Want to Occupy the Skies With Cheap Drones</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=251e0a9f44764fb72f348f0553bfebd9">Ramnit / ZeuS Hybrid Compromises 45,000 Facebook Accounts: What You Should Know</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/01/05/fp-letters-to-the-editor-we-need-ceos-taxes/">FP Letters to the Editor: We need CEOs taxes</a>
</li>
<li><a href="http://www.ottawacitizen.com/Romney+plan+would+balloon+deficit+report/5953691/story.html">Romney tax plan would balloon US deficit: report</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/wikileaks-twitter-bid/">WikiLeaks Supporters Lose Court Bid to Protect Twitter Records</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/OV4qEB-ZML8/">Hackers say they have Symantec&#8217;s Norton AV source code</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Vd3ZFQxX1Ic/">New Ramnit variant steals Facebook logins</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/hnhAeIB4njQ/">Facebook Worm Ramnit Steals Login Credentials, Tests Against Other Services</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/sQGPA1EvsiQ/">Smart Grid Operators Need to Integrate Processes for Security, Compliance</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/tlhpPQhrec4/">Microsoft Plans 7 Fixes for January Patch Tuesday</a>
</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/news/232301377/top-11-trends-for-2012-in-healthcare-data-according-to-industry-experts.html">Top 11 Trends For 2012 In Healthcare Data, According To Industry Experts</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/laptop-password-5th-amendment/">Feds Want Judge to Force Suspect to Give Up Laptop Password</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/c6hv7DepzTk/">Chat Logs Reveal Origins of Cutwail Botnet, Botmaster Identity</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/05/ramnit-malware-targets-facebook-steals-45000-passwords/">Ramnit malware targets Facebook, steals 45,000 passwords</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/_IK7rjKpb2E/">Microsoft preps seven security patches</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/05/ottawa-prepares-to-launch-anti-spam-centre/">Ottawa prepares to launch anti-spam centre</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=877fe18e8cbaa20183393f406f175fb7">SQL Injection Hack Infects 1 Million Web Pages</a>
</li>
<li><a href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16426824">Worm &#8216;steals Facebook passwords&#8217;</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/0XN1zXp_NK0/worm-steals-45000-facebook-login-credentials-infects-victims-friends.ars">Worm steals 45,000 Facebook login credentials, infects victims&#8217; friends</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/EHylclkxZ40/">Gingrich, Obama find common ground in attacking Romney</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/c6q5FAap0mw/">Rick Santorums rivals set to attack after surprising Iowa surge</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/w7QBeRqncVc/icann-pushes-ahead-with-january-12-launch-for-new-top-level-domains.ars">ICANN pushes ahead with January 12 launch for new top-level domains</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/ag1p2XSi9t4/article.php">The antivirus industry and the grayware problem</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-06/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PayPal dispute ends in destruction of violin</title>
		<link>http://jacksch.com/2012/01/paypal-dispute-ends-in-destruction-of-violin/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=paypal-dispute-ends-in-destruction-of-violin</link>
		<comments>http://jacksch.com/2012/01/paypal-dispute-ends-in-destruction-of-violin/#comments</comments>
		<pubDate>Fri, 06 Jan 2012 01:55:53 +0000</pubDate>
		<dc:creator>Eric Jacksch</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4515</guid>
		<description><![CDATA[CNET ran an interesting article yesterday on how a PayPal dispute ended in the destruction of a violin. In summary, the allegation is that the purchaser disputed the authenticity of his $2,500 puchase, PayPal agreed, and they instructed the purchaser to destroy the violin it in order to obtain a refund. People are asking a [...]]]></description>
			<content:encoded><![CDATA[<p>CNET ran an interesting article yesterday on how a <a href="http://news.cnet.com/8301-1023_3-57352627-93/paypal-dispute-ends-in-destruction-of-violin" target="_blank">PayPal dispute ended in the destruction of a violin</a>. In summary, the allegation is that the purchaser disputed the authenticity of his $2,500 puchase, PayPal agreed, and they instructed the purchaser to destroy the violin it in order to obtain a refund.</p>
<p>People are asking a lot of questions about this one, and while I haven&#8217;t heard directly from the seller, her letter is posted on <a href="http://www.regretsy.com/2012/01/03/from-the-mailbag-27/" target="_blank">Regretse</a>. (The buyer&#8217;s identity has not been disclosed.)  The dispute appears to focus on the violin label. I&#8217;m certainly not qualified to discuss violin labels and associated traditions, but these folks are and <a href="http://www.abcviolins.com/labels.html" target="_blank">have something interesting to say</a>.</p>
