<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Security by Eric Jacksch</title>
	<atom:link href="http://jacksch.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://jacksch.com</link>
	<description>Infosec and cyber security news and viewpoints from a security professional with over 15 years in the trenches.</description>
	<lastBuildDate>Thu, 18 Apr 2013 16:02:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Passwords &#8211; Another Perspective</title>
		<link>http://jacksch.com/2013/04/passwords-another-perspective/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=passwords-another-perspective</link>
		<comments>http://jacksch.com/2013/04/passwords-another-perspective/#comments</comments>
		<pubDate>Tue, 16 Apr 2013 14:10:23 +0000</pubDate>
		<dc:creator>Eric Jacksch</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8949</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[<p><img class="alignnone" alt="" src="http://imgs.xkcd.com/comics/password_strength.png" width="592" height="481" /></p>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2013/04/passwords-another-perspective/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Java: Just Another Vulnerability Announcement</title>
		<link>http://jacksch.com/2013/02/java-just-another-vulnerability-announcement/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=java-just-another-vulnerability-announcement</link>
		<comments>http://jacksch.com/2013/02/java-just-another-vulnerability-announcement/#comments</comments>
		<pubDate>Mon, 04 Feb 2013 14:56:10 +0000</pubDate>
		<dc:creator>Eric Jacksch</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8882</guid>
		<description><![CDATA[On the heels of releasing a patch to address a vulnerab [...]]]></description>
				<content:encoded><![CDATA[<p>On the heels of releasing a patch to address a vulnerability so serious that some users uninstalled Java, Oracle has again released a “<a href="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" target="_blank">Critical Patch Update</a>” to address about fifty vulnerabilities, one of which is being actively exploited.</p>
<p>Yet, despite their horrible track record, Oracle continues to tell users that it “provides safe and secure access to the word of amazing Java content.”</p>
<p>&#160;</p>
<p><a href="http://jacksch.com/wp-content/uploads/java-install.jpg"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="java-install" border="0" alt="java-install" src="http://jacksch.com/wp-content/uploads/java-install_thumb.jpg" width="454" height="345" /></a></p>
<p>&#160;</p>
<p>Software security has few absolutes – and Java is a living (or perhaps dying) example of how poorly a lot of software is designed.&#160; It’s time for Oracle to wake up and smells the <strike>java</strike> coffee.</p>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2013/02/java-just-another-vulnerability-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Headlines for Wednesday January 16, 2013</title>
		<link>http://jacksch.com/2013/01/headlines-for-wednesday-january-16-2013/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=headlines-for-wednesday-january-16-2013</link>
		<comments>http://jacksch.com/2013/01/headlines-for-wednesday-january-16-2013/#comments</comments>
		<pubDate>Wed, 16 Jan 2013 14:00:45 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8863</guid>
		<description><![CDATA[Spam Volumes: Past &#38; Present, Global &#38; LocalLas [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/NC6_gZFQOqk/">Spam Volumes: Past &amp; Present, Global &amp; Local</a><br />Last week, National Public Radio aired a story on my Pharma Wars series, which chronicles an epic battle between men who ran two competing cybercrime empires that used spam to pimp online pharmacy sites. As I was working with the NPR reporter on the story, I was struck by how much spam has decreased over the past couple of years. Below is a graphic that&#8217;s based on spam data collected by Symantec&#8217;s MessageLabs. It shows that global spam volumes fell and spiked fairly regularly, from highs of 6 trillion messages sent per month to just below 1 trillion. I produced this graph based on Symantec&#8217;s raw spam data.<br />
<h5>Related Posts:</h5>
<ul>
<li>Taking Stock of Rustock</li>
<li>Spam Volumes Dip After Spamit.com Closure</li>
<li>Harvesting Data on the Xarvester Botmaster</li>
<li>Feds Convict Stock Scammers, Overlook Spammers</li>
<li>Top Spam Botnet, &#8220;Grum,&#8221; Unplugged</li>
</ul>
<p><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/gTBmNY0PNeo/Think_tank_presses_Blue_Coat_over_censorship_concerns">Think tank presses Blue Coat over censorship concerns</a><br />A Canadian think tank called on Tuesday for continued scrutiny of U.S. security vendor Blue Coat Systems after a new technical analysis showed wide use of its products in countries with human rights and censorship concerns.</p>
<p><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/3pBv5_Ycc5Y/Congresswoman_proposes_computer_fraud_law_amendment_to_honor_Aaron_Swartz">Congresswoman proposes computer fraud law amendment to honor Aaron Swartz</a><br />A draft bill to exclude terms of service violations from the Computer Fraud and Abuse Act is to be introduced in the U.S. House of Representatives.</p>
<p><a href="http://go.theregister.com/feed/www.theregister.co.uk/2013/01/16/developer_oursources_job_china/">Security audit finds dev OUTSOURCED his JOB to China</a><br />Cunning scheme netted him &#8216;best in company&#8217; awards: A security audit of a US critical infrastructure company last year revealed that its star developer had outsourced his own job to a Chinese subcontractor and was spending all his work time playing around on the internet.</p>
<p><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/sJsahtP-Apc/Malware_infects_US_power_facilities_through_USB_drives">Malware infects US power facilities through USB drives</a><br />Two U.S. power companies reported infections of malware during the past three months, with the bad software apparently brought in through tainted USB drives, according to the U.S. Department of Homeland Security&#8217;s Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).</p>
<p><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/yGdofRqPdrk/6Scan_launches_free_website_vulnerability_and_malware_scanning_service">6Scan launches free website vulnerability and malware scanning service</a><br />6Scan, a Web security startup based in Tel Aviv, Israel, launched a new service on Tuesday that can scan websites for security issues, like vulnerabilities and malware infections, and allows their owners to automatically fix the identified problems.</p>
<p><a href="http://go.theregister.com/feed/www.theregister.co.uk/2013/01/15/avoid_java_in_browsers/">Latest Java patch is not enough, warns US gov: Axe plugins NOW</a><br />Metasploit boss says Oracle needs TWO years to make everything good: Security experts advise users to not run Java in their web browsers despite a patch from Oracle that mitigates a widely exploited security vulnerability.</p>
<p><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/WiUVdFMgBOc/Java_exploit_used_in_Red_October_cyberespionage_attacks_researchers_say">Java exploit used in Red October cyberespionage attacks, researchers say</a><br />The hundreds of government, military and research organizations targeted in a large-scale cyberespionage operation dubbed Red October were not only attacked using malicious Excel and Word documents, but also with Web-based Java exploits, according to Seculert researchers.</p>
<p><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/LcZembQuo68/">Wombat Unveils Social Engineering Security Training Module</a><br />The training explains the psychology behind social attacks and gives practical tips for recognizing and avoiding them. </img> </img> </img> </img></p>
<p><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/iuvY5X-3oH4/secworld.php">Company bosses slacking on hacking</a><br />Company bosses across the UK have a complacent attitude toward cybercrime and are inviting criminal attacks due to their sloppy approach to internet security, reveals new research from Swivel Secure. &#8230;</p>
<p><a href="/news/world/South+Korea+accuses+North+Korea+launching+cyberattack+against/7826183/story.html">South Korea accuses North Korea of launching cyberattack against conservative Seoul newspaper</a><br />SEOUL, South Korea &#8211; South Korea says North Korea was behind a cyberattack against a conservative Seoul newspaper critical of Pyongyang.</p>
<p><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/YdXFwbIas_4/">Sandy Hook Truthers claim Newtown school massacre a hoax to spur gun control measures</a><br />Their theories appear to lack any basis in fact or common sense. But the movement is gaining momentum with both a college professor and a Fox News anchor questioning the official narrative</p>
<p><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/V3XLj_FUm7w/">Quebec to legalize assisted suicide; Death a medical issue, health minister says</a><br />A panel has recommended the provincial government allow what it calls medical assistance to die in cases where a patient is close to death and unable to endure the pain</p>
<p><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/ljZmvYCcXVA/">AMD accuses former top employees of stealing over 100,000 documents</a><br />Chip maker says the defendants gave trade secrets to their new employer, NVIDIA.</p>
<p><a href="http://www.ottawasun.com/2013/01/15/probe-into-privacy-breach-of-thousands-to-take-months">Probe into privacy breach of thousands to take months RANDY RICHMOND, QMI Agency</a><br />An investigation into the loss of sensitive medical and employment information of about 5,000 Canadians is likely months from completion.</p>
<p><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/sbwJsqJ2ULQ/">A great movie script: Quebec man accused of heading $1B marijuana smuggling operation</a><br />Jimmy Cournoyer lived a playboy lifestyle with a professional model girlfriend, an elite $2-million sports car and lavish parties until it came to an end when he was arrested in Mexico</p>
<p><a href="http://business.financialpost.com/2013/01/15/facebooks-friends-based-foray-into-search-puts-user-data-to-work/">Facebooks friends-based foray into search puts user data to work</a><br />On Tuesday, the worlds largest social network unveiled a new tool dubbed Graph Search, which enables Facebook users to quickly search their friends interests, locations and photos</p>
<p><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/D6AEilnYclE/">Majority of Canadians concerned about financial accountability on First Nations reserves: poll</a><br />More than four out of five Canadians say they dont want more money sent to aboriginal reserves unless proper, independent audits are conducted to ensure financial accountability</p>
<p><a href="http://www.thestar.com/news/canada/article/1315525--class-action-lawsuit-launched-against-government-over-missing-student-loan-info">Class action lawsuit launched against government over missing student loan info</a><br />A Newfoundland lawyer will file a class-action lawsuit Wednesday in court against the Federal department that lost the personal information of 583,000 student loan borrowers.</p>
<p><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/inGjpKr_Qpc/story01.htm">Virut malware fuels Waledac botnet resurgence</a><br />This may not be the first time Virut has been used to spread the Waledac worm, whose goal is to earn money for its purveyors through rogue ad networks, online pharmacies, or outright fraud.</p>
<p><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/HJXvkhNSYSc/online-privacy-is-a-serious-matter-so-why-do-few-people-care.html">Online Privacy Is a Serious Matter, So Why Do Few People Care?</a><br />Facebook, Google and other collect and use consumer information in ways few people understand. It&#8217;s time to stop being so naive, say analysts. </img> </img> </img> </img></p>
<p><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/o1IKo2pQSfQ/">Two US power plants infected with malware spread via USB drive</a><br />Investigators find no up-to-date antivirus, system backups for control systems.</p>
<p><a href="http://darkreading.com/mobile-security/167901113/security/news/240146338/commtouch-s-new-mobile-security-for-android-combats-fast-growing-number-of-mobile-threats.html">Commtouch&#8217;s New Mobile Security For Android Combats Fast-Growing Number Of Mobile Threats</a><br />Solution offers cloud-assisted antivirus and Web security services</p>
<p><a href="http://www.torontosun.com/2013/01/15/feds-lose-student-loan-data-for-583000-people">Feds lose student loan data for 583,000 people QMI Agency</a><br />The federal government has lost a USB stick containing the personal information of more than half a million student loan borrowers.</p>
<p><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/arMuSj6uYzs/">Texas congressman threatens impeachment as Barack Obama considers taking executive action on gun control</a><br />Facing powerful opposition to sweeping gun regulations, President Barack Obama is weighing 19 steps that could be taken through executive action alone, congressional officials said.</p>
<p><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/LQ2gbMoGFnk/story01.htm">&#8220;Red October&#8221; spy campaign uncovered, rivals Flame virus</a><br />Researchers at Kaspersky believe the Red October campaign, which is spreading a data-sucking trojan known as Rocra, dates back at least five years, and is still ongoing.</p>
<p><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Tqy0hqOHOG8/malware_news.php">Automated YouTube account generator offered to cyber crooks</a><br />You&#8217;re a spammer / malware peddler / phisher, and want to register hundreds of bogus accounts on a popular online service such as YouTube in order to lead users to your wares. But, you don&#8217;t want to c&#8230;</p>
<p><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/4WjvPcz384E/secworld.php">Wombat unveils social engineering security training module</a><br />Wombat released its social engineering training module to defend against social engineering threats, including spear phishing and social media-based attacks. Commonly defined as the art of exploiti&#8230;</p>
<p><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/WN521ydo3GY/malware_news.php">Waledac botmasters use Virut malware to build a new botnet</a><br />Despite having been swooped down on by security companies and law enforcement a couple of times, the botmasters of the Waledac (Kelihos) botnet refuse to give up and are using new variants to set up n&#8230;</p>
<p><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/HN9DJ-iU8Xc/">Quebec and Ontario top Canadas health care rankings while Newfoundland lags behind</a><br />The ranking compares the availability and quality of health services with their costs, and finds that spending more does not necessarily mean a better system</p>
<p><a href="http://www.ama-assn.org/amednews/2013/01/14/bisd0115.htm">HHS settles first small data breach case at medical practice</a><br />The agreement underscores the importance of mobile device security and routine risk assessments.</p>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2013/01/headlines-for-wednesday-january-16-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>To Java or Not to Java</title>
		<link>http://jacksch.com/2013/01/to-java-or-not-to-java/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=to-java-or-not-to-java</link>
		<comments>http://jacksch.com/2013/01/to-java-or-not-to-java/#comments</comments>
		<pubDate>Sun, 13 Jan 2013 17:08:45 +0000</pubDate>
		<dc:creator>Eric Jacksch</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8850</guid>
		<description><![CDATA[This week discussions of Java and its latest security f [...]]]></description>
				<content:encoded><![CDATA[<p>This week discussions of Java and its latest security flaw has dominated information security discussions  It&#8217;s not often that the <a href="http://www.dhs.gov" target="_blank">U.S. Department of Homeland Security</a> tells users point blank to <a href="http://www.us-cert.gov/cas/techalerts/TA13-010A.html" target="_blank">temporarily disable java in their web browser</a>. As one would expect, every blogger seems to have an opinion and they range from &#8220;they sky is falling&#8221; to &#8220;DHS is over-reacting.&#8221; Standing out from the crowd, Brian Krebbs deserves kudos for his <a href="http://krebsonsecurity.com/2013/01/what-you-need-to-know-about-the-java-exploit/" target="_blank">solid, well-researched article on the issu</a><a href="http://krebsonsecurity.com/2013/01/what-you-need-to-know-about-the-java-exploit/" target="_blank">e</a>.</p>
<p>So what&#8217;s my take on it?</p>
<p>First of all, there are three reasons that DHS may have made such a strong recommendation:</p>
<ol>
<li>Their intelligence may indicate that the vulnerability is (or has the potential to be) exploited so frequently that it is a legitimate national security concern;</li>
<li>They may be over-reacting; or,</li>
<li>They may be frustrated with Oracle and applying pressure to fix Java.</li>
</ol>
<p>While I don&#8217;t know what intelligence they have, I&#8217;d bet on a combination of 1 and 3.</p>
<p>For an exploitation to occur, a user has to visit a web site containing the malware. Those at highest risk are those who visit marginal web sites looking for porn, music, movies, and other material to download. However, malware may be left on compromised web sites and users directed to malware-laden sites through phishing-like emails. To some degree, we are all at risk.</p>
<p>So the question users face: To Java or not to Java?</p>
<p>At the risk of stating the obvious,  if you don&#8217;t really need Java uninstall it completely from your computer. Java has a poor security record. There is simply no point to having it installed if you don&#8217;t need it. If you&#8217;re unsure whether you need Java on your personal computer, uninstall it anyway. It&#8217;s easy to re-install the latest version if it turns out you really need it.</p>
<p>If you have a genuine need for Java applications installed on your PC, disable the java plug-in in your browser. Instructions to disable it in all browsers or selectively are <a href="http://www.java.com/en/download/help/disable_browser.xml" target="_blank">here</a>.</p>
<p>If you must use a web site that uses Java, the two browser approach is likely your best bet. Note that there is no way to selectively disable Java in Microsoft Internet Explorer (one of many reasons that IE should not be your routine use web browser), so your best bet is to install <a href="https://www.google.com/intl/en/chrome/browser/" target="_blank">Google Chrome</a> and disable the java plug in. (For a shortcut, type &#8220;chrome://plugins/&#8221; into the URL box.)</p>
<p>On the topic of Chrome, if you prefer a more secure browser environment in general, try turning on Chrome&#8217;s &#8220;click to play&#8221; option for plug-ins. Instead of plug-ins running automatically, you&#8217;ll have to click on them to load. Some users  might find it annoying, but it will stop web sites from automatically launching plug-ins, including Java.  You can find the option at &#8220;chrome://chrome/settings/content&#8221;:</p>
<p style="text-align: center;"><a href="http://jacksch.com/wp-content/uploads/chrome-click-to-play.jpg"><img class="size-full wp-image-8853 aligncenter" alt="chrome-click-to-play" src="http://jacksch.com/wp-content/uploads/chrome-click-to-play.jpg" width="320" height="206" /></a></p>
<p>&nbsp;</p>
<p>*** UPDATED 2013-01-14 ***</p>
<p>Oracle has released an out-of-cycle update to Java to address this issue.  Windows users who wish the patch ASAP should go to Control Panel -&gt; Java, select the Update tab, and click on &#8220;Update Now&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2013/01/to-java-or-not-to-java/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-31</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-31/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-31</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-31/#comments</comments>
		<pubDate>Mon, 31 Dec 2012 14:00:49 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8819</guid>
		<description><![CDATA[InfoSec News for Monday December 31, 2012. Attackers Ta [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Monday December 31, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/rfqkkhpc6BE/">Attackers Target Internet Explorer Zero-Day Flaw</a><br />Attackers are breaking into Microsoft Windows computers using a newly discovered vulnerability in Internet Explorer, security experts warn. While the flaw appears to have been used mainly in targeted attacks so far, this vulnerability could become more widely exploited if incorporated into commercial crimeware kits sold in the underground.
