Breaches & Exposures

Visa confirms another payment processor breach

February 24, 2009

Another payment processor has fallen victim to hackers, Visa confirmed on Monday.
 

Poorly implemented Citrix poses security risk

August 06, 2008

Organisational security could be at risk if Citrix is not implemented carefully, according to tests carried out by Global Secure Systems (GSS).
 

Removable devices pose new security risk

July 17, 2008

Government departments 'must beef up the security of removable devices such as USB memory sticks and removable hard drives' to avoid data breaches.
 

Steganography harnesses VoIP networks

Wojciech Mazurczyk and Krzysztof Szczypiorski July 04, 2008

Steganography is an established technique to hide secret data inside normal data transmissions, but new techniques are being developed to hide packets inside routine VoIP traffic, and escape detection
 

Indian Government withdraws threat over BlackBerry services

July 04, 2008

The threat which could have led to the country's BlackBerry services being suspended appears to have lifted after the Government backed down on its own demands for access to users' data
 

HMRC breach would have been avoided for just £15,000

July 03, 2008

The catastrophic loss of information of 25 million UK citizens last year would have been avoided if Her Majesty's Revenue and Customs had spent a maximum of £15,000 on the extraction of data, but it turned down this expenditure because information security was such a low priority, one of the breach investigators revealed today
 

Data watchdog admits to deluge of Central Government breach info

July 03, 2008

The Information Commmissioner's Office has revealed it has been voluntarily informed of a huge number of security breaches - mostly in Westminster - while it eyes up plans for a new law which could make the reporting of such incidents compulsory
 

Exclusive: Privacy campaigners may sue EC over provision of citizens' personal data to the FBI

June 30, 2008

A leading civil rights organisation is threatening the European Commission with legal action as Brussels nears an agreement with the US over plans to release details of individuals' credit card histories and internet browsing habits to the FBI
 

Poynter review: HMRC has radically reduced security risks

June 26, 2008

PwC chairman Kieran Poynter, the man tasked to investigate what happened in the catastrophic HMRC data breach, has revealed that significant progress has been made since the disastrous information leakage last October
 

Oyster card hackers may have their research blocked

June 26, 2008

Two Dutch academics who came to London last week to prove they could break the cipher behind London's Oyster travel card have been warned by the country's Government not to expose any secrets in their upcoming paper on the subject
 

Pacific island knocked off internet by DDoS attack

June 26, 2008

The Marshall Islands have been subjected to a prolonged bout of unexpected email traffic, preventing citizens receiving emails, but the reason for the attack remains unclear
 

Poynter Review, IPCC severely criticise HMRC over data breach

June 25, 2008

Two separate reports into the data leakage of 25 million records from Revenue & Customs last year have widely condemned data security procedures in the Government department
 

Scotland loses details of nearly one million 999 calls

June 24, 2008

Parcel courier TNT has lost a disk containing extensive details of emergency calls made in Scotland over the last two years
 

Dutch academics hack Oyster card

June 24, 2008

Security lecturers from a leading Netherlands university travelled to London last week to crack the Oyster smart card, clone it and get a free day's travel, while they pursue an open source alternative
 

Private investigators fined by magistrates after conning BT for information

June 23, 2008

Two private detectives have been fined by a London court after blagging information on the partner of a man wanted for a debt to their client
 

ATM hackers net millions using stolen information

June 20, 2008

Citibank, one of the world's largest banks, has been hit by a chain of fraudulent cashpoint transactions, according to a US federal grand jury indictment; a Ukranian immigrant has now been charged
 

Weak security controls to blame as finance firm is hit by FSA fine

June 19, 2008

Merchant Securities is forced to cough up £77,000 for putting its customers at risk of identity fraud as part of a crackdown on lax security controls by the financial services watchdog
 

Coffee drinkers in peril after espresso overspill attack

June 19, 2008

A geeky risk advisory manager from global accountancy firm BDO has hacked into a leading coffee machine, causing it to pour scalding water onto unsuspecting espresso lovers
 

Stolen data found on international crimeservers

June 19, 2008

Two crimeservers containing half a gigabyte of stolen data have been discovered in Argentina and Malaysia; the data was likely being made available to the highest bidder
 

Government admits breaching data rules following PC theft

June 18, 2008

A senior civil servant has revealed that his department did not meet its own data protection guidance as the PC of minister Hazel Blears was stolen from her constituency office
 

NASA hacker appeals to House of Lords to overturn extradition

June 18, 2008

Appearing in Parliament this week, Gary McKinnon's legal team have argued that his planned extradition to the US should be overturned because US officials abused legal processes, while lawyers representing the Home Office say the extradition should proceed
 

Home Secretary faces grilling after second secret document leak

June 16, 2008

Jacqui Smith is to face questioning from the chair of the home affairs select committee over whether the country's fight against terrorism has been compromised after a second set of confidential Government documents was left on a train
 