<p>I was a bit surprised to hear that PayPal had the instrument destroyed rather than returned to the vendor, but I found this in<a href="https://cms.paypal.com/us/cgi-bin/marketingweb?cmd=_render-content&amp;content_ID=ua/UserAgreement_full&amp;locale.x=en_US" target="_blank"> PayPal&#8217;s user agreement</a>:</p>
<blockquote><p>If a buyer files a Significantly Not as Described (SNAD) Claim for an item they purchased from you, you will generally be required to accept the item back and refund the buyer the full purchase price plus original shipping costs. You will not receive a refund on your PayPal fees. Further, if you lose a SNAD Claim because we, in our sole discretion, reasonably believe the item you sold is counterfeit, you will be required to provide a full refund to the buyer and you will not receive the item back (it will be destroyed). PayPal Seller protection will not cover your liability.</p></blockquote>
<p>Merchants take heed &#8212; &#8220;in our sold discretion&#8221; gives PayPal at lot of power.</p>
<p>In response to my query, a PayPal spokesperson replied via email,</p>
<blockquote><p>&#8220;While we cannot talk about this particular case due to PayPal&#8217;s privacy policy, we carefully review each case, and in general we may ask a buyer to destroy counterfeit goods if they supply signed evidence from a knowledgeable third party that the goods are indeed counterfeit.  The reason why we reserve the option to ask the buyer to destroy the goods is that in many countries, including the US,  it is a criminal offense to mail counterfeit goods back to a seller.&#8221;</p></blockquote>
<p>A lot of small businesses rely upon PayPal, and this type of incident causes concern among merchants.  For example, one commenter on Regretsy pointed out,</p>
<blockquote><p>This scheme of PayPal’s makes a great way to perpetuate fraud. Want to swap the fake Vuitton bag you bought on Canal Street for a real one? Just buy that real one on eBay, pay through PayPal and report the ‘fake’!</p></blockquote>
<p>Credit card transactions in general place the burden of proof on the merchant. For example, if I ordered goods and subsequently advised the credit card issuer that the product didn&#8217;t arrive, the merchant would face a chargeback unless they were able to provide strong evidence to the contrary. PayPal adds an additional layer. If a buyer who has purchased through PayPal using a credit card is not satisfied and disputes the charge through their credit card issuer, the burden of proof falls to PayPal.</p>
<p>My point is not to excuse PayPal of their responsibilities.  They&#8217;re in the payment game and need to treat all parties fairly as well as manage their own risk. However, it&#8217;s also not fair to assume that these type of disputes or the potential for merchant losses are specific to PayPal. It&#8217;s also not realistic for sellers to assume that PayPal will protect them from all potential fraud scenarios.</p>
<p>I&#8217;m happy to see PayPal take a strong stand against counterfeit goods, but I just wonder if destroying a violin &#8212; even if the label was wrong &#8212; was the right answer in this case. I suspect executives at PayPal are asking that same question.</p>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/paypal-dispute-ends-in-destruction-of-violin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-05</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-05/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-05</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-05/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 13:59:41 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4512</guid>
		<description><![CDATA[InfoSec News for Thursday January 5, 2012. Amazon Kindle Fire browser hacked for your Android pleasureEveryone gets to be smooth as Silk: Hackers have managed to get Amazon&#8217;s proxy-based Silk browser compiled into other Android versions, allowing anyone* to take advantage of the Amazon cloud. Man convicted of murder gets retrial after virus eats court [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Thursday January 5, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/05/amazon_silk_hack/">Amazon Kindle Fire browser hacked for your Android pleasure</a><br />Everyone gets to be smooth as Silk: Hackers have managed to get Amazon&#8217;s proxy-based Silk browser compiled into other Android versions, allowing anyone* to take advantage of the Amazon cloud.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/05/virus_deletes_court_transcript/">Man convicted of murder gets retrial after virus eats court files</a><br />Official&#8217;s blunder sparks transcript deletion: A US man who had been convicted on a second-degree murder charge will get a new trial after a computer virus destroyed transcripts of court proceedings.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/05/google_opendns_clash/">Sites knocked offline by OpenDNS freeze on Google</a><br />JavaScript-hosting server branded &#8216;phishing&#8217; den: Innocent websites were blocked and labelled phishers on Wednesday following an apparent conflict between OpenDNS and Google&#8217;s Content Delivery Network (CDN).