</li>
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/1nLBsoQ5vsk/">Happy 3rd Birthday KrebsOnSecurity.com!</a><br />It&#8217;s difficult to believe I&#8217;ve been doing this solo thing for so long, but as a thoughtful reader just reminded me, Dec. 29 marks the third anniversary of the KrebsOnSecurity.com blog! This past year, KrebsOnSecurity featured nearly 200 blog posts, entries that have generated some 5,700 reader comments. Reader feedback and comments add tremendous value [...]
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/a7aZHtRLDGM/Microsoft_confirms_zero_day_bug_in_IE6_IE7_and_IE8">Microsoft confirms zero-day bug in IE6, IE7 and IE8</a><br />Microsoft on Saturday confirmed that Internet Explorer (IE) 6, 7 and 8 contain an unpatched bug &#8212; or &#8220;zero-day&#8221; vulnerability &#8212; that is being used by attackers to hijack victims&#8217; Windows computers.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/OSGu-PX2_8o/Why_Social_networks_should_be_more_like_Facebook_Poke">Why Social networks should be more like Facebook Poke</a><br />When it comes to Facebook users and their messages, almost nobody knows who can see or share their posts on social networks. And that&#8217;s a problem that must be fixed, says Mike Elgan.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/29/bloomberg_blames_apple_for_crime_spike/">NYC mayor pins crime rate spike on iPhone, iPad theft</a><br />If it weren&#8217;t for Apple kit, crime would be down: Major crime is on the rise in New York City, and Mayor Michael Bloomberg says the increase is due entirely to thefts of Apple&#8217;s iPhone and iPad devices, which he says are inordinately attractive to thieves.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/TDO3wYdtrdw/Researchers_find_malware_targeting_Java_HTTP_servers">Researchers find malware targeting Java HTTP servers</a><br />Security researchers from antivirus vendor Trend Micro have uncovered a piece of backdoor-type malware that infects Java-based HTTP servers and allows attackers to execute malicious commands on the underlying systems.
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/xtyfc1fN30g/">Vancouver-bound tour bus crashes in Oregon, killing nine people and injuring at least 20 others</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/gsvUOnIK2zM/secworld.php">The threat landscape continues to expand rapidly</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/nKuWYwc5wLU/">Crowd-sourcing site shuts down B.C. writers fundraiser for Syrian relatives trapped in war-torn Aleppo</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/6zbB0-f5UO8/secworld.php">Database hacking: The year that was</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/gNIJRzPU-KM/">Microsoft says IE 6, 7, and 8 vulnerable to remote code execution</a>
</li>
<li><a href="http://www.ottawacitizen.com/news/national/Hacker+Public+Works+went+unnoticed+days+documents+show/7758531/story.html">Hacker at Public Works went unnoticed for days, documents show</a>
</li>
<li><a href="http://www.thestar.com/news/gta/article/1308440--concern-mounts-among-those-affected-by-federal-government-privacy-breach">Concern mounts among those affected by federal government privacy breach</a>
</li>
<li><a href="http://www.ottawacitizen.com/business/Cyber+crooks+shifting+smartphones/7756840/story.html">Cyber crooks shifting to smartphones</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/TUUa8-SyWE0/">Most everything went wrong: Three years after an earthquake devastated Haiti, the reconstruction has barely begun</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/FHBJ5op72zQ/">Higgs boson discovery may signal the worlds last physics experiment as scientists struggle to come up with next big question</a>
</li>
<li><a href="http://www.cbc.ca/news/politics/story/2012/12/28/privacy-commissioner-hrdsc-lost-info-personal.html?cmp=rss">Personal info for thousands lost by federal government</a>
</li>
<li><a href="http://darkreading.com/vulnerability-management/167901026/security/news/240145367/pandalabs-reveals-most-unique-viruses-of-2012-in-its-annual-virus-yearbook.html">PandaLabs Reveals Most Unique Viruses Of 2012 In Its Annual Virus Yearbook</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/gdyrkuCtzvg/">Personal information data of thousands of Canadians lost by federal government</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/s0mMbGAyrgM/">You have a job to do and you do it: The rewarding and horrifying job of fighting child porn in Canada</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/kYOPp5TL9Pw/">DDoS Attacks on Major Banks Causing Problems for Customers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/4eMU8qRwYXI/story01.htm">Mobile threats predicted top concern for 2013</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/2e6Di0xZsPs/">North Korea is ready to conduct a third nuclear test, satellite photos show</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/senate-fisa-amendments/">Senate Approves Warrantless Electronic Spy Powers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/dYv2JXOmTD0/story01.htm">Malware that steals from point-of-sale systems detected</a>
</li>
<li><a href="http://darkreading.com/mobile-security/167901113/security/news/240145357/cybersecurity-a-vital-new-year-s-resolution-for-business-and-consumers.html">Cybersecurity &#8212; A Vital New Year&#8217;s Resolution For Business And Consumers</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/G7XslfX0Ma4/">Looking back: the five most important security stories of 2012</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/J4Ow2B-vycI/">Victim of hours-long gang rape fighting for her life in hospital as teen in second attack commits suicide</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-31/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-28</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-28/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-28</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-28/#comments</comments>
		<pubDate>Fri, 28 Dec 2012 14:00:37 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8818</guid>
		<description><![CDATA[InfoSec News for Friday December 28, 2012. Drones, phon [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Friday December 28, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/0ukPt61pOJo/Drones_phones_and_other_2012_privacy_threats">Drones, phones and other 2012 privacy threats</a><br />Verizon&#8217;s attempt to secure a patent for a so-called &#8216;snooping technology,&#8217; which in this case would let television advertisers target individual viewers based on what they&#8217;re doing or saying in front of their sets, capped another challenging year for privacy advocates.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/27/wordpress_cache_plugin_vulnerable/">New WordPress vuln emerges</a><br />W3 Total Cache has faulty defaults: Sorry to spoil the day for any sysadmins that thought today would be a slow day, but a security researcher has announced a serious vulnerability in the default configuration of a popular WordPress plugin.
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/BJ8YqK9EAe0/">Weve lost an American original: Desert Storm commander Stormin Norman Schwarzkopf dies at 78</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/gN22wKYDE3Q/">McAfee Labs predicts the decline of Anonymous</a>
</li>
<li><a href="http://www.cbc.ca/news/yourcommunity/2012/12/randi-zuckerberg-mocked-for-complaining-about-facebook-photo-leak.html?cmp=rss">Randi Zuckerberg mocked for Facebook privacy confusion</a>
</li>
<li><a href="http://www.itnews.com.au/News/327412,analysts-anonymous-to-decline-in-2013.aspx?utm_source=feed&amp;utm_medium=rss&amp;utm_campaign=iTnews+All+Articles+feed">Analysts: Anonymous to decline in 2013</a>
</li>
<li><a href="http://www.pheedcontent.com/click.phdo?i=d3ad683314f14b41c5f44ec862f61220">FTC Tightens Children&#8217;s Online Privacy Protection Act Regulation</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/Ofx85CgF-JA/">What the&#8230;? Tech stories that made us do a double take</a>
</li>
<li><a href="http://darkreading.com/security/news/240145342/sophos-unveils-thirteen-it-security-trends-for-2013.html">Sophos Unveils Thirteen IT Security Trends For 2013</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/XVoI93Ah53I/">U.S. gun control debate rages after newspaper publishes addresses of pistol permit holders</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/9lu8TT4KhUY/">Paranoid China tightens Internet controls even more after Communists embarrassed by online reports</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-28/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-27</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-27/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-27</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-27/#comments</comments>
		<pubDate>Thu, 27 Dec 2012 14:00:38 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8817</guid>
		<description><![CDATA[InfoSec News for Thursday December 27, 2012. Ransomware [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Thursday December 27, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/_Ee2XTfvvW8/Ransomware_scammers_push_panic_button_with_bogus_claims">Ransomware scammers push panic button with bogus claims</a><br />Cyber extortionists shilling &#8220;ransomware&#8221; have upped the ante by pushing users&#8217; panic buttons with claims that their malware will wipe hard drives, a security firm said Monday.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/j6RA49UrMig/Iranian_official_disputes_report_that_power_station_was_hit_by_virus_attack">Iranian official disputes report that power station was hit by virus attack</a><br />A power station in the south of Iran has been hit by a cyberattack, an Iranian news agency reported Tuesday, citing a local civil defense official. But now agency and official are in dispute over whether he really made the remarks.
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/FFo_magP2Ak/">Year in Ideas: How vital oil infrastructure became a villain in Canada</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/Fc6zg87sbhA/">Enterprises Starved for Security Threat Data to Justify Budget Hikes</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/2012-year-in-review/">From Internet Uprisings to John McAfee: The Year in Privacy and Security</a>
</li>
<li><a href="http://www.torontosun.com/2012/12/26/mark-zuckerbergs-sister-angry-over-facebook-privacy-breach">Mark Zuckerbergs sister angry over Facebook privacy breach Alexander C. Kaufman, TheWrap.com</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/2MV26qR_YX8/story01.htm">Another Iran facility hit with cyber attack, perhaps</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/JYSzl1KD7ug/story01.htm">Obama may issue cyber security order in early January</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-27/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-26</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-26/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-26</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-26/#comments</comments>
		<pubDate>Wed, 26 Dec 2012 14:00:33 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8816</guid>
		<description><![CDATA[InfoSec News for Wednesday December 26, 2012. Exploring [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Wednesday December 26, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/KfWsL4FjRkE/">Exploring the Market for Stolen Passwords</a><br />Not long ago, PCs compromised by malware were put to a limited number of fraudulent uses, including spam, click fraud and denial-of-service attacks. These days, computer crooks are extracting and selling a much broader array of data stolen from hacked systems, including passwords and associated email credentials tied to a variety of online retailers.
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/black-boxes-privacy/">Feds Requiring Black Boxes in All Motor Vehicles</a>
</li>
<li><a href="http://www.itnews.com.au/News/327308,iran-deflects-cyber-attack-on-industrial-sites.aspx?utm_source=feed&amp;utm_medium=rss&amp;utm_campaign=iTnews+All+Articles+feed">Iran deflects cyber attack on industrial sites</a>
</li>
<li><a href="http://www.bbc.co.uk/news/world-middle-east-20842113#sa-ns_mchannel=rss&amp;ns_source=PublicRSS20-sa">Iran &#8216;fends off new cyber attack&#8217;</a>
</li>
<li><a href="http://www.nytimes.com/2012/12/25/sports/hackers-of-steubenville-football-teams-web-site-demand-apology-in-rape-case.html?partner=rss&amp;emc=rss">Hackers of Steubenville Football Teams Web Site Demand Apology in Rape Case</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-26/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-25</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-25/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-25</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-25/#comments</comments>
		<pubDate>Tue, 25 Dec 2012 14:00:32 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8815</guid>
		<description><![CDATA[InfoSec News for Tuesday December 25, 2012. Top 12 Secu [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Tuesday December 25, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/NhwcoQlpK3g/Top_12_Security_Slideshows_of_2012">Top 12 Security Slideshows of 2012</a><br />As 2012 comes to a close, it&#8217;s time to reflect on the security trends of the year with this look at the hottest security slideshows of 2012.