Government suspends civil servant over al-Qaeda document leak

June 12, 2008

A Cabinet Office employee who left top secret documents regarding Iraq and Al-Qaeda on a busy London commuter train has been suspended; police are investigating
 

Ethical hacking site falls victim to hackers

June 04, 2008

Metasploit, the hacking tools site which is widely used by white hat hackers, has itself fallen victim to ARP poisoning, which led to the defacement of the site
 

Motorola RAZR found vulnerable to JPEG attack

May 29, 2008

Hackers could run malicious code on the RAZR device by sending a corrupt image by MMS, according to an advisory from TippingPoint
 

RIM stands firm over Indian demands to decrypt data

May 27, 2008

The BlackBerry maker has refused to budge over demands that it allows India's Government to snoop on user's data in order to track terrorists
 

Auditors unearth weak IT security at SocGen

May 27, 2008

The bank which was hit by a £3.9bn trading fraud harbours widespread weaknesses in its systems and applications, according to an audit released on Friday
 

Ex-Mastercard exec reveals top postcodes for identity fraud

May 26, 2008

And it's not good if you live in London...
 

Trustwave branches out into application pen-testing

May 26, 2008

The security services company is to try to help enterprises protect their web-based apps from attacks like SQL injection, buffer overflow and cross-site scripting
 

Apple rapped for Safari download policy

May 19, 2008

The Mac maker and creator of the popular web browser has come under fire from a leading security researcher for the ease at which users can download malicious software from the web, but it seems reluctant to change its mind
 

SC Featured Webcast

Employee file sharing: the good, the bad and the ugly

Streaming live on 4th June 2013 at 3pm GMT

This new webcast is set to unveil the full results from the latest data security survey, where it was revealed that 50 per cent of the information security professionals asked said that they had 'no real visibility' of how data is being sent within and outside the company. Guest speakers include the director of information security from Monster.co.uk and the ISO from Atos. To secure your free place, please click here.

SC Webcasts

Security beyond the (fire)wall

Streaming live on 6th June at 3pm BST

This webcast addresses the technological challenges of maintaining full control of your most sensitive information - even once it goes beyond the firewall - while maintaining the freedom and flexibility necessary to allow your staff and other stakeholders to work as efficiently as possible. Tune in for free to hear from our regular and popular guest speaker, Bola Rotibi from (ISC)2 application security advisory board. To secure your place, please click here.


2013's invisible network threats: Identify and respond

Streaming live on 11th June at 3pm BST

In a recent SC survey, when asked 'Do you think your current network is secure?' 43 per cent of IS professionals said they were not sure. Technology developments such as multi-point cloud solutions, consumerisation, BYOD uptake and even Windows 8 are a major headache in network security for IT leaders. So what can be done? SC's latest webcast shares practical advice from industry experts. To secure your free place, please click here.

SC Whitepapers

Java security: Balancing existing testing platforms with open source solutions

In a rush to get new products out to market quickly, companies expose themselves to the risk of software failure. Java developers often turn to open source solutions to help protect themselves from risk. This new whitepaper explains how you can use your existing testing platforms alongside open source solutions to fix those issues related to both security and quality within your Java code. To download the paper for free, please click here.


DDoS and downtime: Considerations for risk management

The purpose of this paper is to start a conversation about the often overlooked risk of downtime caused by DDoS attacks and to provide sufficient content for risk managers to account for the DDoS threat as they evaluate risks to their day-to-day operations and long-term mission. To read the paper in full, please download it for free here.


Ponemon 2012 Global Encryption Trends Study

In Ponemon's recent Global Encryption Study, the organisation surveyed 4,205 information security professionals across seven countries to examine how encryption has evolved over the last eight years. The study focused on data protection priorities, budgeted expenditures for encryption and the types of encryption technologies involved, with the findings revealing some interesting insight into the relationship between encryption and its impact on the security position of organisations. To read the full report for free, please download it here.


Advanced spear phishing: The rise of industrial phishing attacks

With phishing still the most common form of attack, hackers are now engaging in industrial-scale phishing attacks that leverage sophisticated customisation and delivery techniques. Borrowing tactics from cloud computing and database marketing, this study looks at longline phishing - an advanced form of spear phishing, which has higher clickthrough and penetration rates than traditional attacks, potentially causing a higher risk to IT security departments across the world. To read the study for free, please click here.


Home | News | Products | Whitepapers | Jobs | Subscribe | Contact Us | About Us | Advertising | Sitemap | Editorial | Subscribe to our RSS feeds RSS

This material may not be published, broadcast, rewritten or redistributed in any form without prior authorization.

Your use of this website constitutes acceptance of Haymarket Media's Privacy Policy and Terms & Conditions