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/05/kibosh_gas_projectile/">KIBOSH &#8216;non lethal&#8217; sticky-bomb hits a car, fills it with gas</a><br />US Special Ops: We didn&#8217;t kill them, the crash did: US special operations troops will shortly be armed with a projectile which can be fired from a portable launcher to hit a car or boat some distance off, following which the pocket-size adhesive bomb will release one of several types of &#8220;non lethal&#8221; gas into the target&#8217;s interior. The new weapon has been dubbed the &#8220;KIBOSH&#8221; by the secret super-troopers&#8217; procurement office.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/zTtgV6bRWIQ/Two_new_security_books_ponder_how_vulnerable_we_are">Two new security books ponder how vulnerable we are</a><br />Two recently-published books, &#8220;America the Vulnerable&#8221; by Joel Brenner, a former official at the National Security Agency (NSA) and &#8220;When Gadgets Betray Us,&#8221; by writer and security analyst Robert Vamosi, have one theme in common: We&#8217;ve come to depend on modern networks and technology, but the compromise of them by attackers is a serious threat to both individuals and society as a whole.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/04/pastebin_ddos_recovery/">Pastebin on the mend after DDoS battering</a><br />Were hacktivists the real target?: Popular text file sharing service Pastebin.com has returned online following a denial of service attack on Tuesday.
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120105-smartphone-users-hold-false-sense-of-security">Smartphone users hold false sense of security</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b8b7fc3/l/0Lnews0Btechworld0N0Csecurity0C33279210Ccare2com0Esocial0Enetwork0Eaccounts0Ebreached0Eby0Ehackers0C0Dolo0Frss/story01.htm">Care2.com social network accounts breached by hackers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/BjWLqtOrsuM/secworld.php">Over 1M pages compromised in massive SQL injection attack</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b8a7e0c/l/0Lnews0Btechworld0N0Csecurity0C33279140Canonymous0Ehackers0Ehit0Enazi0Ehate0Esites0C0Dolo0Frss/story01.htm">Anonymous hackers hit Nazi hate sites</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/EqoIadjN1OQ/">After 18 years, $6-million and a change of laws, Stephen Lawrences killers jailed</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/JPid219-NSs/">ZyXEL Melds Low-Cost IP Security Cameras with Remote Access Via the Cloud</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/Ft0SGVfEmJs/">Analysis of Stratfor Site Breach Reveals Weak Passwords, Poor Enforcement</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/Nf0LKUk-e4Q/big-content-applerim-vs-kodak-infringement-suit-proves-rights-holders-need-censorship-powers.ars">RIAA: Kodak/Apple/RIM patent tangle proves we need Web censorship fast</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/9ZWUOHFw62M/">Amazon Web Services Adds Cloud-Based Check Point Security Gateways</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/04/as-bills-climb-for-some-small-internet-firms-cry-foul-over-crtc-ruling/">Small Internet firms cry foul over CRTC ruling, file fresh complaint</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/04/kodak-shares-plunge-after-report-132-year-old-firm-preparing-bankruptcy-filing/">Kodak shares plunge after report that firm preparing bankruptcy filing</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/jHq-tNyq2DI/hands-on-hacking-wifi-protected-setup-with-reaver.ars">Hands-on: hacking WiFi Protected Setup with Reaver</a>
</li>
<li><a href="http://www.darkreading.com/advanced-threats/167901091/security/news/232301279/new-pike-research-report-spotlights-growing-need-for-integrated-approach-to-security.html">New Pike Research Report Spotlights Growing Need For Integrated Approach To Security</a>
</li>
<li><a href="http://www.networkworld.com/news/2012/010412-spyeye-malware-borrows-zeus-trick-254513.html?source=nww_rss">SpyEye malware borrows Zeus trick to mask fraud</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/cLpMGZLdFDo/">At 10 years old, Internet Explorer 6 is almost an artifact</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232301255/check-point-partners-with-amazon-to-offer-new-security-solution-in-the-cloud.html">Check Point Partners With Amazon To Offer New Security Solution In The Cloud</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/FPefsAMgKus/">Fujitsu Working on &#8216;Good Virus&#8217; to Seek and Destroy Attacking Systems</a>
</li>
<li><a href="http://www.darkreading.com/security-services/167801101/security/news/232301240/ul-expands-global-payment-and-security-evaluation-services-with-acquisition-of-witham-laboratories.html">UL Expands Global Payment And Security Evaluation Services With Acquisition Of Witham Laboratories</a>
</li>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/news/232301242/metricstream-and-qualys-partnership-brings-actionable-security-and-risk-intelligence-to-it-grc.html">MetricStream And Qualys Partnership Brings Actionable Security And Risk Intelligence To IT-GRC</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-05/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-04</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-04/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-04</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-04/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 13:59:39 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4510</guid>