</li>
<li><a href="http://business.financialpost.com/2012/12/24/instagram-furor-triggers-first-class-action-lawsuit-over-terms-of-service-changes/">Instagram furor triggers first class action lawsuit over terms of service changes</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/24/rim-pricing-power-with-carriers-slips-as-stock-continues-tanking/">RIM pricing power with carriers slips as stock continues tanking</a>
</li>
<li><a href="/news/world/Iranian+news+agency+reports+another+cyberattack+Stuxnet+worm/7742262/story.html">Iranian news agency reports another cyberattack by Stuxnet worm targeting industries in south</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-25/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-24</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-24/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-24</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-24/#comments</comments>
		<pubDate>Mon, 24 Dec 2012 14:00:35 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8814</guid>
		<description><![CDATA[InfoSec News for Monday December 24, 2012. Google to sc [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Monday December 24, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/23/google_bans_auto_install_chrome_extensions/">Google to scan Chrome extensions, bans auto-install</a><br />Google-as-curator is upon us: Google has taken two steps to prevent its Chrome browser becoming an attack vector for malware that runs as extensions to the browser.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/jeSLvzbCV_k/ProtectMyID_from_Experian_helps_guard_against_identity_theft">ProtectMyID from Experian helps guard against identity theft</a><br />Identity theft is scary business, for sure. But it&#8217;s a threat that seems a whole lot less likely once you sign up for ProtectMyID, an online identity theft protection service that comes from Experian, a trusted credit-reporting company. ProtectMyID is not cheap though, as it costs $16 per month for regular monitoring.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/Ulsrr37zJbk/Instagram_takes_a_hit_but_users_may_be_too_addicted_to_quit">Instagram takes a hit, but users may be too addicted to quit</a><br />Even though it backed away from a controversial change to its Terms of Use policy, Instagram&#8217;s once glossy image has taken a big hit.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/21/amazon_app_store_dodgy_app/">&#8216;Shake to charge&#8217;, similar crapps foul up Amazon Android store</a><br />Thrown out of Google Play, now back in another bazaar: Security researchers have sniffed out dodgy apps floating around the Amazon App Store for Android-powered devices.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/3ix4eVKNQJY/Poor_SCADA_security_will_keep_attackers_and_researchers_busy_in_2013">Poor SCADA security will keep attackers and researchers busy in 2013</a><br />An increasing number of vulnerability researchers will focus their attention on industrial control systems (ICS) in the year to come, but so will cyberattackers, security experts believe.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/DtLVxPuWLLM/Stabuniq_malware_found_on_servers_at_U.S._financial_institutions">Stabuniq malware found on servers at U.S. financial institutions</a><br />Security researchers from Symantec have identified an information-stealing Trojan program that was used to infect computer servers belonging to various U.S. financial institutions.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/u6WSGpXkWqM/1Password_for_iOS_keeps_your_digital_life_safe">1Password for iOS keeps your digital life safe</a><br />For a security mechanism that has existed since mankind traded places with apes to raise to the top of the food chain, passwords have shown a surprising longevity. Passwords act as gatekeepers to our email, banking, social media accounts, and just about anything else that we do, regardless of whether we are online or not.
</li>
<li><a href="http://business.financialpost.com/2012/12/24/amazon-google-on-collision-course-in-2013-as-competition-in-ads-retail-mobile-heat-up/">Amazon, Google on collision course in 2013 as competition in ads, retail, mobile heat up</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/niDcJPZfOmA/">Where OS X security stands after a volatile 2012</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/FlOq9HyfJbg/">Justice Canada study says spousal abuse costs country at least $7.4 billion a year</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/uXETGaQBw2k/">Canadian psycho Luka Magnotta named Canadian Press Newsmaker of the Year</a>
</li>
<li><a href="/news/world/Vatican+convenes+journalists+papal+pardon+expected+exbutler/7737235/story.html">Vatican convenes journalists, papal pardon expected for ex-butler who stole, leaked documents</a>
</li>
<li><a href="http://www.ottawasun.com/2012/12/21/laptop-stolen-in-transpo-bus-swarming">Laptop stolen in Transpo bus swarming Mike Aubry</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/c_pSkmf4-qY/">This is not an Old West shootout. Were talking about an elementary school: Teachers, parents angry at NRAs guns-in-schools proposal</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/BjQZPb1PPR4/story01.htm">National banking regulator advises on DDoS deluge</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/gvsERehTxKU/">Symantec finds a new trojan that steals data from US banks, customers</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/Xb4ZpAXZyV4/">Congress tweaks US video-privacy law so Netflix can get on Facebook</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/s0sk3JqsAjg/">Prosecutors acted improperly in vetting jurors but misconduct wont quash convictions, Supreme Court rules</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/congress-caves-privacy/">Congress Defeats E-mail Privacy Legislation Again</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240145242/eset-mobile-malware-botnets-attacks-on-the-cloud-and-data-breaches-expected-to-grow.html">ESET: Mobile Malware, Botnets, Attacks On The Cloud And Data Breaches Expected To Grow</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/RIgjESxtm5o/">NRA calls for armed police in every U.S. school, mental illness registry in response to Newtown massacre</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/21/rims-service-fee-change-spurs-stock-dive/">RIMs service-fee change spurs stock dive</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/kBSqbvj__k0/secworld.php">Mobile malware, botnets and attacks on the cloud to rise</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/2LmgFstv8xI/">North Korea says it has detained a U.S. citizen after obtaining confession for crimes</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=94388750f20df486d852eca050cfe68d">9 Ways Hacktivists Shocked The World In 2012</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-24/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-21</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-21/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-21</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-21/#comments</comments>
		<pubDate>Fri, 21 Dec 2012 14:00:33 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8813</guid>
		<description><![CDATA[InfoSec News for Friday December 21, 2012. China &#8216 [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Friday December 21, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/21/china_blocks_vpns/">China &#8216;enhances&#8217; Great Firewall, teaches it to choke off VPNs</a><br />If we sniff a private virty network&#8230; you&#8217;re toast: China has tightened the screws on its infamous web-filtering system, according to virtual private network providers.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/21/mayan_apocalypse_malware/">End of days: Possessed POWERPOINT predicts Mayan Apocalypse</a><br />Hardly the end of the world, OR IS IT?: Miscreants have crammed malware into a Microsoft PowerPoint presentation about today&#8217;s supposed Mayan Apocalypse. If someone emails you a .ppt slideshow titled Will the world end in 2012?, give it a wide berth unless the world really does end today and you&#8217;re feeling wild.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/21/itunes_https_shift_routes_around_great_firewall/">Apple shifts iTunes to HTTPS, sidesteps Chinas censors</a><br />Great Firewall foiled for now: Apple has adopted HTTPS for searches and downloads on the version of iTunes used in China. The move comes at a time when China&#8217;s government prepares to step up regulation of online app stores and continues its crackdown on VPNs.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/21/indian_government_email_hacked/">10,000 Indian government and military emails hacked</a><br />State-sponsored snoopers suspected of large scale incursion: Indias government and military have suffered one of the worst cyber attacks in the nations history, after over 10,000 email accounts belonging to top officials were compromised, despite a warning from the countrys cyber security agency.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/kAtPcyO3Wfc/Wells_Fargo_39_s_website_buckles_under_flood_of_traffic">Wells Fargo&#8217;s website buckles under flood of traffic</a><br />Well Fargo urged its customers on Thursday to visit bank branches or use telephone banking due to continuing problems with its website.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/JYCFkGs2XFw/Digital_Citizens_group_focuses_on_Internet_safety">Digital Citizens group focuses on Internet safety</a><br />An Internet safety education campaign will point out scams and other online dangers with an initial target audience of children and seniors.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/0Zn1aP108bk/VMware_patches_39_critical_39_vulnerability">VMware patches &#8216;critical&#8217; vulnerability</a><br />VMware has issued a patch for its VMware View product that fixes a security vulnerability that could allow an unauthorized user to access system files.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/h8cH5eot-sc/FCC_offers_security_advice_to_smartphone_users">FCC offers security advice to smartphone users</a><br />The U.S. Federal Communications Commission is advising smartphone users on how to protect their mobile devices and data from mobile security threats.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/fvrCNR5t9ck/Containerization_and_mobile_threats">Containerization and mobile threats</a><br />For a short and very enjoyable history lesson, watch this Youtube video.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/20/prosecute_foreign_hackers_plan/">US: We&#8217;ll drag cyber-spies into COURT from their hideouts</a><br />&#8216;And Iran to prosecute American programmers for Stuxnet?&#8217;: The US Department of Justice has floated a plan to advance criminal prosecutions against cyber-spies.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/20/elcomsoft_tool_decrypts_pgp/">PGP, TrueCrypt-encrypted files CRACKED by 300 tool</a><br />Plod at the door? Better yank out that power cable: ElcomSoft has built a utility that forages for encryption keys in snapshots of a PC&#8217;s memory to decrypt PGP and TrueCrypt-protected data.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/LfFrPpphveQ/secworld.php">Guidance on cybersecurity, private clouds and privacy</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/PEqFi2so61c/secworld.php">Lancope releases new threat intelligence for detecting attacks</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/U1xMxKqv9jw/malware_news.php">Sudoku puzzle generating spreadsheet carries malware</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20121221-part-two-nnsa-and-private-contractors-nuclear-safety-culture-responsible-for-y12-security-breach">Part Two: NNSA and private contractors nuclear safety culture responsible for Y-12 security breach?</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/12/20/liberals-join-union-defence/">Liberals join union defence</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240145185/trustonic-provides-new-standard-of-trust-and-security-for-connected-device.html">Trustonic Provides New Standard Of Trust And Security For Connected Device</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240145165/voltage-partners-with-perspecsys-to-improve-cloud-data-protection.html">Voltage Partners With PerspecSys To Improve Cloud Data Protection</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/pkjspPqqR6I/story01.htm">Stabuniq trojan found on servers at U.S. banks</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/20/rim-earnings-live-can-the-blackberry-maker-gain-momentum-ahead-of-bb10/">RIM earnings live: Can the BlackBerry maker gain momentum ahead of BB10?</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/net-neutrality-data-bill/">Net Neutrality, Data-Cap Legislation Lands in Senate</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/rNeieOeIBjg/story01.htm">BBB warns of fake charity sites after Newtown shooting</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/F8c6a2um5qo/">IBM Security Access Manager 7.0 Now Available</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/qiRhUXf07TQ/">Obama Administration Outlines National Information Sharing Strategy</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/trnTxg_6WNo/">Senator introduces bill to regulate data caps</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/IgHZtLKk9ek/">Behind closed doors at the UN&#8217;s attempted &#8220;takeover of the Internet&#8221;</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/2AAbpVHDNY8/">The price for a Canadian passport is going up from $87 to $120</a>
</li>
<li><a href="http://darkreading.com/insider-threat/167801100/security/news/240145147/duke-energy-warns-carolinas-customers-about-bill-payment-scam.html">Duke Energy Warns Carolinas Customers About Bill Payment Scam</a>
</li>
<li><a href="http://darkreading.com/authentication/167901072/security/news/240145130/new-automated-risk-based-payment-fraud-prevention-application.html">New Automated Risk-Based Payment Fraud Prevention Application</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/lDkIynA5h74/">UpClicker Trojan Aims to Foil Automated Analysis</a>
</li>
<li><a href="http://darkreading.com/database-security/167901020/security/news/240145129/survey-61-of-it-security-professionals-say-businesses-more-vulnerable-to-attack-during-holidays.html">Survey: 61% Of IT Security Professionals Say Businesses More Vulnerable To Attack During Holidays</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/6hJkr1UGIdM/">State Department tells John Kerry-led panel that security weaknesses led to deadly assault on Libyan consulate</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-21/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-20</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-20/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-20</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-20/#comments</comments>
		<pubDate>Thu, 20 Dec 2012 14:00:32 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8810</guid>
		<description><![CDATA[InfoSec News for Thursday December 20, 2012. Shocking D [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Thursday December 20, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/_rcg_N094hU/">Shocking Delay in Fixing Adobe Shockwave Bug</a><br />The Department of Homeland Security&#8217;s U.S. Computer Emergency Readiness Team (US-CERT) is warning about a dangerous security hole in Adobe&#8217;s Shockwave Player that could be used to silently install malicious code. The truly shocking aspect of this bug? U.S. CERT first warned Adobe about the vulnerability in October 2010, and Adobe says it won&#8217;t be fixing it until February 2013.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/iYYb7aU3GpE/Samsung_to_fix_Android_device_vulnerability">Samsung to fix Android device vulnerability</a><br />Samsung said Wednesday it is working on an update for a software flaw that could allow attackers to siphon personal data from a phone.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/yWfLsjuWjYg/Samsung_to_fix_Androind_device_vulnerability">Samsung to fix Androind device vulnerability</a><br />Samsung said Wednesday it is working on an update for a software flaw that could allow attackers to siphon personal data from a phone.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/0-zUerOL3uk/Adobe_to_patch_2_year_old_Shockwave_flaw_next_year">Adobe to patch 2-year-old Shockwave flaw next year</a><br />Adobe plans in February to close a dangerous hole in its Shockwave application that causes the application to be downgraded when a user launches older multimedia content, allowing hackers to target years-old vulnerabilities.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/20/apache_dangerous_plugin/">Apache plug-in doles out Zeus attack</a><br />Points victims to Sweet Orange exploit server, slurps banking credentials: Anti-virus outfit Eset has discovered a malicious Apache module in the wild that serves up malware designed to steal banking credentials.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/rX_jRvvz7pE/It_39_s_time_to_start_patching_the_Human_OS">It&#8217;s time to start patching the Human OS</a><br />Computers and mobile devices store, process and transfer highly valuable information. As a result, your organization most likely invests a great deal in protecting them. Protect the end point and you protect the information. Humans also store, process and transfer information &#8212; people are in many ways are nothing more than another operating system, the Human OS.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/pYio0te3fX8/FTC_bolsters_online_children_s_privacy_rules">FTC bolsters online children&#8217;s privacy rules</a><br />Websites, mobile apps and online advertising networks targeting children will be required to follow new privacy regulations, including getting a parent&#8217;s permission before collecting geolocation information and photographs from kids, under new rules announced Wednesday by the U.S. Federal Trade Commission.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/zcwZYrXVphM/Zscaler_adds_IE_version_of_HTTPS_Everywhere_security_tool">Zscaler adds IE version of HTTPS Everywhere security tool</a><br />Cloud-based security services provider Zscaler has released an implementation for Internet Explorer of the HTTPS Everywhere browser security extension.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/19/spamsoldier_android_botnet/">Android Trojan taints US mobes, spews 500,000 texts A DAY</a><br />If you could just tear yourself from <i>Angry Birds</i> and check your bill&#8230;: A Trojan that infects Android devices is behind an increase in text message spam in the US.
