Encryption

Infragard Atlanta, an FBI affiliate, hacked by LulzSec

Infragardlogo245

LulzSec, a hacking group known for attacking Sony and PBS, have attacked a non-profit named Infragard who work closely with the FBI. Hundreds of logins and operational details of some individuals were disclosed through pastebin.com and BitTorrent.

Share

Sony Europe hacked by Lebanese hacker... Again

iwasbored245

Updated with information on 14th attack against SonyPictures.RU. Sony was hacked for the 13th time, this time exposing usernames, passwords, work emails, mobile phones and web site information on 120 Sony Europe users.

Share

Sony Pictures attacked again, 4.5 million records exposed

SonyPictures245

Sony Pictures has been hacked by LulzSec leading to 4.5 million records being made available. Usernames, email addresses, passwords (in plain text) and more have been released.

Share

Honda Canada loses 283,000+ records, now faces lawsuit

myhonda

Honda Canada disclosed a breach of their myHonda and myAcura websites that affected more than 283,000 Canadian Honda owners. Information stolen in the attack included names, addresses, Vehicle Identification Numbers and in some cases Honda Finance account numbers.

Share

Sony succumbs to another hack leaking 2,500 "old records"

Arcade240

Sony has acknowledged another system has been compromised by hackers and names and addresses of 2,500 more people have been stolen and published.

Share

Sony admits breach larger than originally thought, 24.5 million SOE users also affected

DataTheft245

Sony disclosed today that the breach two weeks ago affects an additional 24.5 million users of its Sony Online Entertainment division. They have shut down the service until further notice and continue to investigate the thefts.

Share

SSCC 58 - Coreflood, DSLReports, Sony, Stars and Ars Technica

Sophos Security Chet Chat 41

Sophos Security Chet Chat 58 features Paul Ducklin and Chester Wisniewski discussing the week's most pertinent security topics. This week: the Coreflood take-down; password loss at DSLReports; Sony's big data breach; Iran claims a "Stars" virus attack; and Facebook shuts down Ars Technica.

Share

The New York Yankees and DSLReports.com responsible for 30,000 more data loss victims

YankeeHelmet245

The New York Yankees accidentally emailed personal details on 21,000 customers to their affiliates. Around the same time DSLReports disclosed they had been hacked through a SQL injection attack that disclosed the plain text passwords of thousands of members.

Share

Sony says credit card details *were* encrypted, but questions still remain

Sony: Credit card details *were* encrypted

Sony confirms that credit card details which could have been stolen in the recent hack of the PlayStation Network were encrypted, but doesn't reassure customers regarding the strength of encryption.

Share

Easter Egg locations remain safe, says Bunny spokesperson

EasterBunnyistock245

Reports surfaced today that the Easter Bunny was involved in a minor accident and lost a netbook containing the locations he had hidden Easter eggs and baskets around the world.

Share

Ashton Kutcher's Twitter hacked with pro-SSL graffiti

kutcher-thumb

Could an open WiFi hotspot have allowed Ashton Kutcher's Twitter account to have been compromised at TED?

Share

SSCC 50 - Windows 7 SP1, OddJob Trojan, HIPAA fines and erasing SSDs

Sophos Security Chet Chat 41

Chet Chat 50 features Tony Ross talking with Chet about Windows 7 SP1, a new banking Trojan, HIPAA and the difficulty with securing disposing of Solid State Disks.

Share

SSDs, encryption and decommissioning

Encrypting SSDs the right way

A research paper about the secure erasure of data on SSDs has raised a lot of discussion.

What steps do you need to take when decommissioning a disk?

Share

SSDs prove difficult to securely erase

Creative Commons photo courtesy of PiAir's Flickr photostream

Researchers at last weeks Usenix FaST 11 conference presented a paper showing how difficult it can be to erase SSDs. We have summarized their results here and provide best practices on protecting your data if you are using SSDs.

Share

SSCC48 - RSA 2011 Conference roundup

Sophos Security Chet Chat 41

This week's Chet Chat comes to you from the show floor at RSA Conference 2011. Paul Ducklin joins Chet to discuss the buzz from the show and the latest security news.

Share

VIDEO: How to steal passwords from a locked iPhone

iphone-attack-thumb

German researchers say that they have found a way to steal passwords stored on a locked Apple iPhone in just six minutes.

Even if they don't know your iPhone's passcode.

Share

UK councils fined £150,000 for data loss, but who gets the cash?

UK councils fined £150,000 for data loss, but who gets the cash?

Turns out that password protection just ain't enough anymore. Councils need to encrypt laptops as well, and this was an expensive lesson for UK councils Ealing and Hounslow to learn. Question is: who benefits from these fines?

Share

Top tips for Mac OS X security - Part 1

XSecTips250-2

Part one of our three part series on Mac OS X security provides tips on how to secure your Macintosh against physical threats. A few simple steps can protect your precious Mac, is your Mac secure?

Share

WikiLeaks, Gawker, OpenBSD, Lineage II - 90 Sec News - Dec 2010

featured-250

Don't just read the latest computer security news - watch it in 90 seconds!

This month: the WikiLeaks show, massive Gawker password theft, an out-of-the-blue OpenBSD accusation, and virtual property stolen from Lineage II.

Share

Mozilla accidentally publishes user IDs and password hashes

The tshirt Jacob Appelbaum was wearing during his MD5 talk at 25c3

Mozilla, of Firefox and Thunderbird fame, had accidentally published the user IDs and password hashes of users of their addons.mozilla.org website. It appears their reaction to the disclosure has contained the damage, but what can be done to prevent these incidents in the future?

Share