		<description><![CDATA[InfoSec News for Wednesday January 4, 2012. Anonymous hunts neo-Nazis with WikiLeaks-style siteLoads of alleged donors and right-wing players to send those pizzas to: Members of Anonymous have re-doubled their offensive against German neo-Nazis. Saudi hackers plaster 14,000 credit card privates on webRaid on Israeli sites exposes up to 400,000 punters: A Saudi Arabian hacking [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Wednesday January 4, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/04/anon_op_blitzkrieg/">Anonymous hunts neo-Nazis with WikiLeaks-style site</a><br />Loads of alleged donors and right-wing players to send those pizzas to: Members of Anonymous have re-doubled their offensive against German neo-Nazis.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/04/israel_credit_card_hack_fallout/">Saudi hackers plaster 14,000 credit card privates on web</a><br />Raid on Israeli sites exposes up to 400,000 punters: A Saudi Arabian hacking group claims it has leaked information on up to 400,000 Israelis, including names, addresses and credit card details.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/04/fujitsu_virus_japanese_government/">Fujitsu creates antivirus virus for Japanese government</a><br />Code seeks out and destroys malware and botnet systems: Fujitsu has developed code for the Japanese government that will destroy malware and collect information on its creators.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/qL6b8anvKqk/Researcher_Many_Stratfor_passwords_are_weak">Researcher: Many Stratfor passwords are weak</a><br />At Utah Valley University, 120 computers are now working to decode encrypted passwords revealed by the hack of Stratfor Global Intelligence, one of the most significant data breaches of last year.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/03/stratfor_mega_hack/">Stratfor so very, very sorry in wake of mega-hack</a><br />Private spook biz still reeling from credit card data raid: The website of global intelligence-analysing firm Stratfor remains offline &#8211; a week after hacktivists broke into its poorly secured systems and extracted passwords and credit card details.
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b833cb2/l/0Lnews0Btechworld0N0Csecurity0C3327720A0Cstratfor0Ebreach0Eshows0Ethat0Epasswords0Eare0Eweak0Esays0Eutah0Evalley0C0Dolo0Frss/story01.htm">Stratfor breach shows that passwords are weak, says Utah Valley</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/GLf6iZLGl8U/secworld.php">Risk Control 6.0 released</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/KeLOXXYtE6s/secworld.php">Israeli credit card hack creates more opportunities</a>
</li>
<li><a href="http://business.financialpost.com/2012/01/03/pirate-party-discovers-illegal-downloading-in-the-house-of-commons/">Pirate Party discovers illegal downloading in the House of Commons</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/1Kcelz1F1jc/">California union latest Anonymous police victim</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/F5e3WC5J0Ag/">Enterprises Need Encryption to Secure Private Data</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/01/warrantless-gps-monitoring/">No Warrant Needed for GPS Monitoring, Judge Rules</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/K101c-uDue0/">Latest Apple iOS Jailbreak Tool Exploits Two Security Flaws</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/6xJCEEOaoGo/">NYPD arrest man suspected in Islamic centre fire-bombing</a>
</li>
<li><a href="http://www.cbc.ca/news/business/story/2012/01/03/sci-cyber-threats.html?cmp=rss">5 top cyber threats for 2012</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b7d62d6/l/0Lnews0Btechworld0N0Csecurity0C33275480Cjapan0Etesting0Evirus0Ecyberdefence0Eweapon0Ereports0Esay0C0Dolo0Frss/story01.htm">Japan testing &#8216;virus&#8217; cyberdefence weapon, reports say</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/n-pEoPuP4Hs/malware_news.php">Defensive search-and-destroy &#8220;virus&#8221; delivered to Japanese government</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b7c633b/l/0Lnews0Btechworld0N0Csecurity0C332750A20Cmurder0Eretrial0Eordered0Eafter0Ecourt0Erecords0Edestroyed0Eby0Evirus0C0Dolo0Frss/story01.htm">Murder retrial ordered after court records destroyed by virus</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/gF-z1875_Lc/">PhoneFactor</a>
</li>
<li><a href="http://www.thestar.com/news/world/article/1109785--alleged-saudi-hackers-disclose-credit-card-information-of-thousands-of-israelis">Alleged Saudi hackers disclose credit card information of thousands of Israelis</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/-B0cm0GxJ5U/">Cold case murder probe after womans body is found on Queens country estate</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/IaYGX2URlvY/secworld.php">AntiSec hackers hit California State Law Enforcement Association</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/yYCpAsgYICE/">Entrust IdentityGuard</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/tGdJ8WEDRFw/">DigitalPersona Pro Enterprise v5.2</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/MqeXmPlIAYs/">Deepnet Security DualShield v5.2</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/ugqQ3djm9ek/">Cryptocard Blackshield Server v3.1</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/ChLPH63s5Mk/">ActivIdentity 4TRESS Authentication Appliance FT2011</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-04/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-03</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-03/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-03</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-03/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 13:59:39 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4508</guid>