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/cp3KnFKBUak/">WatchGuard Debuts XCS 280, XCS 580 Security Appliances</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/_brO88bss0A/secworld.php">Cloud exploits and mobile device attacks on the horizon</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/ZfiEb004MGQ/secworld.php">88% of corporate databases vulnerable to cybercrime</a>
</li>
<li><a href="http://bits.blogs.nytimes.com/2012/12/19/twitter-reacts-to-anonymous-attacks-on-westboro-baptist-church/?partner=rss&amp;emc=rss">Bits Blog: Twitter Reacts to Anonymous Attacks on Westboro Baptist Church</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/3Jz-FZw8kEE/">People are in a very desperate mode: Fertility specialist faces misconduct charges in treatment of 30 women</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/12/19/terence-corcoran-bank-bashing-101/">Terence Corcoran: Bank Bashing 101</a>
</li>
<li><a href="http://darkreading.com/security-monitoring/167901086/security/news/240145076/gravityzone-by-bitdefender-hits-market-february-2013.html">GravityZone By Bitdefender Hits Market February 2013</a>
</li>
<li><a href="http://darkreading.com/compliance/167901112/security/news/240145097/voltage-secure-stateless-tokenization-advances-data-security-for-enterprises-merchants-and-payment-processors.html">Voltage Secure Stateless Tokenization Advances Data Security For Enterprises, Merchants, And Payment Processors</a>
</li>
<li><a href="http://darkreading.com/smb-security/167901073/security/news/240145098/watchguard-rolls-out-enhanced-xcs-280-and-xcs-580-security-appliances.html">WatchGuard Rolls Out Enhanced XCS 280 And XCS 580 Security Appliances</a>
</li>
<li><a href="http://darkreading.com/smb-security/167901073/security/news/240145099/only-47-of-smbs-ask-partners-about-their-security-processes.html">Only 47% Of SMBs Ask Partners About Their Security Processes</a>
</li>
<li><a href="http://darkreading.com/mobile-security/167901113/security/news/240145100/united-states-is-world-leader-in-fastest-growing-type-of-sms-spam.html">United States Is World Leader In Fastest Growing Type Of SMS Spam</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/2fHwpj5A7J8/">The lowest kind of thievery: Scam artists exploit families coping with Newtown tragedy</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240145073/verizon-dbir-researchers-debunk-2013-security-predictions-inbox-9-x.html">Verizon DBIR Researchers Debunk 2013 Security Predictions Inbox x</a>
</li>
<li><a href="http://darkreading.com/database-security/167901020/security/news/240145094/digital-defense-discovers-zero-day-vulnerability-in-vmware.html">Digital Defense Discovers Zero-Day Vulnerability In VMware</a>
</li>
<li><a href="http://darkreading.com/advanced-threats/167901091/security/news/240145075/crowdstrike-partners-with-coverity-to-ensure-software-security.html">CrowdStrike Partners With Coverity To Ensure Software Security</a>
</li>
<li><a href="http://darkreading.com/risk-management/167901115/security/news/240145095/new-report-highlighting-risks-of-intellectual-property-theft-and-corruption-in-supply-chains.html">New Report Highlighting Risks Of Intellectual Property Theft And Corruption In Supply Chains</a>
</li>
<li><a href="http://darkreading.com/advanced-threats/167901091/security/news/240145096/enisa-report-smart-grid-security-needs-risk-based-approach.html">ENISA Report: Smart Grid Security Needs Risk-Based Approach</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_topstories/~3/lYSQcxMw_58/index.html">Kids&#8217; online privacy rules strengthened</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/cosmo-strikes-again-takes-over-another-westboro-twitter-account/">Cosmo Strikes Again, Takes Over Another Westboro Twitter Account</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/rc5jxjCepX0/">Government toughens up online privacy rules for kids&#8217; websites</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/X-oT66LIGyQ/">Apache plugin turns legit sites into bank-attack platforms</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/state-secrets-drinking-game/">Introducing the State Secrets Drinking Game</a>
</li>
<li><a href="http://darkreading.com/vulnerability-management/167901026/security/news/240145063/free-web-app-scanning-with-ncircle-purecloud.html">Free Web App Scanning With nCircle Purecloud</a>
</li>
<li><a href="http://www.nytimes.com/2012/12/20/technology/ftc-broadens-rules-for-online-privacy-of-children.html?partner=rss&amp;emc=rss">F.T.C. Broadens Rules for Online Privacy of Children</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/kAEXwlT_TC8/">Montreal students create surprisingly realistic animation of baby being snatched by eagle score a viral hit</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/YnsPsYlejKo/story01.htm">Android botnet detected on all major mobile networks</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/airport-scanners-nuking-you/">TSA Wants to Know if Airport Body Scanners are Nuking You</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/kAEXwlT_TC8/">Montreal students create amazingly realistic animation of baby being snatched by eagle score a viral hit</a>
</li>
<li><a href="http://www.nytimes.com/reuters/2012/12/19/us/19reuters-ftc-children-privacy.html?partner=rss&amp;emc=rss">U.S. Tightens Rules Protecting Children&#8217;s Online Privacy</a>
</li>
<li><a href="http://feedproxy.google.com/~r/DataBreachWatch/~3/ASJKHgcAUxE/">2012 Lessons Learned = Compliance</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/0Dez6SDxUDI/">Chief of State Department security service resigns after Benghazi attack report: source</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/3NoH43cpcJo/story01.htm">Dell buys data protection partner Credant Technologies</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/Wbzle0at9lI/">Feds reportedly plan to prosecute hackers sponsored by other nations</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=71fbe956798f5c3e311369fa8bb947d5">Attack Turns Android Devices Into Spam-Spewing Botnets</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/3mG6zKpDrW8/malware_news.php">Apache malware targeting online banking</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/SMTZUsXMDTM/">Benghazi attack report blames State Department for security failures, makes no mention of anti-Islam video</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/19/torontos-chango-partners-with-facebook-to-serve-up-targeted-ads-based-on-search-terms/">Torontos Chango partners with Facebook to serve up targeted ads based on search terms</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-19</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-19/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-19</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-19/#comments</comments>
		<pubDate>Wed, 19 Dec 2012 14:01:55 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8809</guid>
		<description><![CDATA[InfoSec News for Wednesday December 19, 2012. Baby got  [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Wednesday December 19, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/19/batchwiper/">Baby got .BAT: Old-school malware terrifies Iran with del *.*</a><br />New nasty capable of causing about an hour of annoyance: A surprisingly simple disk-wiping malware has set off alarm bells in Iran after surfacing in the Middle East nation.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/OVNxsPDqpOc/Trend_Micro_updates_security_app_to_detect_Samsung_attacks">Trend Micro updates security app to detect Samsung attacks</a><br />Trend Micro has updated its mobile security software to detect potential attacks on several Samsung Electronics devices that have a flaw that could allow a malicious application to access all of the phone&#8217;s memory.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/ADvQceHA2jo/Man_who_hacked_celebrity_email_accounts_sentenced_to_prison">Man who hacked celebrity email accounts sentenced to prison</a><br />Christopher Chaney, a Florida man who admitted to illegally accessing email accounts belonging to more than four dozen celebrities, was sentenced to 10 years in federal prison on Monday.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/nRPhOC_qGJE/SANS_NetWars_tests_cybersecurity_pros_against_peers">SANS NetWars tests cybersecurity pros against peers</a><br />Organizers played &#8220;Eye of the Tiger&#8221; and &#8220;We are the Champions&#8221; over the loudspeakers as participants in the SANS Institute&#8217;s NetWars Tournament of Champions sat down at their laptops and prepared for action.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/iOxnc-c3PFQ/FireEye_Outlines_India_Strategy_to_Secure_APT_Landscape">FireEye Outlines India Strategy to Secure APT Landscape</a><br />In an exclusive interaction, Stephanie Boo, regional director, South Asia Pacific, FireEye, articulates the huge business opportunity for channel partners across APT market.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/18/hackerazzi_hacker_jailed/">Naked Scarlett Johansson pic snatch bloke gets 10 YEARS</a><br />Saucy celeb snap plunderer: &#8216;What a relief&#8217;: A US man who hacked into the email accounts of celebrities including Scarlett Johansson and Mila Kunis and later leaked their nude photos has been sentenced to 10 years in prison.
</li>
<li><a href="http://darkreading.com/mobile-security/167901113/security/news/240144964/dell-reaches-agreement-to-acquire-credant.html">Dell Reaches Agreement To Acquire Credant</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/kLoJ5gGqTLM/">Stephen Harper steps in to save Radarsat upgrade after budget cutbacks threatened satellite programs future</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/h7Su1H9gHog/">Manitoba whistleblower put under house arrest after warning of government fraud, read 156 books while collecting his pay</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/12/18/muskrat-folly/">Muskrat folly</a>
</li>
<li><a href="http://darkreading.com/compliance/167901112/security/news/240144643/new-voltage-secure-stateless-tokenization-able-to-reduce-pci-scope-by-90.html">New Voltage Secure Stateless Tokenization Able To Reduce PCI Scope By 90%</a>
</li>
<li><a href="http://darkreading.com/risk-management/167901115/security/news/240144620/cigital-and-arxan-technologies-form-partnership-to-help-organizations-assess-and-mitigate-app-security-risk.html">Cigital And Arxan Technologies Form Partnership To Help Organizations Assess And Mitigate App Security Risk</a>
</li>
<li><a href="http://darkreading.com/threat-intelligence/167901121/security/news/240144644/rsa-opens-new-anti-fraud-command-center-in-collaboration-with-purdue-university.html">RSA Opens New Anti-Fraud Command Center In Collaboration With Purdue University</a>
</li>
<li><a href="http://darkreading.com/advanced-threats/167901091/security/news/240144645/ubiquitous-internet-connections-will-allow-death-by-device-and-massive-over-the-air-theft-by-2014.html">Ubiquitous Internet Connections Will Allow Death By Device And Massive Over-The-Air Theft By 2014</a>
</li>
<li><a href="http://darkreading.com/vulnerability-management/167901026/security/news/240144647/vulnerabilities-in-java-and-adobe-will-be-main-targets-for-cybercriminals-in-2013.html">Vulnerabilities In Java And Adobe Will Be Main Targets For Cybercriminals In 2013</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/2LKvNC9sCBw/">DOE Cyber Security Audit Shows Incident Reporting, Management Hurdles</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/cRob67CZ3Ac/">Anonymous activist pleads innocent to Stratfor charges</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/8CnaXf15nmg/">Kim Jong-un is Times man of this year, North Korea declares after online prankster flood reader poll</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/I4xnBm_1Fdc/">Samsung smartphone flaw allows root access</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=384a5fcaa77bccf01105855124210c08">Anonymous Posts Westboro Church Members&#8217; Personal Information</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/PedsxNl5Q6c/">Banks Back Under Attack by Claimed Hacktivists</a>
</li>
<li><a href="http://darkreading.com/security-services/167801101/security/news/240144617/avg-and-yahoo-team-on-secure-search.html">AVG And Yahoo Team On Secure Search</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/m59C15x6RBc/">White House rejects Boehners Plan-B fiscal cliff proposal, defends move on taxes</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/warrantless-cell-site-data/">Judge OKs Warrantless Cell-Site Data in Landmark Privacy Case</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/m59C15x6RBc/">White House rejects Boehners plan-b fiscal cliff proposal, defends move on taxes</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/lg0qDRIkdpE/">ARM, Partners Create Trustonic for Greater Mobile Device Security</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=22ed228c1447ea7fae0b9070cfaeff4a">Europe Weighs New Data Breach Rules For Critical Companies</a>
</li>
<li><a href="http://www.cbc.ca/news/arts/story/2012/12/18/hollywood-hacker-sentence-prison-johansson-aguilera-chaney.html?cmp=rss">Hacker gets 10 years in prison for Johansson, Aguilera photo leaks</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/ymMMEbPsYhQ/">Zscaler HTTPS Everywhere Tool Comes to Internet Explorer</a>
</li>
<li><a href="http://darkreading.com/mobile-security/167901113/security/news/240144566/blackberry-7-1-achieves-cesg-security-approval.html">BlackBerry 7.1 Achieves CESG Security Approval</a>
</li>
<li><a href="http://darkreading.com/mobile-security/167901113/security/news/240144603/fcc-lookout-offer-smartphone-security-checker.html">FCC, Lookout Offer Smartphone Security Checker</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/95EUU0CGBqM/malware_news.php">Android botnet spreads SMS spam</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/x0rl1l-vEXo/">Report: data caps just a &#8220;cash cow&#8221; for Internet providers</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/26b88d01/l/0Lnews0Btechworld0N0Csecurity0C34170A290Cinformation0Ecommissioner0Eslams0Ecouncils0Eafter0Efour0Edata0Ebreaches0C0Dolo0Frss/story01.htm">Information Commissioner slams four councils over data breaches</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-19/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-18</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-18/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-18</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-18/#comments</comments>
		<pubDate>Tue, 18 Dec 2012 14:01:53 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8808</guid>
		<description><![CDATA[InfoSec News for Tuesday December 18, 2012. Point-of-Sa [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Tuesday December 18, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/_7sDnC7y-fc/">Point-of-Sale Skimmers: No ChargeYet</a><br />If you hand your credit or debit card to a merchant who is using a wireless point-of-sale (POS) device, you may want to later verify that the charge actually went through. A top vendor of POS skimmers ships devices that will print out &#8220;transaction approved&#8221; receipts, even though the machine is offline and is merely recording the customer&#8217;s card data and PIN for future fraudulent use.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/Hexvhuvh33I/Android_botnet_sends_SMS_spam_through_Android_phones">Android botnet sends SMS spam through Android phones</a><br />In a new twist, spammers have built a botnet that sends SMS spam through infected Android phones, shifting the potentially pricey cost of sending spam to victims.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/18/civil_servants_data_used_to_attack_hmrc/">Conmen DID use leaked info of sporty civil servants&#8230; to attack HMRC</a><br />But why did gov only tell data&#8217;s owners 3 years later?: Criminals used the personal data of 100,000 civil servants that was swiped in early 2010 in an attack on HMRC around the same time, <i>The Register</i> has discovered. Now, almost three years later, the government is still scrabbling around trying to work out whodunnit&#8230; and only recently &#8216;fessed up to the individuals concerned that their data had been snaffled.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/0L2uuxZyMBw/Security_big_data_growth_and_Dotcom">Security, big data, growth and Dotcom</a><br />People accuse Kim Dotcom of many things, both good and bad and not always without merit. However whatever your views of his exploits, one thing you can&#8217;t take away from the eccentric German &#8212; and now Kiwi adoptee &#8212; is the fact that he has completely redefined the word &#8220;Dotcom&#8221;. Sure there was all that interweb stuff too, but let&#8217;s focus on the superficial first.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/0lq5jWyh2tE/Complexity_the_worst_enemy_of_security">Complexity the worst enemy of security</a><br />Computerworld Hong Kong (CWHK): Are we actually any more secure today than we were five years ago?
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/2AsuEmHyYpM/The_new_cybercop_center_of_Hong_Kong">The new cybercop center of Hong Kong</a><br />You read it in Computerworld Hong Kong: the Hong Kong Police have launched a Cyber Security Center to provide round-the-clock services. The HKP made an investment of HK$9 million in hardware and software for the new facility.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/9beLU_y5lcs/Improved_Carberp_malware_targets_U.S._banks">Improved Carberp malware targets U.S. banks</a><br />The creators of Carberp, a banking Trojan program used exclusively in Russian-speaking countries, have started to sell an improved version of the malware together with custom scripts that would allow cybercriminals to target U.S. online banking customers, according to researchers from Russian security firm Group-IB.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/17/anonymous_westboro_baptist_hack/">Anonymous hacks Westboro Baptists over Sandy Hook protests</a><br />Other hackers join the fray: Anonymous has posted personal data of many members of the Westboro Baptist Church and is promising to shut down the religious sect after it announced plans to protest the funerals of those killed at Sandy Hook Elementary School last week.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/F02_5RJF0Tw/Single_sign_on_moves_to_the_cloud">Single sign-on moves to the cloud</a><br />We are awash in passwords, and as the number of Web services increases, things are only going to get worse. Trying to manage all these individual passwords is a major problem for enterprise security. Many end users cope by re-using their passwords, which exposes all sorts of security holes.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/203/~3/r7CmHMdNUTU/More_data_wiping_malware_found_in_Iran">More data-wiping malware found in Iran</a><br />A new piece of malware that deletes entire partitions and user files from infected computers has been found in Iran, according to an alert issued Sunday by Maher, Iran&#8217;s Computer Emergency Response Team Coordination Center.
</li>
<li><a href="http://business.financialpost.com/2012/12/18/apple-loses-bid-to-ban-samsung-devices-as-fans-turn-bearish/">Apple loses bid to ban Samsung devices as fans turn bearish</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/26b6ffca/l/0Lnews0Btechworld0N0Csecurity0C34170A140Candroid0Ebotnet0Eabuses0Epeoples0Ephones0Efor0Esms0Espam0C0Dolo0Frss/story01.htm">Android botnet abuses people&#8217;s phones for SMS spam</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Ud5Jxp_-yXY/article.php">Get ready for invited break-ins, malware-ridden apps and spoof attacks</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/SelaeuXrw_Q/">Its horrible optics: Mark Carney under fire for vacation at Liberal MPs house</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/Z6mQ6ZWEe7Y/">Expensive questions: It cost taxpayers $150,000 to answer a single query from a Liberal MP</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/o3Y5FDVPTZA/">Convicted sex offenders have a right to online privacy, advocates say</a>
</li>
<li><a href="http://opinion.financialpost.com/2012/12/17/pension-shakeup-needed/">Pension shakeup needed</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/threatlevel_1217_wbccosmo/">Cosmo the God Hijacks Twitter Account of Hateful Church</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/jHPpxsxX5qI/">New group acts as financially-shielded middleman for WikiLeaks, others</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/scarlett-johansson-hacker/">Scarlett Johansson Hacker Gets 10 Years</a>
</li>
<li><a href="http://feedproxy.google.com/~r/DataBreachWatch/~3/P79XLkDbu0M/">Key Points on the Ponemon Study on Patient Privacy</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/17/rim-enlists-120-u-s-companies-to-begin-testing-blackberry-10/">RIM enlists 120 U.S. companies to begin testing BlackBerry 10</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/PzHDVkjoGZg/">Anonymous strikes after group plans Newtown vigil protest</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/dish-network-ad-hopping/">Broadcasters Demand Dish Stop Commercial Skipping</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/CfyJxnaRGmQ/">Newtown begins to bury littlest victims of school massacre</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/YwLI7TKHZg4/">Anonymous continues its hack offensive against Westboro Baptist Church</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/RIDEXhsp_sI/">Online hoaxes rampant in wake of Newtown elementary school massacre</a>
</li>
<li><a href="http://darkreading.com/risk-management/167901115/security/news/240144558/lockpath-adds-hitrust-common-security-framework-to-keylight-platform.html">LockPath Adds HITRUST Common Security Framework To Keylight Platform</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/QS-SryDS1yc/">Developer warns of critical vulnerability in many Samsung smartphones</a>
</li>
<li><a href="http://www.itnews.com.au/News/326673,destructive-malware-attacking-iranian-computers.aspx?utm_source=feed&amp;utm_medium=rss&amp;utm_campaign=iTnews+All+Articles+feed">Destructive malware attacking Iranian computers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/PG-wYSI32DI/">Accused U.S. hacker McKinnon to face no charges in U.K.</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/HLl6q42EUv0/">Scarlett Johansson hacker set for sentencing</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/wMeVMnjifEw/">Iranian computers attacked by new malicious data wiper program</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/17/rim-results-could-fuel-more-blackberry-10-buzz/">RIM results could fuel more BlackBerry 10 buzz</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/fLe6QCw8TBI/secworld.php">Payment processor for scareware cybercrime ring jailed</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/a4uUm9VEeC4/">Nurse who committed suicide after falling for royal prank laid to rest in India</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/_9cG1wWF__k/">Divorce records reveal Adam Lanzas mother had full authority over him as portrait of killers family life emerges</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/QyLaZrnMJnU/">Public report examines why police failed to catch B.C. serial killer Robert Pickton</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/9SChI43zeZo/">Newtown prepares to bury first victims of massacre as schools future becomes unclear</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/4PJpejaz-8I/">How to bring down mission-critical GPS networks with $2,500</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-18/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-17</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-17/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-17</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-17/#comments</comments>
		<pubDate>Mon, 17 Dec 2012 14:01:47 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=8807</guid>
		<description><![CDATA[InfoSec News for Monday December 17, 2012. LogMeIn, Doc [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Monday December 17, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/1z-G275zlH0/">LogMeIn, DocuSign Investigate Breach Claims</a><br />Customers of remote PC administration service LogMeIn.com and electronic signature provider DocuSign.com are complaining of a possible breach of customer information after receiving malware-laced emails to accounts they registered exclusively for use with those companies. Both companies say they are investigating the incidents, but so far have found no evidence of a security breach.
</li>
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/uscUBWxnhnw/">LogMeIn, DocuSign Invesigate Breach Claims</a><br />Customers of remote PC administration service LogMeIn.com and electronic signature provider DocuSign.com are complaining of a possible breach of customer information after receiving malware-laced emails to accounts they registered exclusively for use with those companies. Both companies say they are investigating the incidents, but so far have found no evidence of a security breach.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/-ueJI8fRoYI/Egyptian_hacker_claims_to_find_Yahoo_flaws">Egyptian hacker claims to find Yahoo flaws</a><br />A hacker in Egypt has released vague details of three vulnerabilities he claims to have found within Yahoo&#8217;s website, the second time in two months he found problems in the website of a major technology company.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/ZZG97ageXfo/Website_aims_to_bypass_block_on_payments_to_WikiLeaks">Website aims to bypass block on payments to WikiLeaks</a><br />A new website, set up by Pentagon Papers whistleblower Daniel Ellsberg and some other civil rights activists, aims to crowdsource donations for WikiLeaks and three other organizations.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/dny1mBOq15I/After_Newtown_tragedy_cops_target_social_net_pranksters">After Newtown tragedy, cops target social net pranksters</a><br />In the wake of the tragic school shooting in Newtown, Conn, police warned that they will prosecute anyone purposefully posting false information related to the incident on social networks.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/17/us_bank_ddos_assaults/">Hackers warn: We&#8217;ll hit US banks&#8230; again</a><br />Insecure PHP web apps powering zombie DDoS assault: Hackers who claimed responsibility for a series of denial of service attacks against US banks in September have warned the US they plan to renew their assault shortly.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/hMN_zaTvbRw/Preston_Gralla_Is_your_fridge_an_IRS_snitch_">Preston Gralla: Is your fridge an IRS snitch?</a><br />Neither federal and state law nor the courts have come close to catching up with the privacy implications of so much of our data existing in a realm beyond our complete control.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/17/mac_fake_installer_malware/">First Mac OS X fake installer pops up, racks up your mobe bill</a><br />Russian music app? Nope, it&#8217;s an SMS trojan: Crooks have developed a new Mac OS X-specific Trojan that mimics the behaviour of a legitimate software installer.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/17/windows_security_update_kills_fonts/">&#8216;We are screwed!&#8217; Fonts eat a bullet in Microsoft security patch</a><br />Eternal vigilance is the price of wingdings: Windows users were surprised to find that a Microsoft security update stopped fonts from working on their PCs.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/bdMgrtNFCy0/Samsung_devices_vulnerable_to_dangerous_Android_exploit">Samsung devices vulnerable to dangerous Android exploit</a><br />A suspected fault in how Samsung Electronics has implemented the Android&#8217;s kernel in several of its devices could allow a malicious application to gain total control over the device.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/NmP9lAQPpC0/BlackBerry_blacklists_the_39_Pooh_39_gang">BlackBerry blacklists the &#8216;Pooh&#8217; gang</a><br />A report surfaced recently contending that BlackBerry OS 10 will include a list of 106 prohibited passwords designed to prevent the clueless from choosing the likes of 123456, blackberry, or the ever-popular &#8220;password&#8221; as their password.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/17/samsung_exynos_flaw/">Security flaw found in Samsung&#8217;s system-on-chip</a><br />Cluster of Exynos-powered Galaxy devices could be rooted by apps: A member of an XDA developers forum who calls him-or-herself alephzain claims to have found a flaw in several Samsung handsets and tablets that could allow attackers to enjoy access to their RAM.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/z37UnQGs3zg/How_to_activate_Windows_Defender_in_Windows_8">How to activate Windows Defender in Windows 8</a><br />Like every new Windows release, Windows 8 is more secure than the operating systems that came before it. That&#8217;s due in large part to three major enhancements: An increased emphasis on UEFI Secure Boot optimizations, the extension of the SmartScreen Filter across the operating system, and the default inclusion of a more robust version of Windows Defender, which now protects against all kinds of malware&#8211;not just spyware.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/15/mcafee_bank_attack_trojan/">McAfee warns of Project Blitzkrieg hack attack on US banks</a><br />No, not <i>that</i> McAfee, the <i>other</i> McAfee: Security firm McAfee warns that there is a credible threat of a coordinated Spring offensive against at least 30 US banks next year by Eastern European fraudsters.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/2ld9DuG3p6c/Microsoft_We_re_working_to_adjust_IE_s_mouse_tracking">Microsoft: We&#8217;re working to &#8216;adjust&#8217; IE&#8217;s mouse tracking</a><br />A U.K. analytics firm that warned earlier this week of an information leak in Internet Explorer (IE) today rebuked Microsoft for downplaying the bug.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/u1AIlMfS_-o/SMS_stealing_apps_uploaded_to_Google_Play_by_Carberp_banking_malware_gang">SMS stealing apps uploaded to Google Play by Carberp banking malware gang</a><br />Several malicious Android apps designed to steal mobile transaction authentication numbers (mTANs) sent by banks to their customers over SMS (Short Message Service) were found on Google Play by researchers from antivirus vendor Kaspersky Lab.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/14/ie_mouse_tracking_rebuffed/">Microsoft: IE mouse tracking vuln no big deal. Sort of&#8230;</a><br />Will fix it anyway. Probably&#8230;: Microsoft has dismissed allegations that Internet Explorer can allow attackers to track the position of the user&#8217;s mouse cursor, arguing that the original report was self-serving and that the observed behavior does not represent a credible threat.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/3Ho3n_veKi0/Google_Maps_for_iPhone_violates_European_data_protection_law_German_watchdog_says">Google Maps for iPhone violates European data protection law, German watchdog says</a><br />When users install Google Maps on their iPhone, the option to share location data with Google is switched on by default. By doing this, Google violates European data protection law, according to a German data protection watchdog.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/14/twitter_hijack_prank/">Dutch script kiddie pwns 20,000 Twitter profiles</a><br />How much do you have in common with the other lusers?: A Dutch teenager successfully hijacked 20,000 Twitter profiles to post a message dissing their owners for being slack with security.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/14/government_response_to_consultation_on_online_parental_controls/">UK.gov backs away from ISP level filtering plan to protect kids</a><br />Parents, keeping your broadband clean is up to you: The government has decided to stop short of forcing telcos to filter websites at a network level, after discovering that there wasn&#8217;t a major &#8220;appetite&#8221; for such a system among parents who want to prevent their kids from accessing supposedly inappropriate material online.