		<description><![CDATA[InfoSec News for Tuesday January 3, 2012. Japan tasks Fujitsu with creating search-and-destroy cyber-weaponZombie boss hunter developed in lab: Fujitsu has been commissioned to develop seek and destroy malware, reportedly designed to track and disable the sources of cyber-attacks. Cloud SWAT teamsCloud computing poses unique security challenges. Here&#8217;s how cloud-specific &#8216;security incident-response teams&#8217; could help [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Tuesday January 3, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/03/japan_cyber_weapon_research/">Japan tasks Fujitsu with creating search-and-destroy cyber-weapon</a><br />Zombie boss hunter developed in lab: Fujitsu has been commissioned to develop seek and destroy malware, reportedly designed to track and disable the sources of cyber-attacks.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/z5uJ8uNZa3M/Cloud_SWAT_teams">Cloud SWAT teams</a><br />Cloud computing poses unique security challenges. Here&#8217;s how cloud-specific &#8216;security incident-response teams&#8217; could help governments and large enterprises respond to malicious activity and make the cloud more trustworthy. <i>Insider (registration required)</i>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120103-raytheon-acquires-cybersecurity-specialist">Raytheon acquires cybersecurity specialist</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20120103-mcafee-releases-2012-cyber-threat-predictions">McAfee releases 2012 cyber threat predictions</a>
</li>
<li><a href="http://datalossdb.org/incidents/5324-2-519-first-and-last-names-usernames-clear-text-passwords-e-mail-addresses-as-well-as-dozens-of-full-credit-card-numbers-with-expiration-dates-and-e-mail-spools-dumped-by-hackers">2,519 first and last names, usernames, clear-text passwords, e-mail addresses, as well as dozens of full credit card numbers with expiration dates and e-mail spools dumped by hackers</a>
</li>
<li><a href="http://datalossdb.org/incidents/5323-a-small-fraction-of-its-12-million-users-verified-account-information-acquired-by-hackers">A &#8220;small fraction&#8221; of its 12 million users&#8217; verified account information acquired by hackers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/VV92QMHINns/malware_news.php">Stuxnet and Duqu created on same platform, say researchers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/Mf4Z4G2rDcY/">Snipers, still a threat as Syrian military hovers on outskirts of cities: Arab League head</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/bvwL6t0f6Bc/">Iran test fires long-range missiles near the Strait of Hormuz</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-03/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-01-02</title>
		<link>http://jacksch.com/2012/01/infosec-news-2012-01-02/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-01-02</link>
		<comments>http://jacksch.com/2012/01/infosec-news-2012-01-02/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 13:59:42 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4506</guid>
		<description><![CDATA[InfoSec News for Monday January 2, 2012. Pharma Wars: Google, the Cutwail BotmasterPrevious stories in my Pharma Wars series have identified top kingpins behind the world&#8217;s largest spam botnets. Today&#8217;s post includes never-before-published information on &#8220;Google,&#8221; the secretive hacker in charge of the infamous Cutwail botnet. Another year, another Telstra privacy slipCustomer list pops up [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Monday January 2, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/_FRDClb9yU4/">Pharma Wars: Google, the Cutwail Botmaster</a><br />Previous stories in my Pharma Wars series have identified top kingpins behind the world&#8217;s largest spam botnets. Today&#8217;s post includes never-before-published information on &#8220;Google,&#8221; the secretive hacker in charge of the infamous Cutwail botnet.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/01/telstra_data_on_stupid_insecure_cloud_spreadsheet/">Another year, another Telstra privacy slip</a><br />Customer list pops up on cloud spreadsheet service: Telstra, which hasnt yet gotten over the privacy breach that required 60,000 password resets in December, has suffered another embarrassment involving customer data.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/01/01/reg_review_of_2011_part_two/">2011 <i>Reg</i> roundup: Hacking hacks, spying apps and an end to Einstein?</a><br />Smartphones, privacy and a year of tears: Part Two As mobile sales and connections continued to soar and break records, just how much your phone knows about you and who can see that information were big subjects in 2011.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/27Tcqumb9Us/Two_new_tools_exploit_router_security_setup_problem">Two new tools exploit router security setup problem</a><br />Researchers have released two tools that can take advantage of a weakness in a system designed to let people easily secure their wireless routers.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/uG-H1OMRJ2Y/malware_news.php">Fake Amazon smartphone shipping confirmation leads to malware</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b7211ec/l/0Lnews0Btechworld0N0Csecurity0C33273230Canonymous0Estrikes0Eagain0Ehackers0Erelease0Eelite0Eresearch0Efirms0Esubscriber0Edata0C0Dolo0Frss/story01.htm">Anonymous strikes again? Hackers release elite research firm&#8217;s subscriber data</a>
</li>
<li><a href="http://datalossdb.org/incidents/5321-2-784-forum-usernames-clear-text-passwords-and-e-mail-addresses-dumped-by-hacker">2,784 forum usernames, clear-text passwords, and e-mail addresses dumped by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5314-names-mileage-plus-numbers-future-flight-itineraries-with-confirmation-codes-and-previous-trip-info-of-20-people-available-to-individual-who-logged-in-to-mobile-web-site">Names, Mileage Plus numbers, future flight itineraries with confirmation codes, and previous trip info of 20 people available to individual who logged in to mobile web site</a>
</li>
<li><a href="http://datalossdb.org/incidents/5313-194-usernames-e-mail-addresses-ip-addresses-and-easily-decrypted-md5-passwords-posted-to-web-by-hacker">194 usernames, e-mail addresses, IP addresses, and easily decrypted MD5 passwords posted to web by hacker</a>
</li>
<li><a href="http://datalossdb.org/incidents/5311-a-spreadsheet-with-e-mail-addresses-dates-of-birth-and-phone-numbers-of-more-than-a-thousand-bigpond-customers-uploaded-to-an-external-site-by-a-consultant-in-training">A spreadsheet with e-mail addresses,dates of birth, and phone numbers of more than a thousand BigPond customers uploaded to an external site by a consultant in training</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/0Y3StzH1tL0/">Arab Leauge advisory body urges monitors to withdraw from Syria over violence</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/jvbNAItuVs8/">Duqu, Stuxnet Built on Common Platform With Other Similar Super-Malware</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/rXvKy4UVq5Y/">Latest Phishing Scams Target Users of New Christmas Gadgets</a>
</li>
<li><a href="http://datalossdb.org/incidents/5306-17-900-617-members-notified-of-forced-password-reset-after-hacker-accesses-limited-number-of-users-logins">17,900,617 members notified of forced password reset after hacker accesses &#8220;limited number&#8221; of users&#8217; logins</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2011/12/boston-subpoena-twitter/">Boston D.A. Subpoenas Twitter Over Occupy Boston, Anonymous</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/CXJdGC3LfgY/">Anonymous publishes Stratfor customer data</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2011/12/occupy-wall-street-music/">Beyond Blowin in the Wind: The Music of Occupy Wall Street</a>
</li>
<li><a href="http://www.networkworld.com/news/2011/123011-hacking-group-releases-more-stratfor-254449.html?source=nww_rss">Hacking group releases more Stratfor subscriber data</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/j66OJcHE-Vc/">Raytheon Buys Henggeler Computer Consultants for Key Intelligence Contracts</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/1b65e950/l/0Lnews0Btechworld0N0Csecurity0C3327240A0Cstuxnet0Eduqu0Epart0Eof0Elarger0Ecyberweapon0Ecampaign0C0Dolo0Frss/story01.htm">Stuxnet and Duqu part of larger cybermalware campaign</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/XZgxXYFO-3o/">Dell, Cisco, IBM Among Top Buyers of Security Companies in 2011</a>
</li>
<li><a href="http://feeds.pcworld.com/click.phdo?i=db5fa548727ce97daf284c8447ae891d">Microsoft Ruins Perfect Record with Out-Of-Band Patch</a>
</li>
<li><a href="http://business.financialpost.com/2011/12/30/letter-shows-hp-ex-ceo-hurd-pursued-sex-with-former-contractor/">Letter shows HP ex-CEO Hurd pursued sex with former contractor</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/01/infosec-news-2012-01-02/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2011-12-30</title>
		<link>http://jacksch.com/2011/12/infosec-news-2011-12-30/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2011-12-30</link>
		<comments>http://jacksch.com/2011/12/infosec-news-2011-12-30/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 13:59:45 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4504</guid>
		<description><![CDATA[InfoSec News for Friday December 30, 2011. New Tools Bypass Wireless Router SecuritySecurity researchers have released new tools that can bypass the encryption used to protect many types of wireless routers. Ironically, the tools take advantage of design flaws in a technology pushed by the wireless industry that was intended to make the security features [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Friday December 30, 2011.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/MDTyV7KO540/">New Tools Bypass Wireless Router Security</a><br />Security researchers have released new tools that can bypass the encryption used to protect many types of wireless routers. Ironically, the tools take advantage of design flaws in a technology pushed by the wireless industry that was intended to make the security features of modern routers easier to use.