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/2fPy9bDrKPQ/">We cant tolerate this anymore: Obama signals action over gun laws</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/B4jv2TDlMT8/malware_news.php">Ransomware demands survey completion instead of cash</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/26ad66d2/l/0Lnews0Btechworld0N0Csecurity0C34167860Ciran0Ehit0Eby0Enew0Edata0Ewiping0Ecyberattack0C0Dolo0Frss/story01.htm">Iran hit by new data-wiping cyberattack</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/fDHYF2OLX9c/">Anonymous sets sights on an old enemythe Westboro Baptist Church</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/WKxWoGwVR6w/">The Senkaku islands are our territory: Japanese nationalists return to power in a landslide victory</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/t2j2Gk4ySTg/">Canadian army struggles to hold on to war time intelligence gains amid budgets cuts</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/CZSV--ROMAU/">Gunman Adam Lanza killed himself as police closed in, shot all victims multiple times</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/eABddKNvjNk/">Newtown shooting victims named; Police have very good evidence regarding Adam Lanzas motives</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/cZ5nAvHEALs/">Heroes of Newtown: Sandy Hook principal died lunging at gunman, others shielded students with their bodies</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/eABddKNvjNk/">Newton shooting victims named; Police have very good evidence regarding Adam Lanzas motives</a>
</li>
<li><a href="http://www.nytimes.com/2012/12/15/world/europe/britain-police-say-they-wont-charge-hacker.html?partner=rss&amp;emc=rss">World Briefing | Europe: Britain: Police Say They Wont Charge Hacker</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/cZ5nAvHEALs/">The heroes of Newtown: Sandy Hook Elementary staff died protecting students</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/wRPt31x1oeE/">Shattered: Family of nurse who died after royal prank speaks about her death</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/lo6Fj4qKVrI/">Brilliant but remote: Police still hunting for motive that drove goth Adam Lanza to kill 27</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/YPz0q7jkxA8/">Rhetoric isnt enough: After Obamas tearful call for meaningful action, could latest tragedy be gun-control tipping point?</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/cHX6pONROPE/">Adam Lanza, the Newtown school shooting suspect, was a 20-year-old honours student who lived with his mother</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/bl5Zxvd3oOY/">28 dead, including 20 children, in mass U.S. school shooting: official</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/bl5Zxvd3oOY/">27 dead, including 20 children, in mass U.S. school shooting: official</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/yYoIegueX90/">My ability to make life-saving decisions is hampered: Paramedics complain of staff and vehicle shortages that put public in danger</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/state-secrets-catch-22/">State Secrets Defense Corners Judge in Catch-22 Predicament</a>
</li>
<li><a href="http://darkreading.com/security/news/240144485/new-smart-card-management-system-introduced-by-versatile-security.html">New Smart Card Management System Introduced By Versatile Security</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/wGJTh5LO-lI/">John McAfee back in U.S.</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/O8GHQGr6HU0/">Verizon to Test Support for One Password for Whole Internet</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/7UqajpWPTC8/">Banking trojan on offer again, this time with sky-high price tag</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/united-nations-internet/">Internet Safe From Globalized Censorship as UN Treaty Fails</a>
</li>
<li><a href="http://www.torontosun.com/2012/12/14/us-banks-fend-off-hacker-activist-attacks">U.S. banks fend off hacker activist attacks Jim Finkle and Rick Rothacker, REUTERS</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=097abdeb2243363013277acd8e8883b5">Bank Attackers Used PHP Websites As Launch Pads</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/14/startup-roundup-canopy-labs-raises-1-5m-cn-tower-elevator-pitches-and-ottawas-new-incubator/">Startup Roundup: Canopy Labs raises $1.5M, CN Tower elevator pitches and Ottawas new incubator</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/TiXjYDLQ6Zw/">Nurse who died after royal prank call left suicide note criticizing hospital staff: report</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=69bb759a53867bf5e6759033c920fdfb">S.C. Security Blunders Show Why States Get Hacked</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-17/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-14</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-14/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-14</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-14/#comments</comments>
		<pubDate>Fri, 14 Dec 2012 14:01:47 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=5000</guid>
		<description><![CDATA[InfoSec News for Friday December 14, 2012. Feds Convict [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Friday December 14, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/PrM6X5GmjE8/">Feds Convict Stock Scammers, Overlook Spammers</a><br />On Wednesday, the U.S. Justice Department announced that it had obtained convictions against a cybercrime gang that committed securities fraud through the use of botnets and spam. Oddly enough, none of the botmasters or spammers that assisted in the scheme were brought to justice or identified beyond their hacker handles. This blog post may change that.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/C-V-OufmxE4/Project_Blitzkrieg_e_banking_heist_is_a_credible_threat_McAfee_says">Project Blitzkrieg e-banking heist is a credible threat, McAfee says</a><br />Project Blitzkrieg, a coordinated attack against U.S. banking customers allegedly planned for the spring of 2013, is a real and credible threat, security researchers at McAfee have said.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/13/cisco_voip_phones_vulnerable/">Yet another eavesdrop vulnerability in Cisco phones</a><br />Security groundhog day: A university student presenting at the Amphion Forum has demonstrated turning a Cisco VoIP phone into a listening device, even when its on the hook.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/kjuugkGAApA/DDoS_attacks_against_U.S._banks_peaked_at_60_Gbps">DDoS attacks against U.S. banks peaked at 60 Gbps</a><br />Some of the distributed denial-of-service (DDoS) attacks that targeted the websites of U.S. financial institutions this week have peaked at 60 Gbps, according to researchers from DDoS mitigation provider Arbor Networks.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/14/dexter_malware_targets_pos_systems/">Dexter malware targets point of sale systems worldwide</a><br />Payment cards plundered in 40 countries: You could be getting more than you bargained for when you swipe your credit card this holiday shopping season, thanks to new malware that can skim credit card info from compromised point-of-sale (POS) systems.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/14/ransomware_suspects_cuffed/">Suspected fake internet cop trio collared by real cops</a><br />Ransomware demanded on-the-spot 100 fines from victims: UK cops have arrested three people in Staffordshire on suspicion of running a ransomware scam that fooled victims into paying 100 fines.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/14/uk_anon_investigation/">UK cops: How we sniffed out convicted AnonOps admin &#8216;Nerdo&#8217;</a><br />Hint: Sometimes gamer tags give the game away: Analysis of IRC logs and open source intelligence played a key role in the successful police prosecution that led up the conviction of a member of Anonymous for conspiracy to launch denial of service attacks against PayPal and other firms.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/14/first_virus_elk_cloner_creator_interviewed/">The 30-year-old prank that became the first computer virus</a><br />Elk Cloner creator Rich Skrenta looks back: To the author of Elk Cloner, the first computer virus to be released outside of the lab, its sad that, 30 years after the self-replicating code&#8217;s appearance, the industry has yet to come up with a secure operating system.
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/zGg7etfmOpk/">Scathing auditor general report finds OPP lost track of evidence, police vehicles</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/13/u-s-federal-agency-gives-rim-another-chance-with-plan-to-test-blackberry-10-smartphone/">U.S. federal agency gives RIM another chance with plan to test BlackBerry 10 smartphone</a>
</li>
<li><a href="http://darkreading.com/security/news/240144344/hitrust-and-isc-2-launch-first-certification-for-healthcare-info-security-professionals.html">HITRUST And (ISC)2 Launch First Certification For Healthcare Info Security Professionals</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/2692ea76/l/0Lnews0Btechworld0N0Csecurity0C34163470Cpolice0Earrest0Ethree0Eover0Eransom0Emalware0Eattacks0C0Dolo0Frss/story01.htm">Police arrest three over ransom malware attacks</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/dpvqtsfzsts/">Royal radio hoax staff moved into safehouses as inquest reveals nurse hanged herself, left three suicide notes</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/13/review-googles-new-maps-app-for-iphone-is-an-absolute-smash-hit/">Review: Googles new Maps app for iPhone is an absolute smash hit</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Tg7AkSMgmXc/">Team GhostShell leaks data from 1.6 million accounts</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/gov-dossiers-on-us-citizens/">Attorney General Secretly Granted Gov Ability to Develop and Store Dossiers on Innocent Americans</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/-oZ3evIInrA/">Tony Clement picks new fight with budget watchdog over $20K gap over cost of civil servants</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/ap4HEJLpCDY/">Encryption: Debunking the Top 10 Myths About This Data Defense</a>
</li>
<li><a href="http://feedproxy.google.com/~r/DataBreachWatch/~3/NbfqTWhZaVI/">2012 Data Breaches: A Look Back</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/phone-spoofing/">Non-Harmful Phone Spoofing OK, Appeals Court Says</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/hackers-breach-ics/">Hackers Breached Heating System Via Industrial Control System Backdoor</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/bKNNPZhSEd4/">Mobile Users Remain Safe (Mostly) in 2013, Lookout Says</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/C4V32JKiRqo/">&#8216;Dexter&#8217; Malware Caught Swiping Credit Card Numbers From POS Systems</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/mzhd6xZ0nCY/">Fraudsters plan spring strike on U.S. banks</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/state-secrets-front-center/">State Secrets Front and Center in Dragnet Surveillance Case</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/sbQ3jJTgiew/">Canada joins Western countries rejecting UN Internet treaty over fears of government control</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/242UBbn9-ps/">HITRUST, ISC2 to Create Credential Program for Health Care Data Security</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240144419/total-defense-launches-cloud-security-solution.html">Total Defense Launches Cloud Security Solution</a>
</li>
<li><a href="http://darkreading.com/mobile-security/167901113/security/news/240144435/alu-s-kindsight-introduces-new-mobile-security-features-expands-protection.html">ALU&#8217;s Kindsight Introduces New Mobile Security Features, Expands Protection</a>
</li>
<li><a href="http://darkreading.com/authentication/167901072/security/news/240144434/forgerock-news-adaptive-authentication.html">ForgeRock News &#8212; Adaptive Authentication</a>
</li>
<li><a href="http://rss.cnn.com/~r/rss/cnn_topstories/~3/SsQQ2fr6YYg/">Massive bank cyberattacks planned</a>
</li>
<li><a href="http://bits.blogs.nytimes.com/2012/12/13/lookout-toll-fraud/?partner=rss&amp;emc=rss">Bits Blog: Android Malware Creeps Into Cellphone Bills</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/AY3ZJjWfHA0/">Susan Rice withdraws her name from consideration for U.S. Secretary of State</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/vVTGd1NuGWA/secworld.php">Top 7 security predictions for 2013</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/b_BbN3zKafA/malware_news.php">Fake CitiBank credit card statement leads to malware</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-14/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-13</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-13/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-13</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-13/#comments</comments>
		<pubDate>Thu, 13 Dec 2012 14:01:45 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4998</guid>
		<description><![CDATA[InfoSec News for Thursday December 13, 2012. New Findin [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Thursday December 13, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/RgJgMJ51mKo/">New Findings Lend Credence to Project Blitzkrieg</a><br />&#8220;Project Blitzkrieg,&#8221; a brazen Underweb plan for hiring 100 botmasters to fuel a blaze of ebanking heists against 30 U.S. financial institutions in the Spring of 2003, was met with skepticism from some in the security community after news of the scheme came to light in October. Many assumed it was a law enforcement sting, or merely the ramblings of a wannabe criminal mastermind. But new research suggests the crooks who hatched the plan were serious and have painstakingly built up a formidable crime machine in preparation for the project.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/jmU55vnBaAw/Internet_Explorer_flaw_gives_ad_trackers_a_sneaky_edge_for_now">Internet Explorer flaw gives ad trackers a sneaky edge &#8212; for now</a><br />Some advertising analytics companies are using a vulnerability in Microsoft&#8217;s Internet Explorer browser for a questionable edge in figuring out if web users are seeing display advertisements buried within web pages.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/8vZGvnnRSiM/Microsoft_Most_PCs_running_pirated_Windows_in_China_have_security_issues">Microsoft: Most PCs running pirated Windows in China have security issues</a><br />Microsoft launched a new anti-piracy campaign in China to highlight the security risks of buying counterfeit software.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/fjfNpT2VIXE/Japan_police_offer_first_ever_reward_for_wanted_hacker">Japan police offer first-ever reward for wanted hacker</a><br />Police in Japan are looking for an individual who can code in C#, uses a &#8220;Syberian Post Office&#8221; to make anonymous posts online, and knows how to surf the web without leaving any digital tracks &#8212; and they&#8217;re willing to pay.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/13/exploithub_breach/">Hacking bazaar ExploitHub gets hacked, database leaked</a><br />But online shop denies $250k of exploits were pinched: Online boutique ExploitHub, which sells code to attack software security holes, has been plundered by hackers. A database snaffled from the marketplace was dumped online as proof of the raid.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/12/ie_stupidly_exposes_cursor_movements/">Internet Explorer tracks cursor even when minimised</a><br />Keep calm: its only being exploited by adware blood-suckers &#8230; probably: A security researcher has published yet another reason not to use Internet Explorer for anything, under any circumstances: it can track your mouse cursor movements, even when its minimised.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/tfTAZlJijhU/After_vote_Facebook_moves_to_update_privacy_settings">After vote, Facebook moves to update privacy settings</a><br />Despite Facebook users losing out on a privacy policy vote earlier this week, the social network moved today to make its privacy tools easier for them to access.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/12/dec_patch_tuesday/">Microsoft Santa gifts you with 5 critical fixes in Xmas Patch Tuesday</a><br />Still using Word? You&#8217;ll want to read this: December&#8217;s Patch Tuesday brought seven bulletins from Microsoft, five of which cover critical security vulnerabilities.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/12/facebook_fbi_malware_suspects/">Feds smash international cybercrime ring with Power of Facebook</a><br />Ad-men and G-men form potent globo force: The FBI have said that with the help of Facebook, they&#8217;ve taken down an international crime gang who went on an $850m botnet spree.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/12/john_mcafee_release_from_detention/">Guatemalan judge orders McAfee released from detention</a><br />Just wants to &#8216;fish and swim&#8217;, no more aerotrekking: A Guatemalan judge has reportedly ordered the release of John McAfee, after ruling the anti-virus pioneer turned Belizean manhunt target was being detained illegally.