<p>At issue is a technology that ships with most modern consumer wireless routers, called &#8220;Wi-Fi Protected Setup&#8221; (WPS). According to the Wi-Fi Alliance, an industry group, WPS is &#8220;designed to ease the task of setting up and configuring security on wireless local area networks. WPS enables typical users who possess little understanding of traditional Wi-Fi configuration and security settings to automatically configure new wireless networks, add new devices and enable security.&#8221;</p>
</li>
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/8UEuUFvZFWM/">Happy 2nd Birthday, KrebsOnSecurity.com!</a><br />I&#8217;m taking a short break from some year-end downtime to observe that KrebsOnSecurity.com turns two years old today!
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/12/30/chinese_space_white_paper/">New Chinese space plans are all about security and strategy on Earth</a><br />Nothing much to do with manned or deep space exploring: Analysis Chinese officials have published a new white paper detailing China&#8217;s aspirations in space for coming years. Most media have chosen to focus on Beijing&#8217;s vague aspirations toward deep-space and manned exploration, but in fact the concrete details given all point toward a primary emphasis on strategic advantage for China here on Earth.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/12/30/kaspersky_stuxnet_duqu_link/">Kaspersky claims smoking code linking Stuxnet and Duqu</a><br />Warns of three other unknown variants: Researchers at Kaspersky Lab are claiming to have found proof that the writers of the Stuxnet and Duqu malware are one and the same, and are warning of at least three new families of advanced malware potentially in circulation.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/12/29/wi_fi_not_protected/">Wi-Fi Protected Setup easily unlocked by security flaw</a><br />Couple of hours of brute force will crack a network&#8217;s PIN: Security researcher Stefan Viehbck has demonstrated a critical flaw in the Wi-Fi Protected standard that opens up routers to attack and has prompted a US-CERT Vulnerability notice.
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=c3fba65345a52470344554bee993753f">Bits Blog: Hackers Release More Data From Stratfor</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2011/12/anonymous-101-part-deux/">Anonymous 101 Part Deux: Morals Triumph Over Lulz</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/4HARTtzQqLE/">Son-in-law of Spanish King charged in fraud case</a>
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=cb07c2e9844557643f7f2278151e82f9">Hacker Attacks Like Stratfors Require Fast Response</a>
</li>
<li><a href="http://datalossdb.org/incidents/5304-2-967-names-addresses-and-full-credit-card-numbers-with-what-may-be-expiration-dates-and-cvv-s-from-german-austrian-and-swiss-customers-posted-on-web">2,967 names, addresses, and full credit card numbers with what may be expiration dates and CVV&#8217;s from German, Austrian, and Swiss customers posted on web</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2011/12/dragnet-surveillance-case/">Court Revives NSA Dragnet Surveillance Case</a>
</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232301143/stratfor-taps-csid-to-protect-identities-breached-in-cyberattack.html">Stratfor Taps CSID To Protect Identities Breached In Cyberattack</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/ohbZ5aUZRhU/">Book of Lists: 2011&#8242;s strongest trends, weirdest news</a>
</li>
<li><a href="http://business.financialpost.com/2011/12/29/race-for-facebook-likers-heats-up/">Race for Facebook Likers heats up</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/zqoZO_HVuQ8/">Microsoft delivers rare out-of-band patch for ASP.NET issue</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/McSMn4rS_Jc/">Flaw Makes WiFi Network Security Vulnerable to Brute-Force Attacks: US-CERT</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/ZCu6fC2cA0o/">Microsoft Patches ASP.NET Vulnerability</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/-3M22rS7w3g/">Mobile Phone Users Remain Lax about Cyber-Security, Says McAfee</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=b140043ee3d756134af5ebbb4840e42e">Stuxnet, Duqu Date Back To 2007, Researcher Says</a>
</li>
<li><a href="http://datalossdb.org/incidents/5299-laptop-and-external-hard-drive-stolen-from-an-employee-s-car-contained-names-social-security-numbers-driver-s-license-numbers-dates-of-birth-and-phone-numbers-of-those-undergoing-drug-testing-and-those-doing-the-testing">Laptop and external hard drive stolen from an employees car contained names, Social Security numbers, driver&#8217;s license numbers, dates of birth, and phone numbers of those undergoing drug testing and those doing the testing</a>
</li>
<li><a href="http://datalossdb.org/incidents/5296-backup-tapes-or-disks-with-personal-details-of-1-4-million-loan-customers-as-well-as-data-on-some-employees-reported-missing">Backup tapes or disks with personal details of 1.4 million loan customers as well as data on some employees reported missing</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/lmHd8Z6pcc0/moving-files-through-the-cloud-your-favorite-free-file-sharing-services.ars">Moving files through the cloud: your favorite free file-sharing services</a>
</li>
<li><a href="http://www.darkreading.com/security/news/232301120/prolexic-issues-dirt-jumper-threat-advisory-and-releases-free-security-scanner.html">Prolexic Issues Dirt Jumper Threat Advisory And Releases Free Security Scanner</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/P0lLUA-c5zw/">Kim Jong-un declared North Koreas supreme leader as mourning period ends</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/K0NqaYvJRLo/malware_news.php">Beware of password-protected documents carrying malware</a>
</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232301119/hitachi-id-systems-releases-2011-data-security-survey-results.html">Hitachi ID Systems Releases 2011 Data Security Survey Results</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2011/12/infosec-news-2011-12-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2011-12-29</title>
		<link>http://jacksch.com/2011/12/infosec-news-2011-12-29/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2011-12-29</link>
		<comments>http://jacksch.com/2011/12/infosec-news-2011-12-29/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 14:33:28 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4501</guid>
		<description><![CDATA[InfoSec News for Thursday December 29, 2011. Microsoft announces ASP.NET zero-day vulnWorkaround ahead of patch: Just in case anybodys got a BOFH working at the moment, pay attention: Microsoft has released a security advisory covering a zero-day vulnerability in ASP.NET. Stratfor attackers prep to publish emailsThats if you trust the Pastebin posts: Someone claiming to [...]]]></description>
			<content:encoded><![CDATA[<p>InfoSec News for Thursday December 29, 2011.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/12/28/ms_zero_day/">Microsoft announces ASP.NET zero-day vuln</a><br />Workaround ahead of patch: Just in case anybodys got a BOFH working at the moment, pay attention: Microsoft has released a security advisory covering a zero-day vulnerability in ASP.NET.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/12/28/stratfor_part_b/">Stratfor attackers prep to publish emails</a><br />Thats if you trust the Pastebin posts: Someone claiming to speak or at least post on behalf of Antisec has published a threat on Pastebin that they are planning to release e-mails obtained in the Stratfor Global Intelligence break-in.
</li>
<li><a href="http://feeds.nytimes.com/click.phdo?i=863f6ac789f9149ec8973a846109f4bb">Bits Blog: Stratfor Hackers Claim Another Attack</a>
</li>
<li><a href="http://datalossdb.org/incidents/5295-1-336-social-security-and-driver-s-license-numbers-and-patients-medical-records-stolen-by-employee">1,336 Social Security and driver&#8217;s license numbers and patients&#8217; medical records stolen by employee</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2011/12/civil-liberties-ip/">2011: The Year Intellectual Property Trumped Civil Liberties</a>
</li>
<li><a href="http://datalossdb.org/incidents/5295-1-300-social-security-and-driver-s-license-numbers-and-patients-medical-records-stolen-by-employee">1,300 Social Security and driver&#8217;s license numbers and patients&#8217; medical records stolen by employee</a>
</li>
<li><a href="http://datalossdb.org/incidents/5291-3-079-patients-social-security-numbers-birthdates-account-numbers-disability-codes-and-diagnoses-on-stolen-computers-from-physician-s-office">3,079 patients Social Security numbers, birthdates, account numbers, disability codes and diagnoses on stolen computers from physician&#8217;s office</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/CGTlymG5FcM/">Criminals Used Affiliate Marketing Sites in Majority of Facebook Scams in 2011</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/Tn2qDDsWYYw/">CSOs Should Address Risks and Network Visibility With Board of Directors</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/T8QctggbPtM/">Talented hackers could shut down train lines: security expert</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/IfXpCSC3MZw/">Email from The New York Times meant for 300, sent to 8M</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/Yvp_cE209OQ/spammers-take-control-of-new-york-times-e-mail-list.ars">New York Times mistakenly spams 8 million people</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/s9uCUWo8gmc/">Vulnerability allows brute force hacking of wireleless routers</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/a3Dbfr8b4AM/">Microsoft Releases Workarounds for DoS Zero-Day Bug in ASP.NET</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=d412498c8cb167b7e48ef10d34d50381">Aggressive Phishing Attack Targets Military Personnel</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Fhpp8H73z_E/">Microsoft scrambles to address widespread ASP.NET bug</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/KhQnyGpvkxs/antisec-hits-private-intel-firm-millions-of-docs-allegedly-lifted.ars">Antisec hits private intel firm; millions of docs allegedly lifted</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/5fZTmRmtzYk/">Anonymous, RSA Lead the Top IT Security News of 2011</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2011/12/infosec-news-2011-12-29/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