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/ekVdKi7F7oY/">Radio hoax nurse found hanging in her room with three suicide notes, inquest reveals</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/dCyhT_rFhFg/malware_news.php">Mac users hit with fake installer and SMS fraud</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Jl-S3jO4A18/secworld.php">Motivations, trends and measurement of IT security spending</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20121213-cybersecurity-company-using-hackers-own-devices-against-them">Cybersecurity company using hackers own devices against them</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/c6wbRVzSvII/">Marois wants to sell $6M Montreal home to European businessman, but law prohibits sale of agricultural land to foreigners</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/JslApLUbbKk/">Facebook Teams With Federal Authorities to Bust $850 Million Botnet</a>
</li>
<li><a href="http://darkreading.com/vulnerability-management/167901026/security/news/240144313/sentinel-ips-announces-the-global-release-of-an-industry-first-collective-intelligence-scoring-system.html">Sentinel IPS Announces The Global Release Of An Industry-First Collective Intelligence Scoring System</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/fisa-act-reauthorization/">Expiring Warrantless Spy Bill to be Reauthorized By Years End</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/pDx5EM-pwio/">Mac OS X users targeted in SMS scam</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/12/will-apple-bid-for-tomtom/">Will Apple bid for TomTom?</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/iTlqCqUxZ24/">FBI nabs 10 for Yahos worm spread on Facebook</a>
</li>
<li><a href="http://darkreading.com/advanced-threats/167901091/security/news/240144307/safenet-inc-sells-government-solutions-business-unit-to-raytheon-company.html">SafeNet, Inc., Sells Government Solutions Business Unit To Raytheon Company</a>
</li>
<li><a href="http://darkreading.com/security-services/167801101/security/news/240144315/whitehat-security-brings-new-standards-to-mobile-application-security.html">WhiteHat Security Brings New Standards To Mobile Application Security</a>
</li>
<li><a href="http://darkreading.com/security-services/167801101/security/news/240144316/ncircle-purecloud-automatically-scans-for-zero-day-threats.html">nCircle PureCloud Automatically Scans For Zero-Day Threats</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/cTEldqp830c/">How an Internet-connected Samsung TV can spill your deepest secrets</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/facebook-helps-bust-botnet/">Facebook Helps Feds Crack $850 Million Botnet Ring</a>
</li>
<li><a href="http://darkreading.com/security-monitoring/167901086/security/news/240144287/ncp-engineering-releases-secure-enterprise-management-version-3-0.html">NCP Engineering Releases Secure Enterprise Management Version 3.0</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/tTabGZajDMw/">$1.4-billion in unpaid corporate taxes being written off in Ontario: Auditor-General</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=e9aa1cd73809881f95850a6e4f3536ef">Could A Thumb Drive Stop Stuxnet?</a>
</li>
<li><a href="http://darkreading.com/risk-management/167901115/security/news/240144286/habits-of-highly-successful-security-awareness-programs.html">Habits Of Highly Successful Security Awareness Programs</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/jEOa9K--qYw/">New Mac trojan tricks users into paying pricey cell phone fees</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/12/facebook-assists-in-fbi-bust-of-major-international-cyber-crime-operation/">Facebook assists in FBI bust of major international cyber crime operation</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/26888637/l/0Lnews0Btechworld0N0Csecurity0C3416230A0Cfbi0Earrests0Edown0Efacebook0Ebotnet0Ethat0Estole0E850A0Emillion0C0Dolo0Frss/story01.htm">FBI arrests down Facebook botnet that stole $850 million</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/f1Q_oPaUewI/">FBI snares $850 million Butterfly botnet ring with help of Facebook</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/kwsdXKQh2LU/">Key Citadel developer banned from online crime forum</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/K4ehuorPJkc/">Royal hoax nurse left suicide note, reports say: Autopsy results to be revealed Thursday</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/lWtmcYUtoD4/">John McAfee ordered released (formal ruling coming soon), says software pioneers lawyer</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/qgpPNA2c68Y/malware_news.php">Researchers uncover Tor-powered Skynet botnet</a>
</li>
<li><a href="http://darkreading.com/insider-threat/167801100/security/news/240144263/most-dangerous-holiday-web-search-terms-of-2012.html">Most Dangerous Holiday Web Search Terms Of 2012</a>
</li>
<li><a href="http://darkreading.com/insider-threat/167801100/security/news/240144246/fbi-international-law-enforcement-disrupt-international-organized-cybercrime-ring-related-to-butterfly-botnet.html">FBI, International Law Enforcement Disrupt International Organized Cybercrime Ring Related To Butterfly Botnet</a>
</li>
<li><a href="http://darkreading.com/insider-threat/167801100/security/news/240144266/despite-lack-of-trust-internet-users-security-behaviors-far-from-ideal-roboform-study-finds.html">Despite Lack Of Trust, Internet Users&#8217; Security Behaviors Far From Ideal, RoboForm Study Finds</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/a9LqWFR0zCA/malware_news.php">Exploit tool hitting Joomla and WordPress sites</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/PH6Zb9_ti04/">10 Nations Facing the Most Pervasive Threats From Malware, Botnets</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-12</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-12/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-12</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-12/#comments</comments>
		<pubDate>Wed, 12 Dec 2012 14:01:41 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4996</guid>
		<description><![CDATA[InfoSec News for Wednesday December 12, 2012. Critical  [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Wednesday December 12, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/riWj2cG4uCE/">Critical Updates for Flash Player, Microsoft Windows</a><br />Adobe and Microsoft have each released security updates to fix critical security flaws in their software. Microsoft issued seven update bundles to fix at least 10 vulnerabilities in Windows and other software. Separately, Adobe pushed out a fix for its Flash Player and AIR software that address at least three critical vulnerabilities in these programs.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/Leipgv8cIZo/Samsung_TV_vulnerability_could_let_a_hacker_change_the_channel">Samsung TV vulnerability could let a hacker change the channel</a><br />If you&#8217;re watching TV and the channel suddenly changes, you may not have sat on the remote control by accident.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/zbQ2QPTumUU/ExploitHub_admits_39_embarrassing_oversight_39_led_to_hack">ExploitHub admits &#8216;embarrassing oversight&#8217; led to hack</a><br />A marketplace where security researchers can sell details on software bugs said it was compromised on Tuesday due to an &#8220;embarrassing oversight&#8221; that left its web server vulnerable.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/FP5aioEWHeU/ExploitHub_admits_39_embarrassing_oversight_39_lead_to_hack">ExploitHub admits &#8216;embarrassing oversight&#8217; lead to hack</a><br />A marketplace where security researchers can sell details on software bugs said it was compromised on Tuesday due to an &#8220;embarrassing oversight&#8221; that left its web server vulnerable.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/wZ8sWT5n-YQ/US_law_enforcement_busts_cybercrime_rings_with_help_from_Facebook">US law enforcement busts cybercrime rings with help from Facebook</a><br />U.S. law enforcement agencies with the help of Facebook have arrested 10 people from various countries in connection with international cybercrime rings that targeted users on the social network.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/12/russian_cyberespionage_attack/">Russian space research org targeted by mystery malware attack</a><br />Korean message forum becomes cyber-espionage hub: Security researchers have discovered a targeted attack against Russian hi-tech firm that appears to originate in Korea.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/12/smart_tv_pwned/">Samsung&#8217;s smart TVs &#8216;wide open&#8217; to exploits</a><br />The downside to being &#8216;more like a PC&#8217;: Samsung&#8217;s Smart TV has a vulnerability which allows remote attackers to swipe data, according to security researchers.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/djt6Pml847I/Microsoft_quashes_critical_bugs_in_IE10_Windows_8_Word">Microsoft quashes critical bugs in IE10, Windows 8, Word</a><br />Microsoft today patched a dozen vulnerabilities in Internet Explorer, Windows, Word and Exchange, fixing flaws in the new IE10 for the first time and crushing bugs in Windows 8 and Windows RT for the second month running.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/11/adfa_hacked_in_november/">Attacker steals old passwords from Oz defence academy site</a><br />Security fail sparks usual hypegasm: An attack on Australian Defence Force Academy systems operated by the University of New South Wales (UNSW), has spilled 20,000 user records.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/11/microsoft_stores_theft/">Girl gang targets Microsoft&#8217;s Seattle stores for $5,000 theft spree</a><br />Sounds like a job for the Rain City Superhero Movement: Seattle police are on the lookout for a group of female thieves who are targeting Microsoft retail stores on its home turf.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/85/~3/mLfyJhgbXro/Dexter_malware_infects_point_of_sale_systems_worldwide_researchers_say">Dexter malware infects point-of-sale systems worldwide, researchers say</a><br />Researchers from Israel-based IT security firm Seculert have uncovered a custom-made piece of malware that infected hundreds of point-of-sale (PoS) systems from businesses in 40 countries in the past few months and stole the data of tens of thousands of payment cards.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/11/john_mcafee_film_deal/">Look out, world! Are you ready for John McAfee: THE MOVIE?</a><br />Antivirus thrillseeker flogs manhunt film rights: Antivirus pioneer John McAfee, who found himself at the centre of Central America&#8217;s hottest manhunt in recent history, has sold the exclusive film rights to his life story.
</li>
<li><a href="http://www.bbc.co.uk/news/technology-20693213#sa-ns_mchannel=rss&amp;ns_source=PublicRSS20-sa">Arrests over $850m Facebook crime</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/mugshot-industry-legal-attack/">Shamed by Mugshot Sites, Arrestees Try Novel Lawsuit</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/de9AZtM3n4o/secworld.php">Facebook helps Feds take down international cybercrime ring</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/v6ScwujK8mM/malware_news.php">Custom-made malware is infecting POS terminals</a>
</li>
<li><a href="http://www.homelandsecuritynewswire.com/dr20121212-israel-cyber-security-incubator-program-established-by-bengurion-university-of-the-negev">Israel cyber security incubator program established by Ben-Gurion University of the Negev</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/kmen1ErtGqg/">Facebook User Policy Vote Ends With a Whimper</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/qn5jDnhR5iI/">Cloud Security Will Overtake On-Premise Systems in Three Years: Gartner</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240144232/survey-exposes-new-cloud-security-flaws.html">Survey Exposes New Cloud Security Flaws</a>
</li>
<li><a href="http://darkreading.com/security-monitoring/167901086/security/news/240144254/ixia-unveils-ixnetwork-7-0.html">Ixia Unveils IxNetwork 7.0</a>
</li>
<li><a href="http://darkreading.com/advanced-threats/167901091/security/news/240144255/bond-and-bourne-fuel-belief-that-cyberhacking-is-easy-so-why-fight-it-u-k-study-shows.html">Bond And Bourne Fuel Belief That Cyberhacking Is Easy So Why Fight It, U.K. Study Shows</a>
</li>
<li><a href="http://darkreading.com/insider-threat/167801100/security/news/240144231/survey-of-it-professionals-reveals-discrepancy-between-support-of-and-implementation-of-desktop-privilege-control.html">Survey Of IT Professionals Reveals Discrepancy Between Support Of And Implementation Of Desktop Privilege Control</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Ikp9luC_XRo/">Microsoft, Adobe patch a range of vulnerabilities</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/-2vU2DBCnas/">Microsoft Releases Critical IE, Word Fixes on Year&#8217;s Final Patch Tuesday</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/47nbPXhNMm4/">Russian space, telecom industries targeted by espionage</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/Hi64yw6thvc/">FTC finds little improvement in mobile privacy for children</a>
</li>
<li><a href="http://darkreading.com/insider-threat/167801100/security/news/240144223/chubb-cyber-endorsement-addresses-increase-in-bank-account-takeover-frauds.html">Chubb Cyber Endorsement Addresses Increase In Bank Account Takeover Frauds</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/267ed54c/l/0Lnews0Btechworld0N0Csecurity0C34159980Candroid0Eusers0Eface0Erise0Ein0Esms0Efraud0Eapps0Ereckons0Ebitdefender0C0Dolo0Frss/story01.htm">Android users face rise in SMS fraud apps, reckons Bitdefender</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/8HyKhS3M1OM/">Anonymous spokesman charged with linking to stolen data</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/11/cellphone-users-want-50-cap-on-international-data-roaming-fees-study-says/">Cellphone users want $50 cap on international data roaming fees, study says</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/DvUFy4jL2GI/">Ikea monkey owner says she wants Darwin back as videos reveal her life with well-dressed monkey</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/oGMuzViMysU/">Average public servant costs taxpayers $114K a year, PBO reveals</a>
</li>
<li><a href="/news/world/Closing+arguments+pretrial+hearing+soldier+charged+WikiLeaks/7680874/story.html">Closing arguments set in pretrial hearing for US soldier charged in WikiLeaks case</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/MS_TZWPtPb8/">&#8220;Dexter&#8221; malware steals credit card data from point-of-sale terminals</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/jRGX40KGaVg/">Royal prank call may have been illegal, experts say as radio station donates $500,000 to nurses family</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-11</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-11/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-11</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-11/#comments</comments>
		<pubDate>Tue, 11 Dec 2012 14:01:36 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4994</guid>
		<description><![CDATA[InfoSec News for Tuesday December 11, 2012. A Closer Lo [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Tuesday December 11, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/5Q5cHlNbW3s/">A Closer Look at Two Bigtime Botmasters</a><br />Over the past 18 months, I&#8217;ve published a series of posts that provide clues about the possible real-life identities of the men responsible for building some of the largest and most disruptive spam botnets on the planet. I&#8217;ve since done a bit more digging into the backgrounds of the individuals thought to be responsible for the Rustock and Waledac spam botnets, which has produced some additional fascinating and corroborating details about these two characters.
</li>
<li><a href="http://feedproxy.google.com/~r/KrebsOnSecurity/~3/phDUCk4YaoQ/">Chinese Espionage Attacks Against Ruskies?</a><br />Hardly a week goes by without news of a cyber espionage attack emanating from China that is focused on extracting sensitive data from corporations and research centers in the United States. But analysis of a recent malware campaign suggests that Chinese cyberspies may be just as interested in siphoning secrets from Russian targets
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/11/draft_communications_data_bill_joint_committee_report/">Parliament: Snoop Charter plan &#8216;too sweeping&#8217;, &#8216;misleading&#8217;, &#8216;suspicious&#8217;</a><br />&#8216;Goes much further than it need or should&#8217;: Theresa May&#8217;s communications data draft bill is far too broad and needs to be slimmed down, concluded MPs and peers who have spent many months scrutinising the Home Secretary&#8217;s lambasted plans to massively increase the surveillance of online activity in the UK.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/11/ghostshell_christmas_release/">GhostShell hackers release 1.6 million NASA, FBI, ESA accounts</a><br />Hacktivist crew signs off for Christmas: The hacking collecting GhostShell has announced it has finished operations for the year, but has signed off with a dump of around 1.6 million account details purloined from government, military, and industry.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/Rw5vi3ByJe0/Vote_ends_on_Facebook_privacy_changes_for_good">Vote ends on Facebook privacy changes, for good</a><br />The user vote over Facebook&#8217;s latest proposed privacy policy change is over and the small number of voters who took part means Facebook can proceed with its plans.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/android_malware_scanner_fails/">Boffin: Android&#8217;s on-board malware scanner utterly FAILS</a><br />App blocker detects just 15% of malware: Google has added new anti-malware capabilities to Android 4.2 &#8220;Jelly Bean,&#8221; but relying on them to block malicious apps might not be a good idea, says a computer science boffin from North Carolina State University.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/wGBjg86FkJs/Police_themed_ransomware_speaks_to_victims_literally">Police-themed ransomware speaks to victims &#8212; literally</a><br />A new variant of a Trojan program called Reveton that prevents victims from using their computers and displays rogue messages from law enforcement agencies is using localized voice messages to trick victims into paying made-up fines, according to researchers from antivirus vendor Trend Micro.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/john_mcafee_bizarre_press_conference/">John McAfee: Let me go to the USA &#8211; or old Blighty</a><br />You can trust what I say &#8211; I don&#8217;t use McAfee AV: Former anti-virus mogul turned fugitive John McAfee has appealed to be allowed to return to the United States rather than deported from Guatemala to Belize.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/saudi_aramco_shamoon_inquest/">Saudi Aramco: Foreign hackers tried to cork our gas output</a><br />Worm outbreak targeted oil giant&#8217;s output: Hackers who used the Shamoon worm to attack oil giant Saudi Aramco were bent on halting its fuel production, according to the company and Saudi government officials.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/203/~3/NA49tuOLjqI/Ira_Winkler_Stupid_users_or_stupid_infosec_">Ira Winkler: Stupid users, or stupid infosec?</a><br />When security professionals see stupidity all around them, shouldn&#8217;t they ask themselves whether it&#8217;s their own precautions that are lacking?
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/ZeXTgSJK5ik/">DataMotion Announces SecureMail Gateway Email Encryption</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/k-kXwjAvAVY/malware_news.php">Fake Better Business Bureau notifications carry malware</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/i7nquGLMiGU/secworld.php">Ultra-secure memory sticks with anti-malware features</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/W7QH32xc46I/secworld.php">Panda Cloud Antivirus 2.1 released</a>
</li>
<li><a href="http://www.pheedcontent.com/click.phdo?i=439cb085690b2972cede86e00cb64dce">Anonymous&#8217;s Public Face Indicted</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/oRfXuLHmyBY/">Ikea monkey Darwin checks into his new home at animal sanctuary in rural Ontario</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/scotus-thomas-rasset-riaa/">Supreme Court Asked to Review $222K Landmark File-Sharing Case</a>
</li>
<li><a href="http://feedproxy.google.com/~r/DataBreachWatch/~3/mbqIkNVY5Jo/">Newly Released Ponemon Report: Healthcare Data Breach on the Rise</a>
</li>
<li><a href="http://darkreading.com/security/news/240144152/panda-security-launches-panda-cloud-antivirus-2-1-with-anti-exploit-technologies.html">Panda Security Launches Panda Cloud Antivirus 2.1 With Anti-Exploit Technologies</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/public-bus-audio-surveillance/">Public Buses Across Country Quietly Adding Microphones to Record Passenger Conversations</a>
</li>
<li><a href="http://www.torontosun.com/2012/12/10/us-regulators-start-probe-into-childrens-online-privacy">U.S. regulators start probe into childrens online privacy Diane Bartz, REUTERS</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/10/canadians-are-tired-and-frustrated-liberal-contender-garneau-calls-for-more-wireless-competition/">Canadians are tired and frustrated: Liberal contender Garneau calls for more wireless competition</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=8c3fcd7f0054bee6386ccab0d64bb79c">Google&#8217;s Android Malware Detection Falls Short</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/ftc-mobile-kid-privacy-probe/">FTC Probing Childrens Mobile Apps for Privacy Breaches</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/CBej0CkfaCM/">Microsoft Patch Tuesday Ensnares Windows RT Users</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/fGkY1Rub_LE/secworld.php">Former Anonymous spokesman indicted for sharing stolen card data</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/QiGXf9NmIhY/">FTC: disclosures severely lacking in kids&#8217; mobile appsand it&#8217;s getting worse</a>
</li>
<li><a href="/news/world/Hearing+enters+10th+soldier+says+illegally+punished+WikiLeaks/7675391/story.html">Commander: WikiLeaks suspect&#8217;s treatment closely watched by US supervisors</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/ucdOIqOGaKI/secworld.php">Hackers encrypt medical centre&#8217;s patient data, ask for ransom</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240144147/biggest-u-k-brands-failing-to-protect-their-customers-from-online-fraud-new-research-find.html">Biggest U.K. Brands Failing To Protect Their Customers From Online Fraud, New Research Find</a>
</li>
<li><a href="http://darkreading.com/cloud-security/167901092/security/news/240144128/bat-blue-networks-expands-its-cloud-security-offering-to-europe.html">Bat Blue Networks Expands Its Cloud Security Offering To Europe</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/pH8LFnA4jbY/">Android&#8217;s built-in malware scanner gets a failing grade</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/qZZGEM2QdGw/">Embattled software founder John McAfee says return to the U.S. is his only hope now</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/5OIcphxGDAs/">Hassan Rasouli case before Supreme Court will have profound effect on end-of-life care decisions</a>
</li>
<li><a href="http://feeds.informationweek.com/click.phdo?i=1aa41d59dba8c468c07bb3d78e266c79">Anonymous No Longer: Hacktivist Spokesman Charged</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/_FWZpiM8AN8/malware_news.php">200,000 new malicious programs detected every day</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/2673dfd3/l/0Lnews0Btechworld0N0Csecurity0C34156350Cransom0Ehackers0Eencrypt0Emedical0Ecentres0Eentire0Edatabase0C0Dolo0Frss/story01.htm">Ransom hackers encrypt medical centre&#8217;s entire database</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec News 2012-12-10</title>
		<link>http://jacksch.com/2012/12/infosec-news-2012-12-10/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=infosec-news-2012-12-10</link>
		<comments>http://jacksch.com/2012/12/infosec-news-2012-12-10/#comments</comments>
		<pubDate>Mon, 10 Dec 2012 14:01:37 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[ISN]]></category>

		<guid isPermaLink="false">http://jacksch.com/?p=4992</guid>
		<description><![CDATA[InfoSec News for Monday December 10, 2012. &#8216;UK DN [...]]]></description>
				<content:encoded><![CDATA[<p>InfoSec News for Monday December 10, 2012.</p>
<ol style="font-family: Arial, sans-serif;font-size: 13px">
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/dna_database/">&#8216;UK DNA database by stealth&#8217; proposed in 100m NHS project</a><br />Mighty archive to &#8216;unlock the power of DNA&#8217; &#8211; Cameron: Prime Minister David Cameron is to announce plans for the NHS to create a massive database of patients&#8217; DNA, which experts have advised could lead to massive health benefits and advances in medical technology. However the creation of such a database has obvious and far reaching privacy implications.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/82/~3/vLbn_1PnqAQ/Delta_Air_Lines_publishes_privacy_policy_but_reseacher_finds_a_fault">Delta Air Lines publishes privacy policy, but reseacher finds a fault</a><br />Delta Air Lines quickly published a privacy policy for its mobile application after being sued by California&#8217;s attorney general, but a privacy researcher has already found a fault with it and the app.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/communications_data_bill/">Parliament to unleash barrage of criticism on Snoopers&#8217; Charter</a><br />Unseen spook Farr back again with plan to tap the UK net: The joint parliamentary committee scrutinising the governments Communications Data Bill &#8211; universally dubbed the Snoopers&#8217; Charter &#8211; is set to slate the draft law in its official report published tomorrow.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/tor_admin/">Tor node admin raided by cops appeals for help with legal bills</a><br />&#8216;I&#8217;m on my own and require a good lawyer&#8217; says bloke: A sysadmin had his flat raided and equipment seized by police last week for hosting a Tor exit node.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/qr_code_sticker_scam/">That square QR barcode on the poster? Check it&#8217;s not a sticker</a><br />Crooks slap on duff codes leading to evil sites: Cybercrooks are putting up stickers featuring URLs embedded in Quick Response codes (QR codes) as a trick designed to drive traffic to dodgy sites.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/hong_kong_cyber_security_centre/">Hong Kong cops open 700k cyber security centre</a><br />27-man centre will try to spot and combat CNI attacks: The Hong Kong government has thrown HK$9 million (730,000) at a new Cyber Security Centre in a bid to tackle the growing threat to critical infrastructure in the Special Administrative Region of China.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/10/pakistan_cyber_army_hack_bangladesh_china/">Pakistan Cyber Army declares war on Chinese, Bangladeshi sites</a><br />Hacktivists go on web defacement spree: Hacktivists claiming to hail from the Pakistan Cyber Army have defaced over 400 Chinese government web sites and also hit in excess of 20 Bangladeshi government sites.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/244/~3/xuBzgJKGhDU/Tor_network_used_to_command_Skynet_botnet">Tor network used to command Skynet botnet</a><br />Security researchers have identified a botnet controlled by its creators over the Tor anonymity network. It&#8217;s likely that other botnet operators will adopt this approach, according to the team from vulnerability assessment and penetration testing firm Rapid7.
</li>
<li><a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/12/07/patch_tuesday_dec_2012_pre_alert/">Rare critical Word vuln is the star of December Patch Tuesday</a><br />Microsoft cheese a bit less swiss this year: Microsoft is planning to release seven bulletins next Tuesday, five of which tackle critical vulnerabilities, as part of its final Patch Tuesday update of 2012.
</li>
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/84/~3/AeZAXBiERPw/Facebook_sued_over_App_Center_data_sharing_in_Germany">Facebook sued over App Center data sharing in Germany</a><br />German consumer organizations are suing Facebook because the social network keeps sharing personal data with third-party app makers without getting explicit consent from users.
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/32Nw4eNHGZA/malware_news.php">Multipurpose Necurs Trojan infects over 83,000 computers</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/R_l9i_PPOC8/malware_news.php">Beware of Bitcoin miner posing as Trend Micro AV</a>
</li>
<li><a href="http://rss.feedsportal.com/c/270/f/3551/s/2672021b/l/0Lnews0Btechworld0N0Csecurity0C34155650Canonymous0Espokesman0Eindicted0Efor0Ethreats0Estolen0Ecredit0Ecards0C0Dolo0Frss/story01.htm">Anonymous spokesman indicted for threats, stolen credit cards</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/0yzpNDAx0JU/secworld.php">DataMotion unveils SecureMail Gateway</a>
</li>
<li><a href="http://www.nytimes.com/2012/12/10/business/global/saudi-aramco-says-hackers-took-aim-at-its-production.html?partner=rss&amp;emc=rss">Saudi Aramco Says Hackers Took Aim at Its Production</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/zmOFB3-FOVU/">Hugo Chavez heading back to Cuba for surgery as cancer resurfaces, names VP as successor</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/0Z1LLeh26yY/">Canadas top court asked to settle battle over Tommy Douglas intelligence dossier</a>
</li>
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/50X0bbYziqw/">Former Anon spokesperson indicted for allegedly linking to stolen information</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/JsmJTbem4bU/">Suicide of Kate Middleton nurse tragic beyond words: hospital chairman joins condemnation of Aussie DJ hoax</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/NL9rPMWUMvo/">I made a vow to his memory: Bill Browder wins fight to ban corrupt Russian business in memory of dead friend</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/NL9rPMWUMvo/">I made a vow to his memory: Bill Browder wins fight to ban corrupt Russian business in the U.S. in memory of dead friend</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/sy-QDEbD6mI/">No greater friend: The bond between Netanyahu and Harper goes beyond statecraft</a>
</li>
<li><a href="http://www.wired.com/threatlevel/2012/12/fbi-charges-barrett-brown/">Feds Charge Anonymous Spokesman For Circulating Hacked Stratfor Credit Cards</a>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/tkkY9kUHouw/">Identify Theft Is a Growing Risk in Health Care: Ponemon Report</a>
</li>
<li><a href="http://darkreading.com/risk-management/167901115/security/news/240144119/awareness-there-policies-lacking-results-of-a-new-sans-survey-on-application-security-policies-in-enterprises.html">Awareness There, Policies Lacking: Results Of A New SANS Survey On Application Security Policies In Enterprises</a>
</li>
<li><a href="http://darkreading.com/advanced-threats/167901091/security/news/240144083/damballa-failsafe-5-1-unveils-breach-confirmation-and-instant-replay-capabilities.html">Damballa Failsafe 5.1 Unveils Breach Confirmation And Instant Replay Capabilities</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/6K-s-gsQW5o/">Nine out of 10 hospitals lost personal data in last two years</a>
</li>
<li><a href="http://www.thestar.com/business/article/1299348--blackberry-maker-rim-gets-good-news-from-2013-it-predictions-by-idc">BlackBerry maker RIM gets good news from 2013 IT predictions by IDC</a>
</li>
<li><a href="/news/world/linked+hacker+group+Anonymous+faces+charges+tied+attack/7668234/story.html">US man linked to hacker group Anonymous faces new charges tied to attack on intelligence firm</a>
</li>
<li><a href="http://feedproxy.google.com/~r/SCMagazineNews/~3/ygws_s0oOBM/">California sues Delta Air Lines over mobile privacy</a>
</li>
<li><a href="http://www.nytimes.com/2012/12/08/technology/eu-panel-to-pressure-google-on-privacy-rules.html?partner=rss&amp;emc=rss">E.U. Panel to Pressure Google on Privacy Rules</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/ZWcMCBx-9ak/">Aussie DJs drop off Twitter after being bombarded by thousands of angry messages in wake of nurses apparent suicide</a>
</li>
<li><a href="http://business.financialpost.com/2012/12/07/takeover-alert-hp-is-now-worth-less-than-it-spent-in-its-acquisition-binge/">TAKEOVER ALERT! HP is now worth less than it spent in its acquisition binge</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/PSiwbE9jpSw/">Australian radio DJs removed from air after nurse they fooled with Kate Middleton prank call dies</a>
</li>
<li><a href="http://darkreading.com/mobile-security/167901113/security/news/240144071/mobile-browsers-fail-georgia-tech-safety-test.html">Mobile Browsers Fail Georgia Tech Safety Test</a>
</li>
<li><a href="http://darkreading.com/security/news/240144072/sia-and-gtsc-announce-collaboration.html">SIA And GTSC Announce Collaboration</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NPWorld/~3/_AgZGGeEf48/">Jacintha Saldanha, who died in suspected suicide after Kate Middleton radio hoax, was an excellent nurse</a>
</li>
<li><a href="http://feedproxy.google.com/~r/DataBreachWatch/~3/fLuWs5DPDeI/">Data Breach &amp; C-Suite</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/_AgZGGeEf48/">Jacintha Saldanha, who committed suicide after Kate Middleton radio hoax, was an excellent nurse</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/VA710GQrVeg/">Search for survivors continues while death toll from Philippine typhoon climbs past 500</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/He3Bsp94bXQ/">Fraser Institute criticizes Dalton McGuintys poor fiscal management in ranking of Canadas premiers</a>
</li>
<li><a href="/news/world/Quantico+brig+commander+taking+stand+WikiLeaks+case+took+away/7666698/story.html">2nd Quantico brig commander taking stand in WikiLeaks case; she took away GI&#8217;s underwear</a>
</li>
<li><a href="http://feedproxy.google.com/~r/NP_Top_Stories/~3/grO5dNlrSH8/">Kate Middleton hospital receptionist who put through prank call from Aussie DJs found dead in apparent suicide</a>
</li>
<li><a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/6RlyV6ixnZo/secworld.php">U.K. hacker convicted for taking part in Anonymous attacks</a>
</li>
<li><a href="http://www.thestar.com/news/canada/article/1299015--breach-of-health-records-shocks-b-c-minister-margaret-macdiarmid">Breach of health records shocks B.C. minister Margaret MacDiarmid</a>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://jacksch.com/2012/12/infosec-news-2012-12-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
